Kaspersky Lab: With actions ranging from creating spy infrastructure within a country's borders for real-time connections and data mining, to creating spy tools with 48 commands, the Naikon threat actor has successfully infiltrated national organizations in countries in the South China Sea region over the past five years, according to research by Kaspersky Lab.
Kaspersky Lab experts discovered that the Naikon group attackers appear to be of Chinese origin and that their primary targets are top government agencies, as well as political and military organizations in countries such as the Philippines, Malaysia, Cambodia, Indonesia, Vietnam, Myanmar, Singapore, Nepal, Thailand, Laos, and China.
Kaspersky Lab identified the following characteristics in Naikon's operations:
- At least five-year aggressive activity with geopolitical goals, which manifested with high intensity and against significant organizations
- Each target country has a predetermined administrator, who exploits elements from the local culture, such as the tendency to use personal email accounts for work.
- The deployment of infrastructure (a proxy server) within the country's borders aims to provide daily support for real-time connections and for data exfiltration.
- Use of code that was not affected by specific platforms and the ability to monitor and intervene in the entire network traffic overall.
- 48 commands in the remote management program's repository, including commands for full inventory, data retrieval and transmission, installation of add-on functions, or working on the command line.
The Naikon cyber espionage threat actor was first mentioned by Kaspersky Lab in its recent report, titled “The Hellsing APT Chronicles: The Empire Strikes Back,”where the actor played a pivotal role in a unique story of counterattack and revenge in the world of Advanced Persistent Threats (APTs). The Hellsing group is another threat actor that decided to take revenge when it was attacked by the Naikon group.
“The criminals behind the Naikon attacks managed to devise a very flexible infrastructure that could be set up in each target country, successfully funneling information from the victim systems to the command center. With this infrastructure, if the attackers decided to go after another target in another country, they could simply create a new connection. The Naikon was also facilitated by the existence of administrators dedicated to their own specific set of targets,” said Kurt Baumgartner, Principal Security Research at Kaspersky Lab’s Global Research and Analysis Team.
The targets of Naikon are being attacked using traditional spear‑phishing techniques, via email that carry attachments designed to match the interests of the potential victim. The attachments could look, for example, like a Word document, but in reality were executable files with double extensions.
Kaspersky Lab urges organizations to protect themselves from the Naikon espionage campaign by following some basic guidelines:
- Do not open attached files and links from senders they do not know
- Να χρησιμοποιούν μια προηγμένηanti-malware λύση
- Αν υπάρχουν αμφιβολίες για ένα συνημμένο αρχείο, καλύτερα το άνοιγμα του να γίνετε σε ένα περιβάλλον sandbox
- Να βεβαιωθούν ότι διαθέτουν ενημερωμένο λειτουργικό σύστημα, με όλα τα απαραίτητα patches εγκατεστημένα
Οι λύσεις της Kaspersky Lab προστατεύουν τους χρήστες από την απειλή αυτή, εντοπίζοντας την με τη λειτουργία “Automatic Exploit Prevention”. Η απειλή έχει καταχωρηθεί με τις κωδικές ονομασίες “Exploit.MSWord.CVE-2012-0158”, “Exploit.MSWord.Agent”, “Backdoor.Win32.MsnMM”, “Trojan.Win32.Agent”και“Backdoor.Win32.Agent”.
More information about the Naikon company is available on the Securelist.com.
