New spyware detected targeting firms in Russia, China: Symantec
- Top 10 News for 10/17 - 10/21: Merger Rumors Abound; CEOs Depart; Tesla Kicks Autopilot Up A Notch
- Wall Street ends little changed; Microsoft hits record
- AT&T (T) in Advanced Talks to Acquire Time Warner (TWX) - DJ
- Rockwell Automation (ROK) Said to Attract Takeover Interest from Schneider Electric - Source
- British American Tobacco Offers to Acquire Remaining Shares of Reynolds American (RAI) for $56.50/Share
A padlock is displayed at the Alert Logic booth during the 2016 Black Hat cyber-security conference in Las Vegas, Nevada, U.S. August 3, 2016. REUTERS/David Becker
News and research before you hear about it on CNBC and others. Claim your 2-week free trial to StreetInsider Premium here.
By Eric Auchard
FRANKFURT (Reuters) - A previously unknown hacking group variously dubbed "Strider" or "ProjectSauron" has carried out cyber-espionage attacks against select targets in Russia, China, Iran, Sweden, Belgium and Rwanda, security researchers said on Monday.
The group, which has been active since at least 2011 and could have links to a national intelligence agency, uses Remsec, an advanced piece of hidden malware, Symantec researchers said in a blog post (http://symc.ly/2aTHoOm).
Remsec spyware lives within an organization's network rather than being installed on individual computers, giving attackers complete control over infected machines, researchers said. It enables keystroke logging and the theft of files and other data.
Its code also contains references to Sauron, the all-seeing title character in The Lord of the Rings, Symantec said. Strider is the nickname of the fantasy trilogy's widely traveled main character Aragorn.
Separately, Moscow-based Kaspersky Lab has labeled the same group using the Remsec spyware as "ProjectSauron" (http://bit.ly/2b0YtqV).
The newly discovered group's targets include four organizations and individuals located in Russia, an airline in China, an organization in Sweden and an embassy in Belgium, Symantec said.
Kaspersky said it had found 30 organizations hit so far in Russia, Iran and Rwanda, and possibly additional victims in Italian-speaking countries. Remsec targets included government agencies, scientific research centers, military entities, telecoms providers and financial institutions, Kaspersky said.
"Based on the espionage capabilities of its malware and the nature of its known targets, it is possible that the group is a nation state-level attacker," Symantec said, but it did not speculate about which government might be behind the software.
Despite headlines that suggest an endless stream of new types of cyber-spying attacks, Orla Fox, Symantec’s director of security response said the discovery of a new class of spyware like Remsec is a relatively rare event, with the industry uncovering no more than one or two such campaigns per year.
Remsec shares certain unusual coding similarities with another older piece of nation state-grade malware known as Flamer, or Flame, according to Symantec.
Kaspersky agreed that the same group it calls ProjectSauron appears to have adopted the tools and techniques of other better-known spyware, including Flame, but said it does not believe that ProjectSauron and Flame are directly connected.
Flamer malware has been linked to Stuxnet, a military-grade computer virus alleged by security experts to have been used by the United States and Israel to attack Iran’s nuclear program late in the last decade (http://reut.rs/2b2FA8z).
(Corrects spelling of Kaspersky in seventh paragraph)
(Editing by Greg Mahlich)
Serious News for Serious Traders! Try StreetInsider.com Premium Free!
You May Also Be Interested In
- Midstates Petroleum (MPO) Completes Ch. 11 Bankruptcy; Will Trade Under 'MPO'
- Zimbabwe's Mugabe skirts retirement talk at burial of friend
- Two children killed in Georgia home invasion: police
Create E-mail Alert Related CategoriesCorporate News, Reuters
Sign up for StreetInsider Free!
Receive full access to all new and archived articles, unlimited portfolio tracking, e-mail alerts, custom newswires and RSS feeds - and more!