The mystery of Malaysian Airlines flight MH370 , a Boeing 777-200 that has been missing since it flew from Kuala Lumpur to Beijing, ended with a statement from Malaysia's prime minister, who said the plane had crashed in a remote part of the southern Indian Ocean.
Cybercriminals are known to exploit major news or events, and this time they used the MH370 tragedy to trap innocent internet users.
This week, security researchers at FireEye have uncovered several ongoing phishing and malware attacks based on APT attackers.
According to researchers, the Chinese hacker group, called "admin @ 338", specializes in cyber espionage attacks and has sent multiple phishing emails about flight MH370 to government officials in the Asia-Pacific region, with an attachment related to the flight.
The attached file was actually malware (Poison Ivy RAT – remote access tool and WinHTTPHelper malware), to compromise the IT systems of government officials.
More technical details and various attacks are reported on the FireEye blog. If you receive an email or any social media message claiming to have information or news about Malaysian Airlines, do not click on any links or attachments.


