Welcome to SAMAA TV
 
SAMAA SMS News Alerts
 
Gunmen kill five more persons in Karachi         PPP got mandate from Sindh because of services: Qaim         UK fighters escort Pakistan plane to airport; 2 arrested         Large blast heard in centre of Kabul         Shahbaz asks caretaker government to reduce load shedding hours         British security services in spotlight after soldier murder         Pedestrian dies in accident involving US embassy vehicle, condolences offered         MQM never wanted to spread hatred, says Altaf Hussain         US hints at renewed Iranian sanctions waiver for India         PTI Chief Imran Khan condemns Peshawar blast         Rain delays start of second test at Headingley         British Airways plane makes Heathrow emergency landing after engine fire         Three killed in suspected suicide blast at Peshawar madrasah         Govt. withdraws ban on supplying CNG to vehicles above 1000cc         China says hopes visit of North Korean envoy can ease tension         US ambassador Olson meets Imran Khan; enquires about health         Repatriating detainees to Yemen key to closing Guantanamo         Hot weather will continue to prevail today; rain likely in Malakand, Gilgit         Google, like Facebook, in talks to buy Waze for $1 billion: report         Strong quake strikes Russian Far East         Russia's top social network blacklisted by regulator         US lawmakers intensify push on military sexual assault problem         Asian stocks shaky, Nikkei still seen vulnerable         Global markets face rough summer ride as Fed pullback feared         British police ponder conspiracy after soldier murder         Bridge collapses in Washington state, sending cars into river         Quetta: CD shop owner killed in grenade attack         Karachi: Cracker blast outside govt school; none injured         Anti-war woman protests during Obama's speech         PCB stands aloof from Asad Rauf issue         MQM to elect new Coordination Committee on Saturday         Balochistan plunges into darkness after midnight         IMF's Lagarde questioned over French arbitration case         Cannes festival hit by second suspected jewellery theft         Obama limits use of U.S. drone strikes        
Cyber spying expands in Iran after operation is blown
Wednesday, August 29, 2012 4:11:57 PM | Comments (0)
Cyber spying expands in Iran after operation is blown

BOSTON: The scope of a cyber espionage campaign targeting Iran and other parts of the Middle East has widened, even after security experts blew the operation's cover last month, according to the research firm that discovered the Mahdi Trojan.

Israeli security company Seculert said that it has identified about 150 new Mahdi victims over the past six weeks as the developers of the virus have changed the code to evade detection from anti-virus programs. That has brought the total number of infections found so far to nearly 1,000, the bulk of them in Iran.

"These guys continue to work," Seculert Chief Technology Officer Aviv Raff said via telephone from the company's headquarters in Israel.

The decision to keep the operation running implies that Mahdi's operators were not particularly worried about getting caught, said Roel Schouwenberg, a senior researcher with Kaspersky Lab, which has collaborated with Seculert in analyzing Mahdi.

Schouwenberg said that some viruses are designed for stealth because they become useless if they are discovered. He pointed to the Stuxnet Trojan that targeted Iran's nuclear program in 2010. After that customer-built virus was uncovered by a security researcher in Belarus, authorities in Iran discovered it in a uranium enrichment facility that it had targeted.

Mahdi is a "less professional" operation that runs on technology built with widely available software, according to Schouwenberg.

"If the quality of your operation is not that high, then maybe you don't care about being discovered," he said. "But the scary thing is that it can still be effective."

The Mahdi Trojan lets remote attackers steal files from infected PCs and monitor emails as well as instant messages, Seculert and Kaspersky said. It can also record audio, log keystrokes and take screen shots of activity on those computers.

The firms said they believed multiple gigabytes of data have been uploaded from targeted machines.

Targets of Mahdi include critical infrastructure firms, engineering students, financial services firms and government embassies located in five Middle Eastern countries, with the majority of the infections in Iran, according to the two security firms.

The bulk of the new victims were in Iran, which is where most infections have occurred to date, according to Seculert, though a few were identified in the United States and Germany.

The two firms have declined to identify specific victims.

Raff said that he suspects the campaign is being run by hacker activists, or "hactivists," who are either funded by a government or provide information they collect to a nation for ideological reasons. He declined to say which country might be involved.

Seculert and Kaspersky dubbed the campaign Mahdi after a term referring to the prophesied redeemer of Islam because evidence suggests the attackers used a folder with that name as they developed the software to run the project.

They also included a text file named mahdi.txt in the malicious software that infected target computers.  -- AGENCIES

 
 
Watch SAMAA TV Live
McCain slams White House over cyber leaks
South Korean paper hit by major cyber attack
Disinformation flies in Syria's growing cyber war
Virus found in Mideast can spy on finance transactions
PPP got mandate from Sindh because of services: Qaim
Large blast heard in centre of Kabul
Shahbaz asks caretaker government to reduce load shedding hours
British security services in spotlight after soldier murder
Pedestrian dies in accident involving US embassy vehicle, condolences offered
 
 
 
Post Your Comments
Note: SAMAA TV values your opinions and encourages you to add a comment to this discussion. Please don't be offended if we edit and/or remove questionable, off topic comments; SAMAA TV is not responsible for user comments.
Name:
 
Email:
 
 Leave a Comment:
 
Security Code:
 
 
User Comments
No comment(s) found.
 
     
SAMAA TV
UPDATES WITH
follow us on facebook
follow us on twitter
follow us on youtube
isamaa
subscribe for samaa email news alerts
samaa sms alert
samaa rss