F-Secure Study Links CozyDuke to High-Profile Espionage

F-Secure Study Links CozyDuke to High-Profile Espionage

ID: 389922

F-Secure Labs' Latest White Paper Highlights CozyDuke as Part of an Ongoing Series of Advanced Persistent Threats Targeting Governments and Other Large Organizations


(firmenpresse) - SAN JOSE, CA -- (Marketwired) -- 04/30/15 -- A new malware analysis from points to as a continuing menace facing governments and other large organizations. CozyDuke is an Advanced Persistent Threat (APT) toolkit that uses combinations of tactics and malware to compromise and steal information from its targets, and the new analysis links it to other APTs responsible for a number of high profile attacks.

According to the analysis, CozyDuke shares command and control resources with the prominent and OnionDuke APTs. F-Secure Labs has attributed several high-profile attacks to these APT platforms, including malicious attacks against people using a Russian Tor exit node, and targeted attacks against NATO and a number of European government agencies.* CozyDuke utilizes much of the same infrastructure as these other platforms and employs components with encryption algorithms similar to those used by OnionDuke, linking the same technology to different campaigns.

"All of these threats are related to one another and share resources, but they're built a little bit differently to make them more effective against particular targets," said F-Secure security advisor . "The interesting thing about CozyDuke is that it's being used against a more diverse range of targets. Many of its targets are still Western governments and institutions, but we're also seeing it being used against targets based in Asia, which is a notable observation to make."

CozyDuke and its associates are believed to originate from Russia**. The attackers establish a beachhead in an organization by tricking employees into doing something such as opening an attachment in an e-mail that distracts users with a decoy file (like a PDF or a video), allowing CozyDuke to infect their system without being noticed. Attackers can then perform a variety of tasks by using different payloads compatible with CozyDuke, and this can let them gather passwords and other sensitive information, remotely execute commands, or intercept confidential communications.





Sullivan acknowledges there's not yet sufficient evidence to definitively conclude what the attackers' true identities and motives are, but he is quite confident that they are the same people responsible for attacks attributed to OnionDuke and MiniDuke.

"CozyDuke has actually been around since 2011, but it's something that's been developing so it keeps on changing. This tells us that a group or groups have been investing time and money to nurture these tools, so figuring out what they're after now is really what we need to be focusing on."

The white paper also notes that CozyDuke checks for cybersecurity software before establishing its infection, and certain types of software can cause it to abandon the attack. The white paper, penned by F-Secure Threat Intelligence Analyst Artturi Lehtiö, is free and available for download from .

*Source:
**Source:



F-Secure is an online security and privacy company from Finland. We offer millions of people around the globe the power to surf invisibly and share stuff, safe from online threats. We are here to fight for digital freedom. Join the movement and switch on freedom.

Founded in 1988, F-Secure is listed on NASDAQ OMX Helsinki Ltd.

| |



Weitere Infos zu dieser Pressemeldung:

Themen in dieser Pressemitteilung:


Unternehmensinformation / Kurzprofil:
drucken  als PDF  an Freund senden  Noble Iron Delays Filing Annual Financial Statements Integration Point Named Top 100 Logistics IT Provider From Inbound Logistics for Eighth Consecutive Year
Bereitgestellt von Benutzer: Marketwired
Datum: 30.04.2015 - 15:51 Uhr
Sprache: Deutsch
News-ID 389922
Anzahl Zeichen: 0

contact information:
Town:

SAN JOSE, CA



Kategorie:

Software



Diese Pressemitteilung wurde bisher 190 mal aufgerufen.


Die Pressemitteilung mit dem Titel:
"F-Secure Study Links CozyDuke to High-Profile Espionage"
steht unter der journalistisch-redaktionellen Verantwortung von

F-Secure, Inc. (Nachricht senden)

Beachten Sie bitte die weiteren Informationen zum Haftungsauschluß (gemäß TMG - TeleMedianGesetz) und dem Datenschutz (gemäß der DSGVO).

F-Secure Acquires Nordic's Leading Cybersecurity Provider ...

SAN JOSE, CA -- (Marketwired) -- 06/02/15 -- announced today that it has acquired nSense -- a privately held Danish company providing security consultations, vulnerability assessment services and related products to large enterprises. The acquisiti ...

New F-Secure App Plugs Privacy Gaps for Mac Users ...

SAN JOSE, CA -- (Marketwired) -- 05/05/15 -- OS X delivers an intuitive user experience and pleasing aesthetic design to Mac users, and many MacBook owners can be seen enjoying their machines in public, but enjoying these devices in places offering ...

Alle Meldungen von F-Secure, Inc.



 

Werbung



Facebook

Sponsoren

foodir.org The food directory für Deutschland
Informationen für Feinsnacker finden Sie hier.

Firmenverzeichniss

Firmen die firmenpresse für ihre Pressearbeit erfolgreich nutzen
1 2 3 4 5 6 7 8 9 A B C D E F G H I J K L M N O P Q R S T U V W X Y Z