Attacks/Breaches
3/6/2014
06:03 PM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

Oil & Gas Firms Targeted In Web Server Hacks

'STTEAM' group also attacking Middle East state government sites, General Dynamics Fidelis says

A group of hackers who goes by the handle "STTEAM" has hit about a half-dozen oil and gas and government agencies in the Middle East using a mix of hacktivist, nation-state, and pure cybercrime techniques.

Researchers at General Dynamics Fidelis discovered the attacks, where the attackers ultimately wrest control of the organizations' website servers and use Trojan backdoors to hack into other systems within the victim organization.

Jim Jaeger, chief cyber services strategist for General Dynamics Fidelis Cybersecurity Solutions, says the latest twist to the attacks is that there are more victims, including Middle Eastern government agencies. "It appears to target those organizations and to gain access to their Web servers, and then move laterally with backdoors," he says.

The attackers leave a calling card on the sites, with an Anonymous icon and the message "Hacked by STTEAM," as well as Arabic language text and a note threatening oil and gas ministries. Jaeger says it appears the hacktivist defacement is more of a false flag to hide the attackers' infiltration of the victims' network via the Web servers using two different Trojan backdoors.

It doesn't appear to be a nation-state group, he says, because he malware doesn't indicate that. "It's probably criminals trying to get information that they could sell," he says. "We don't see nation-state footprints."

One backdoor contains Turkish words and is able to grab system information, connect to SQL databases, list tables and execute commands, browse directories, and move and copy files and folders or delete them, although there has been no proof thus far of data destruction by the attacks.

A second backdoor is able to do the same as the first, but also can add users to the system, add a user to the administrator group, disable a Windows firewall, enable RDP, delete IIS logs, and run Netcat as a reverse backdoor shell.

Just where the attackers come from is difficult to discern because they use an anonymous tunnel, Jaeger says. Fidelis has contacted the victim organizations, one of which the company has been working with. "We're seeing this pick-up of activity in the Middle East," he says.

The full report on the STTEAM attacks is available here for download.

Have a comment on this story? Please click "Add Your Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message.

Kelly Jackson Higgins is Executive Editor at DarkReading.com. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-7441
Published: 2015-05-29
The modern style negotiation in Network Block Device (nbd-server) 2.9.22 through 3.3 allows remote attackers to cause a denial of service (root process termination) by (1) closing the connection during negotiation or (2) specifying a name for a non-existent export.

CVE-2014-9727
Published: 2015-05-29
AVM Fritz!Box allows remote attackers to execute arbitrary commands via shell metacharacters in the var:lang parameter to cgi-bin/webcm.

CVE-2015-0200
Published: 2015-05-29
IBM WebSphere Commerce 6.x through 6.0.0.11 and 7.x before 7.0.0.8 IF2 allows local users to obtain sensitive database information via unspecified vectors.

CVE-2015-0751
Published: 2015-05-29
Cisco IP Phone 7861, when firmware from Cisco Unified Communications Manager 10.3(1) is used, allows remote attackers to cause a denial of service via crafted packets, aka Bug ID CSCus81800.

CVE-2015-0752
Published: 2015-05-29
Cross-site scripting (XSS) vulnerability in Cisco TelePresence Video Communication Server (VCS) X8.5.1 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCut27635.

Dark Reading Radio
Archived Dark Reading Radio
After a serious cybersecurity incident, everyone will be looking to you for answers -- but you’ll never have complete information and you’ll never have enough time. So in those heated moments, when a business is on the brink of collapse, how will you and the rest of the board room executives respond?