|
The scope of a cyber espionage campaign targeting Iran and other parts of the Middle East has widened, even after security experts blew the operation's cover last month, according to the research firm that discovered the Mahdi Trojan.
Israeli security company Seculert said that it has identified about 150 new Mahdi victims over the past six weeks as the developers of the virus have changed the code to evade detection from anti-virus programs. That has brought the total number of infections found so far to nearly 1,000, the bulk of them in Iran.
![]() Mahdi Trojan discovered
"These guys continue to work," Seculert Chief Technology Officer Aviv Raff said via telephone from the company's headquarters in Israel. The decision to keep the operation running implies that Mahdi's operators were not particularly worried about getting caught, said Roel Schouwenberg, a senior researcher with Kaspersky Lab, which has collaborated with Seculert in analyzing Mahdi.
Schouwenberg said that some viruses are designed for stealth because they become useless if they are discovered. He pointed to the Stuxnet Trojan that targeted Iran's nuclear program in 2010. After that customer-built virus was uncovered by a security researcher in Belarus, authorities in Iran discovered it in a uranium enrichment facility that it had targeted.
Mahdi is a "less professional" operation that runs on technology built with widely available software, according to Schouwenberg.
"If the quality of your operation is not that high, then maybe you don't care about being discovered," he said. "But the scary thing is that it can still be effective."
The Mahdi Trojan lets remote attackers steal files from infected PCs and monitor emails as well as instant messages, Seculert and Kaspersky said. It can also record audio, log keystrokes and take screen shots of activity on those computers.
The firms said they believed multiple gigabytes of data have been uploaded from targeted machines.
Targets of Mahdi include critical infrastructure firms, engineering students, financial services firms and government embassies located in five Middle Eastern countries, with the majority of the infections in Iran, according to the two security firms.
The bulk of the new victims were in Iran, which is where most infections have occurred to date, according to Seculert, though a few were identified in the United States and Germany.
The two firms have declined to identify specific victims.
Raff said that he suspects the campaign is being run by hacker activists, or "hactivists," who are either funded by a government or provide information they collect to a nation for ideological reasons. He declined to say which country might be involved.
Seculert and Kaspersky dubbed the campaign Mahdi after a term referring to the prophesied redeemer of Islam because evidence suggests the attackers used a folder with that name as they developed the software to run the project.
They also included a text file named mahdi.txt in the malicious software that infected target computers.
Reuters |
Tags: cyber strike , Iran , Mahdi , Mahdi Trojan , Mahdi Trojan Iran , Hactivists , hacker activists , malicious software
SPOTLIGHT
Nvidia to license its GPU, visual computing
19 Jun, 2013, 07:26 PM
Overview: Intel Haswell platform
19 Jun, 2013, 05:30 PM
Microsoft to use Qualcomm chips on...
19 Jun, 2013, 09:20 PM
No delivery, says Flipkart for Rs 10,000-plus orders from UP
07 Jun, 2013, 11:07 AM IST
Mumbai movie-goers breathe sigh of relief after online Convenience...
17 Jun, 2013, 09:01 PM IST
Vietnam arrests well-known blogger for criticising the Government
14 Jun, 2013, 09:56 AM IST
Vodafone India slashes 2G rates by 80 percent in some circles
19 Jun, 2013, 05:48 PM IST
Best online resources for GMAT
19 Jun, 2013, 01:39 PM IST
Researchers are now able to get inside iOS Wi-Fi hotspots in under a minute
19 Jun, 2013, 08:48 PM
Concerned data protection officials write to Google CEO to discuss privacy on Glass
19 Jun, 2013, 08:05 PM
Vodafone India slashes 2G rates by 80 percent in some circles
19 Jun, 2013, 05:48 PM
Best online resources for GMAT
Indian students planning to pursue GMAT have sufficient paid as well as...
How IRCTC can make tatkal bookings easier
In India, online travel ticketing has gotten mature and more Indians are...
Looking for food past midnight? Check out these services
Struck by midnight hunger pangs? Check these services that will bring...
Sony Xperia Tablet Z (SGP321) Review
daniel
Thu Jun 20, 05:09:41
Sony Xperia Tablet Z (SGP321) Review
daniel
Thu Jun 20, 05:08:09
Sony Xperia Tablet Z (SGP321) Review
daniel
Thu Jun 20, 05:04:56
LG working on always-on voice commands for
Huawei Ascend Mate: A specifications review
Microsoft to use Qualcomm chips on...
Sony Xperia Tablet Z (SGP321) Review
New MacBook Air coming soon to India;...
Alienware shows three new gaming notebooks
Sony shows off PlayStation 4's...
PC version of The Witcher 3 to get free...


















reddit

Mixx
Facebook
Twitter
Digg
delicious
MySpace
















