On February 13, FireEye reported that hackers are actively exploiting Adobe Reader zero-days to distribute malware. Experts from Kaspersky and Hungarian security firm CrySyS Lab have found that the same zero-days are being used for very high-profile targets.
The researchers who discovered the threat named it MiniDuke due to its similarities to the well-known Duqu and it has been used by cybercriminals to hit 59 unique victims located in 23 countries around the world, including Brazil, Bulgaria, Georgia, Germany, Israel, Japan, Latvia, Lebanon, Lithuania, Montenegro, Russia and the United Kingdom.
In Ukraine, Belgium, Portugal, Romania, the Czech Republic and Ireland, the malware has been detected on the systems of government organizations. In Hungary, it has been detected on the networks of a social institution and in the United States, on the computers of think tanks, a research institute and a healthcare provider.
Kaspersky experts say that the large number of high-profile victims makes the malicious campaign stand out, similar to the infamous Red October.
The malware is spread through clever PDF documents that have topics related to NATO, Ukrainian foreign policy, or a human rights seminar.
Once someone opens the PDF, the malware uses an interesting communication technique. It has contacts from certain Twitter accounts that post encrypted strings containing a “uri!” (see image)
This encrypted identifier contains the login details to a command and control server (C&C server).
“Based on our experience, this is a unique and very strange attack. The many different targets hit in separate countries, combined with the choice of very high-profile targets, the decoy documents they use, and the strange backdoors, reveal a threat with completely unusual behaviors,” Kaspersky explains in a detailed report. (PDF)
“Some elements remind us of both Duqu and Red October, such as the minimalist approach, hacked servers, encrypted channels, and the typology of victims,” reports Softpedia.

