Through websites related to defense issues
The cyberespionage group Sednit, known for past attacks on various organizations in Eastern Europe, recently began using a new exploit kit to spread malware, according to a report from ESET's Montreal labs.
The victims of the attack include a large financial institution in Poland. ESET discovered that the group uses domains similar to real websites, which focus on military, defense and international relations topics.
"Recently, there have been incidents where legitimate financial institution websites are being redirected to a special exploit kit. According to our research and based on information from the Google Security Team, we were able to prove that it is being used by the Sednit group. It is a new strategy for this group, which until now has relied mainly on spear-phishing emails," notes ESET researcher Joan Calvet.
ESET has specifically analyzed redirects to the exploit kit from websites belonging to a large financial institution in Poland. In the attack, the Sednit group misuses legitimate websites related to military and defense issues. During the attack, remotely administered malware with various malicious actions is installed on the system. “This may be indicative of an ongoing campaign against these specific sectors,” Calvet adds.
In recent years, exploit kits have become a commonly used method of spreading crimeware, i.e. malicious software that, through mass distribution, facilitates criminal purposes of financial fraud and computer abuse, for example, sending spam, collecting bitcoins, collecting personal data, and more. Since 2012, ESET has observed this strategy being used for espionage purposes as well as for attacks that have become known as “watering-hole attacks” or “strategic web compromises.”.
A watering-hole attack can be described as the redirection of websites that are most likely visited by members of specific organizations or industries that are targets.
Source: protothema.gr

