Attacks/Breaches
8/13/2013
04:59 AM
Tim Wilson
Tim Wilson
Quick Hits
Connect Directly
RSS
E-Mail
50%
50%

Hackers Who Attacked New York Times Are At It Again, FireEye Says

China-based attackers named in Mandiant's "APT1" report now using retooled malware, report says

The China-based attackers who broke into systems at The New York Times and other media outlets earlier this year are at it again, according to a new report.

In a blog posted on Monday, researchers at FireEye say they have detected the first significant activity from the China-based hacking group since it was made infamous in Mandiant's "APT1" report early this year.

The group had been largely silent since the Mandiant report came out, according to FireEye, but is now actively conducting attacks again using retooled versions of Aumlib and Ixeshe, two previously known malware exploits that are used for targeted attacks.

Both of these malware families have been known for years, but the attackers appear to have rewritten them significantly, possibly in response to the APT1 report, FireEye says.

"We cannot say for sure whether the attackers were responding to the scrutiny they received in the wake of the [New York Times] episode," the blog states. "But we do know the change was sudden. Akin to turning a battleship, retooling TTPs [techniques, tactics and procedures] of large threat actors is formidable. Such a move requires recoding malware, updating infrastructure, and possibly retraining workers on new processes."

Some researchers said the retooled malware was predictable. "Since being exposed and subjected to wide-scale scrutiny and criticism of their operation from the security community, it should come as no surprise that these state-sponsored groups have upped their game," says Richard Henderson, security strategist for Fortinet's FortiGuard Labs.

"We often see variations in known malware in the field," says Jeremy Coons, senior manager of cybersecurity services at AccessData. "In fact, public release of reports such as the APT1 has actually increased that activity. It is a serious issue, as there is really no way to stay ahead of the curve."

Other security researchers confirmed that they are also detecting the revised malware, but were less inclined to connect it to the group that devised the attacks described in APT1.

"I don't think this code has anything to do with the APT1 report," says Adam Meyers, a researcher at security firm CrowdStrike. "I suspect after a number of years [the attackers] needed some upgraded functionality -- and, as FireEye states, because their traffic was readily identifiable, this lowered the effectiveness of their operations. But this actor is very different than the 'APT1' actor we call Comment Panda."

Some experts said the APT1 report may eventually make it more difficult to defend against sophisticated groups of attackers. "If you're playing poker and you discover your opponent has a 'tell,' you don't point it out to him," says John Prisco, CEO of security vendor Triumfant. "Malware authors are obviously going to be changing their tactics because the whole world already knows what tactics they were previously using -- thanks to the APT1 report that pointed out the tell."

Have a comment on this story? Please click "Add a Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message. Tim Wilson is Editor in Chief and co-founder of Dark Reading.com, UBM Tech's online community for information security professionals. He is responsible for managing the site, assigning and editing content, and writing breaking news stories. Wilson has been recognized as one ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
jayevee
50%
50%
jayevee,
User Rank: Apprentice
8/15/2013 | 7:13:58 PM
re: Hackers Who Attacked New York Times Are At It Again, FireEye Says
I was just about the say the same thing.
Tartarus
50%
50%
Tartarus,
User Rank: Apprentice
8/13/2013 | 4:41:31 PM
re: Hackers Who Attacked New York Times Are At It Again, FireEye Says
There's some confusion here. The FireEye blog posting is about the Ixeshe group (APT 12). Not APT 1.
Register for Dark Reading Newsletters
Partner Perspectives
What's This?
In a digital world inundated with advanced security threats, Intel Security seeks to transform how we live and work to keep our information secure. Through hardware and software development, Intel Security delivers robust solutions that integrate security into every layer of every digital device. In combining the security expertise of McAfee with the innovation, performance, and trust of Intel, this vision becomes a reality.

As we rely on technology to enhance our everyday and business life, we must too consider the security of the intellectual property and confidential data that is housed on these devices. As we increase the number of devices we use, we increase the number of gateways and opportunity for security threats. Intel Security takes the “security connected” approach to ensure that every device is secure, and that all security solutions are seamlessly integrated.
Featured Writers
White Papers
Cartoon
Current Issue
Dark Reading's October Tech Digest
Fast data analysis can stymie attacks and strengthen enterprise security. Does your team have the data smarts?
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-2021
Published: 2014-10-24
Cross-site scripting (XSS) vulnerability in admincp/apilog.php in vBulletin 4.4.2 and earlier, and 5.0.x through 5.0.5 allows remote authenticated users to inject arbitrary web script or HTML via a crafted XMLRPC API request, as demonstrated using the client name.

CVE-2014-3604
Published: 2014-10-24
Certificates.java in Not Yet Commons SSL before 0.3.15 does not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

CVE-2014-6230
Published: 2014-10-24
WP-Ban plugin before 1.6.4 for WordPress, when running in certain configurations, allows remote attackers to bypass the IP blacklist via a crafted X-Forwarded-For header.

CVE-2014-6251
Published: 2014-10-24
Stack-based buffer overflow in CPUMiner before 2.4.1 allows remote attackers to have an unspecified impact by sending a mining.subscribe response with a large nonce2 length, then triggering the overflow with a mining.notify request.

CVE-2014-7180
Published: 2014-10-24
Electric Cloud ElectricCommander before 4.2.6 and 5.x before 5.0.3 uses world-writable permissions for (1) eccert.pl and (2) ecconfigure.pl, which allows local users to execute arbitrary Perl code by modifying these files.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Follow Dark Reading editors into the field as they talk with noted experts from the security world.