HomeSecurityAdvanced version of NetTraveler malware detected

Advanced version of NetTraveler malware detected

Updated-NetTraveler-Backdoor-Has-Encrypted-Configuration-File

A new spear- phishing campaign has been detected by Kaspersky security researchers , which is designed to spread a new variant of the NetTraveler malware.

The malicious software, also known as “Travnet” or“Netfile,” has been active for at least ten years, as the first indications that reveal its activity date back to 2004.

Researchers have observed that the malware are Uyghur and Tibetan activists, while the victim profile has not changed in the recent campaign.

Analyzing an email sample from NetTraveler, researchers at Kaspersky, Costin Raiu and Kurt Baumgartner found that the targets' computers are infected via a malicious DOC file. The document contains an exploit for a Microsoft Word vulnerability, identified as CVE-2012-0158.

This particular vulnerability was reported in October 2012 and has since been patched, but many systems still run an older version of Word that is vulnerable to this flaw.

NetTraveler has been used in many cyber espionage campaigns, such as the Red October campaign.

“For the past 10 years NetTraveler has been targeting various sectors, with an emphasis on diplomatic, governmental and military targets”, says Kaspersky. 32% of the victims belong to the diplomatic sector, while 19% of them are linked to the government.

Finally, the researchers observed that the authors of the malware have used stronger encryption compared to earlier variants of the malicious software, but not complex enough to be unbypassable.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS