Japanese energy, oil/gas, and transportation industries the target of stealthy, patient cyber-espionage group.

Sara Peters, Senior Editor

February 23, 2016

2 Min Read

A threat group that has attacked a variety of targets including US defense agencies since 2010, has recently zeroed in all efforts on Japanese critical infrastructure. Though they have not yet been "destructive or disruptive," the cyber espionage group has been quietly, persistently lurking within Japan's power, oil/gas, construction, finance, and transportation industries, according to researchers at the Cylance SPEAR Team.

Dubbed Operation Dust Storm by researchers, the attackers' tools of choice are mostly second-stage backdoors and their activities are related to current events. In 2011, early in the group's evolution, they targeted the US defense sector by using phishing lures related to the death of Libyan Prime Minister Muammar Gaddafi. More recently, in 2015, group compromised investment arm of a Japanese automaker, implanting a second-stage backdoor (via an existing backdoor) two weeks before 11 Japanese autoworker unions demanded a monthly raise of 6,000 yen.

Their goals thusfar appear to be reconaissance and long-term espionage. "At this time, SPEAR does not believe the attacks were meant to be destructive or disruptive," according to the report. "However, our team believes that attacks of this nature on companies involved in Japanese critical infrastructure and resources are ongoing and are likely to continue to escalate in the future."

The group has managed to maintain persistence and stay under the radar, by registering new domain names, taking advantage of dynamic DNS, and using a variety of customized backdoors -- particularly second-stage backdoors with hard-coded proxy addresses and credentials, as well as Android backdoors. Their mobile malware initially only forwarded SMS and call data to command-and-control servers, then added the ability to enumerate and exfiltrate specific files from devices. Those efforts to stay ahead of security tools have been largely successful.

According to the report: "No antivirus vendors seem to reliably detect most of the variants SPEAR identified."

 

About the Author(s)

Sara Peters

Senior Editor

Sara Peters is Senior Editor at Dark Reading and formerly the editor-in-chief of Enterprise Efficiency. Prior that she was senior editor for the Computer Security Institute, writing and speaking about virtualization, identity management, cybersecurity law, and a myriad of other topics. She authored the 2009 CSI Computer Crime and Security Survey and founded the CSI Working Group on Web Security Research Law -- a collaborative project that investigated the dichotomy between laws regulating software vulnerability disclosure and those regulating Web vulnerability disclosure.


Keep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox.

You May Also Like


More Insights