• Latest
  • Trending
Advanced hacking groups debuts new malware

Advanced hacking groups debuts new malware

November 9, 2019
Hockey: Portland NHL pulling faulty pucks

Hockey: Portland NHL pulling faulty pucks

January 21, 2021
U.S. attack on the Capitol: The “Bud Light Putsch”, a watershed moment for America?

Portland Police Charge Demonstrators Destroy Democratic Party Offices

January 21, 2021
U.S. attack on the Capitol: The “Bud Light Putsch”, a watershed moment for America?

U.S. attack on the Capitol: The “Bud Light Putsch”, a watershed moment for America?

January 18, 2021
How Israel’s Likud Party played the long game toward annexation of the West Bank

How Israel’s Likud Party played the long game toward annexation of the West Bank

January 11, 2021
How the Capitol riot exposed our national security blind spots

How the Capitol riot exposed our national security blind spots

January 11, 2021
‘Good riddance,’ says China as Germany leaves UN Security Council

‘Good riddance,’ says China as Germany leaves UN Security Council

December 23, 2020
Indonesian police needs reforms, urgently & not just in Papua

Indonesian police needs reforms, urgently & not just in Papua

December 13, 2020
Chinese honey trap operation?

Chinese honey trap operation?

December 11, 2020
Bali’s villa dream or just another nightmare?

Bali’s villa dream or just another nightmare?

December 5, 2020
When the going gets tough, the tough gets Ramen!

When the going gets tough, the tough gets Ramen!

November 28, 2020
Giuliani attends Pennsylvania GOP meeting on alleged election issues

Giuliani attends Pennsylvania GOP meeting on alleged election issues

November 28, 2020
Biden: ‘They are back’ !

Biden: ‘They are back’ !

November 28, 2020
citizendaily
  • Asia News
    • Northeast Asia
      • China
      • Japan
    • North Korea
    • Oceania
      • Australia
      • New Zealand
    • South Asia
      • Afghanistan
      • Bangladesh
      • India
      • Pakistan
    • Southeast Asia
      • Indonesia
      • Malaysia
      • Philippines
      • Singapore
      • Thailand
  • World News
    • Africa
    • Europe
      • Germany
      • United Kingdom
    • Latin America
      • Cuba
      • Mexico
    • Middle East
      • Gulf States
      • Iran
      • Iraq
      • Saudi Arabia
      • Syria
    • North America
      • Canada
      • United States
    • Russian Federation
  • Economy
    • Brexit
    • Free Market
  • Politics
    • ASEAN
    • Diplomacy
    • ISIS
    • National Defence & Security
  • Editorial
  • Environment
    • Climate Change
    • Forests
    • Water & Oceans
    • Wildlife & Endangered Species
  • Lifestyle
    • Books & Literature
    • Entertainment
    • Food & Dining
    • Religion
    • Travel
    • Tech
  • Sports
No Result
View All Result
Monday, January 25, 2021
  • Asia News
    • Northeast Asia
      • China
      • Japan
    • North Korea
    • Oceania
      • Australia
      • New Zealand
    • South Asia
      • Afghanistan
      • Bangladesh
      • India
      • Pakistan
    • Southeast Asia
      • Indonesia
      • Malaysia
      • Philippines
      • Singapore
      • Thailand
  • World News
    • Africa
    • Europe
      • Germany
      • United Kingdom
    • Latin America
      • Cuba
      • Mexico
    • Middle East
      • Gulf States
      • Iran
      • Iraq
      • Saudi Arabia
      • Syria
    • North America
      • Canada
      • United States
    • Russian Federation
  • Economy
    • Brexit
    • Free Market
  • Politics
    • ASEAN
    • Diplomacy
    • ISIS
    • National Defence & Security
  • Editorial
  • Environment
    • Climate Change
    • Forests
    • Water & Oceans
    • Wildlife & Endangered Species
  • Lifestyle
    • Books & Literature
    • Entertainment
    • Food & Dining
    • Religion
    • Travel
    • Tech
  • Sports
No Result
View All Result
citizendaily
No Result
View All Result

Advanced hacking groups debuts new malware

Malware hides at every step by mimicking common software in long multi-stage execution

November 9, 2019
in Featured, News, Science & Technology, World News
0
Home Featured
Post Views: 19

 

One of the world’s most most technologically advanced hacking groups has a new backdoor that’s every bit as sophisticated as its creators.

Dubbed Titanium by the Kaspersky Lab security researchers who discovered it, the malware is the final payload delivered in a long and convoluted attack sequence. The attack chain uses a host of clever tricks to evade antivirus protection. Those tricks include encryption, mimicking of common device drivers and software, memory-only infections, and a series of droppers that execute the malicious code a multi-staged sequence. Yet another means of staying under the radar is hidden data delivered steganographically in a PNG image.

Named after a password used to encrypt a malicious archive, Titanium was developed by Platinum, a so-called advanced persistent threat group that focuses hacks on the Asia-Pacific region, most likely on behalf of a nation.

