Hacked Kaspersky Lab Security Company

The Russian security firm Kaspersky Lab recently discovered that a powerful and mysterious group of hackers using an advanced persistent threat (APT) known as Duqu has breached its systems by using a zero-day Windows Kernel.
From 2012 to date, no other cyber-related activity associated with Duqu is a platform used for cyber-espionage.dump Kaspersky Lab

However, the infections were made by a new version of the platform (called Duqu 2). The new malicious software appeared in 2014 and continues to exist in Western countries to date.

The zero-day vulnerability that exploits malware is CVE-2015-2360, which was patched by Microsoft on Tuesday. Kaspersky reports that one or two other vulnerabilities have been used in the attack on its systems.

Researchers report that the initial attack began in one of Asia's smallest offices and spear-phishing emails were probably used.

"Malicious modules were observed trying to perform 'pass the hash' attacks on the local network, essentially giving attackers many different ways to perform lateral movement," Kaspersky Lab reports.

Over 100 malicious variants detected

Duqu 2 uses multiple tactics to spread across the network, and in most cases, the attack was carried out with Microsoft Windows Installer support (MSI packages that can be remotely enabled on other computers).

MSI files could memorize the payload of malicious software and open backdoors for the attackers' spy targets.

The main module of Duqu 2 implements controls to communicate with the command and control center or C&C and uses too many proxy connection protocols and self-signed HTTPS certificates.

The purpose of the attack on Kaspersky Lab's network appears to be the espionage of the technology used and that developed by the company. However, research is being carried out by security experts and later on we will know more details.

Analysis of the malware showed that it could collect data from running processes, on work and terminal sessions. It still searched for, recorded, and ran files such as “*.inuse, *.hml,” filename contains “data.hmi” or “val.dat,” as well as the contents of specific folders.

Kaspersky Lab believes that the specific there is no impact on its products, technologies and services, and that its customers and partners are safe…

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by giorgos

George still wonders what he's doing here ...

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).