Attacks/Breaches
11/1/2011
02:10 PM
Connect Directly
RSS
E-Mail
50%
50%

Nitro Malware Targeted Chemical Companies

Symantec finds Trojan launched industrial espionage attacks against chemical compound and advanced material manufacturers.

Multiple Fortune 100 companies have recently been targeted by malware as part of a campaign designed to steal proprietary information. In particular, at least 50 different waves of attacks were launched against businesses involved in the research, development, and manufacture of both chemical compounds and advanced materials.

That revelation comes from a study, "The Nitro Attacks: Stealing Secrets from the Chemical Industry," released Monday by Symantec. According to the study's authors, Eric Chien, technical director of Symantec Security Response, and Symantec threat intelligence officer Gavin O'Gorman, the attack campaign against the chemical industry--which led to their codenaming it "Nitro"--ran from July to mid-September 2011.

But they've found evidence that part of the attack infrastructure was put to use before then. Notably, they said that the command-and-control servers communicating with the remote-access tools used in the attacks first appeared in April 2011, and targeted human-rights-related nonprofit groups. The next month, meanwhile, the infrastructure was employed to attack the motor manufacturing industry. Then, after being dormant for part of June and July, the command-and-control servers were reactivated for the recent chemical industry attack campaign, which lasted for about 10 weeks.

[End users aren't the only people who may be compromising your security. Are Your IT Pros Abusing Admin Passwords?]

So far, Symantec has confirmed that 29 chemical companies and 19 organizations in other industries were targeted by the malware. But it warned that the actual number of businesses targeted--or exploited--by the malware may be much higher. "In a recent two-week period, 101 unique IP addresses contacted a command and control server with traffic consistent with an infected machine. These IPs represented 52 different unique Internet service providers or organizations in 20 countries," said Chien and O'Gorman.

In the case of the chemical industry attacks, the attackers targeted businesses that manufacture chemical compounds or advanced materials used for manufacturing military vehicles, as well as businesses that design and build manufacturing systems for the chemical and advanced material industries. "The purpose of the attacks appears to be industrial espionage, collecting intellectual property for competitive advantage," they said. In particular, the attackers were hunting for "sensitive documents such as proprietary designs, formulas, and manufacturing processes."

Targeted attacks involving remote access tools aren't new. Earlier this year, for example, McAfee published its findings into a series of attacks it dubbed Shady RAT, for remote access tool. But McAfee's report was criticized by some for being unnecessarily alarmist after outside experts studied the malware and found it to be relatively unsophisticated, and far less dangerous than many other botnets currently at large. In contrast to the McAfee study, Symantec's report paints a picture of malware that's only as sophisticated as it needs to be.

In particular, the Nitro malware was emailed to a select--and apparently prescreened group--of recipients, numbering anywhere from just a handful of employees to almost 500 in any given business. The emails, however, really constituted a phishing attack, sent under the pretext of either a meeting invitation from a known business partner or a necessary security update for either Flash Player or an antivirus product.

The email's attachment--a self-extracting executable included in a zipped file, with the password pasted into the email body--was actually a common Trojan malware known as Poison Ivy. But just because the remote administration tool might be common--and free to download--doesn't mean it isn't dangerous or effective. Indeed, the malware, which security researchers say was developed by a Chinese-language speaker, was used both to exploit RSA's SecurID, as well as in the Operation Aurora attack against Google.

Previous
1 of 2
Next
Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
Partner Perspectives
What's This?
In a digital world inundated with advanced security threats, Intel Security seeks to transform how we live and work to keep our information secure. Through hardware and software development, Intel Security delivers robust solutions that integrate security into every layer of every digital device. In combining the security expertise of McAfee with the innovation, performance, and trust of Intel, this vision becomes a reality.

As we rely on technology to enhance our everyday and business life, we must too consider the security of the intellectual property and confidential data that is housed on these devices. As we increase the number of devices we use, we increase the number of gateways and opportunity for security threats. Intel Security takes the “security connected” approach to ensure that every device is secure, and that all security solutions are seamlessly integrated.
Featured Writers
White Papers
Cartoon
Current Issue
Dark Reading's October Tech Digest
Fast data analysis can stymie attacks and strengthen enterprise security. Does your team have the data smarts?
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-7052
Published: 2014-10-19
The sahab-alkher.com (aka com.tapatalk.sahabalkhercomvb) application 2.4.9.7 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

CVE-2014-7056
Published: 2014-10-19
The Yeast Infection (aka com.wyeastinfectionapp) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

CVE-2014-7070
Published: 2014-10-19
The Air War Hero (aka com.dev.airwar) application 3.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

CVE-2014-7075
Published: 2014-10-19
The HAPPY (aka com.tw.knowhowdesign.sinfonghuei) application 2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

CVE-2014-7079
Published: 2014-10-19
The Romeo and Juliet (aka jp.co.cybird.appli.android.rjs) application 1.0.6 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Follow Dark Reading editors into the field as they talk with noted experts from the security world.