RelatedPosts

Cyberattack Sweeps Globe, Researchers See ‘WannaCry’ Link

“The Titanium APT has a very complicated infiltration scheme,” Kaspersky Lab researchers wrote in a post. “It involves numerous steps and requires good coordination between all of them. In addition, none of the files in the file system can be detected as malicious due to the use of encryption and fileless technologies. One other feature that makes detection harder is the mimicking of well-known software.”

Titanium uses several different methods to initially infect its targets and spread from computer to computer. One is a local intranet that has already been compromised with malware. Another vector is an SFX archive containing a Windows installation task. A third is shellcode that gets injected into the winlogon.exe process (it’s still unknown how this happens). The end result is a stealthy and full-featured back door that can:

  • Read any file from a file system and send it to an attacker-controlled server
  • Drop a file onto or delete it from the file system
  • Drop a file and run it
  • Run a command line and send execution results to the attacker’s control server
  • Update configuration parameters (except the AES encryption key)

Platinum has been operating since at least 2009, according to a detailed report Microsoft published in 2016. The group is primarily focused on the theft of sensitive intellectual property related to government interests. Platinum often relies on spear phishing and zero-day exploits.

Interestingly, Kaspersky Lab says it has yet to detect any current activity related to Titanium. It’s not clear if that’s because the malware isn’t in use or if it’s just too hard to detect infected computers.

 

Source: ArsTechnica
Tags: Computer VirusKaspersky LabPlatinum Hacker GroupPlatinum MalwareTitanium Malware
Previous Post

Questioning the urgency of Deputy Commander of Indonesian National Army

Next Post

Foreigners who join Hong Kong protests say they’re not interfering, just ‘showing solidarity’

Related Posts

Hockey: Portland NHL pulling faulty pucks
Canada

Hockey: Portland NHL pulling faulty pucks

January 21, 2021
U.S. attack on the Capitol: The “Bud Light Putsch”, a watershed moment for America?
Asia News

Portland Police Charge Demonstrators Destroy Democratic Party Offices

January 21, 2021
How Israel’s Likud Party played the long game toward annexation of the West Bank
Commentary

How Israel’s Likud Party played the long game toward annexation of the West Bank

January 11, 2021
How the Capitol riot exposed our national security blind spots
Bilateral

How the Capitol riot exposed our national security blind spots

January 11, 2021
‘Good riddance,’ says China as Germany leaves UN Security Council
Asia News

‘Good riddance,’ says China as Germany leaves UN Security Council

December 23, 2020
Indonesian police needs reforms, urgently & not just in Papua
ASEAN

Indonesian police needs reforms, urgently & not just in Papua

December 13, 2020
Next Post
Foreigners who join Hong Kong protests say they’re not interfering, just ‘showing solidarity’

Foreigners who join Hong Kong protests say they’re not interfering, just ‘showing solidarity'

Translate

Subscription

Popular Post

Hockey: Portland NHL pulling faulty pucks
Canada

Hockey: Portland NHL pulling faulty pucks

January 21, 2021
0

  Portland (21/1-50).   For once technology got defeated. ESPN reported that the National Hockey League (NHL) announced that it will...

Read more

NGOs call for mass boycott of palm oil giant IOI

June 29, 2016
No peace for Greenpeace

No peace for Greenpeace

July 1, 2016

The Case Against Greenpeace

July 1, 2016
Children in ISIS Nusantara Media Outreach

Children in ISIS Nusantara Media Outreach

July 2, 2016
  • About Us
  • Creative Commons
  • Privacy Policy
  • Terms & Conditions
  • Disclaimer
  • Contact Us

Topics

Follow Us

About Us

citizendaily.news is part of the citizen Daily Media Group LLC, which delivers daily news around the globe. ​

© 2012 The Citizen Daily

No Result
View All Result
  • Asia News
    • Northeast Asia
      • China
      • Japan
    • North Korea
    • Oceania
      • Australia
      • New Zealand
    • South Asia
      • Afghanistan
      • Bangladesh
      • India
      • Pakistan
    • Southeast Asia
      • Indonesia
      • Malaysia
      • Philippines
      • Singapore
      • Thailand
  • World News
    • Africa
    • Europe
      • Germany
      • United Kingdom
    • Latin America
      • Cuba
      • Mexico
    • Middle East
      • Gulf States
      • Iran
      • Iraq
      • Saudi Arabia
      • Syria
    • North America
      • Canada
      • United States
    • Russian Federation
  • Economy
    • Brexit
    • Free Market
  • Politics
    • ASEAN
    • Diplomacy
    • ISIS
    • National Defence & Security
  • Editorial
  • Environment
    • Climate Change
    • Forests
    • Water & Oceans
    • Wildlife & Endangered Species
  • Lifestyle
    • Books & Literature
    • Entertainment
    • Food & Dining
    • Religion
    • Travel
    • Tech
  • Sports

© 2012 The Citizen Daily