HomeSecurityPalmerworm hackers hid in corporate networks for months

Palmerworm hackers hid in corporate networks for months

Symantec said the attacks against organizations in the US, Japan, Taiwan and China are aimed at stealing information and have been linked to a spying group known as Palmerworm – also known as BlackTech – which has been operating since 2013.

Palmerworm hackers

In some cases, the Palmerworm group maintained its presence on compromised networks for a year or more, often with the help of tactics that exploit legitimate software and toolsso as not to raise suspicions that anything might be going wrong – and thus creating less evidence that can be used to trace the origin of the attack.

Researchers were unable to determine how hackers gained network access in this latest round of Palmerworm attacks, but previous campaigns had used the phear-phishing to compromise victims.

However, the malware's development is known to use custom loaders and network reconnaissance tools similar to previous campaigns , with researchers being "fairly confident" that the same group is behind these attacks.

The Palmerworm malware also uses stolen code signing certificates in its payloads to make them appear more legitimate. This tactic is also known to have been previously deployed by the group.

The malware provides attackers with a secret backdoor into the network, and access is maintained using several legitimate tools, including PSExec and SNScan, which are exploited to move across the network undetected. Meanwhile, WinRar is used to compress files, making it easier for attackers to extract from the network.

Symantec has not attributed Palmerworm to any specific location, but Taiwanese officials have previously claimed that the attacks could be linked to China. If that is the case, it suggests that Chinese hackers have targeted a Chinese company as part of the campaign.

However, what is certain is that the Palmerworm group is unlikely to stop operating and will remain a threat for many years to come.

While the nature of advanced hacking campaigns means they can be difficult to detect, organizations can protect themselves by having a clear picture of their network and knowledge of normal and unusual activity – and blocking suspicious activity if necessary.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS