Incidents

New runner in Horse Race

Some interesting developments in the Operation Horse Race story, which we wrote about in our news section a couple of days ago.

A security company named 2bSecure originally located the Trojan code. The police asked them not to share the Trojan sample with antivirus companies in order to avoid alerting the offenders. However, now that they have been arrested and evidence is being collected, 2bSecure intend to publish the code of the Trojan on their website.

The company also plans to publish a disinfection tool along with the code to help victims remove the Trojan from their computer. 2bSecure believes that making the Trojan code publicly available will serve a similar purpose, by helping victims to identify infected systems and to evaluate the damage.

The full disclosure concept is nothing new, and in the past, other so-called security companies have published Trojan and virus code in order to “help” users deal with them.

In this case, given that a disinfection tool will be available, I think publishing the source or the Trojan code is redundant and, in my opinion, irresponsible. In the past, whenever a piece of malware has been made available on the Internet, it basically opened the door to countless modifications, hacks, or patched variants. We’ve seen this happen in the past with other bots where the source has been widely distributed – Agobot and SdBot are the first that come to mind, with over 800 variants in each family!

Sure, there will be researchers who will benefit from access to the Trojan – they’ll be able to analyse its behaviour and develop protection against it. However, the damage which will be inflicted on the Internet community by the potential multitude of new variants will far outweigh any positive effects.

New runner in Horse Race

Your email address will not be published. Required fields are marked *

 

Reports

APT trends report Q2 2021

This is our latest summary of advanced persistent threat (APT) activity, focusing on significant events that we observed during Q2 2021: attacks against Microsoft Exchange servers, APT29 and APT31 activities, targeting campaigns, etc.

LuminousMoth APT: Sweeping attacks for the chosen few

We recently came across unusual APT activity that was detected in high volumes, albeit most likely aimed at a few targets of interest. Further analysis revealed that the actor, which we dubbed LuminousMoth, shows an affinity to the HoneyMyte group, otherwise known as Mustang Panda.

WildPressure targets the macOS platform

We found new malware samples used in WildPressure campaigns: newer version of the C++ Milum Trojan, a corresponding VBScript variant with the same version number, and a Python script working on both Windows and macOS.

Ferocious Kitten: 6 years of covert surveillance in Iran

Ferocious Kitten is an APT group that has been targeting Persian-speaking individuals in Iran. Some of the TTPs used by this threat actor are reminiscent of other groups, such as Domestic Kitten and Rampant Kitten. In this report we aim to provide more details on these findings.

Subscribe to our weekly e-mails

The hottest research right in your inbox