HomeSecurity"Desert Hawks": Arab digital espionage group

"Desert Hawks": Arab digital espionage group

arab hacking groupKaspersky Lab's Global Research and Analysis Team exposes the Arab Desert Falcons group and its activities, a digital espionage targeting multiple high-profile organizations and individuals from Middle Eastern countries.

Below is information from Kaspersky Lab's announcement regarding the discovery and pursuit of the Arab digital espionage group Desert Falcons:

Kaspersky Lab experts consider this organization to be the first known Arab group of “digital mercenaries” who have developed and carried out comprehensive digital espionage operations.

  • The campaign has been active for at least two years. The Arab Desert Falcons group began to develop and establish its operations in 2011. However, the start of the group's main activity and malware infections is placed in 2013. The peak of activity for the Arab group is recorded in early 2015.
  • The vast majority of targets are located in Egypt, Palestine, Israel and Jordan.
  • In addition to the Middle Eastern countries, which were the initial targets, the Arab group Desert Falcons is also active outside of this region. In total, its members have managed to attack more than 3,000 victims, in more than 50 countries worldwide, having stolen over 1 million files.
  • Attackers are using malicious tools they have developed themselves to launch attacks on Windows computers and Android devices.
  • Kaspersky Lab experts have many reasons to believe that the native language of the Desert Falcons team members is Arabic.

The list of victims targeted includes military and government organizations – and in particular, officials tasked with combating money laundering. The campaign also targeted executives from the healthcare and financial sectors, leading media outlets, research and educational institutions, energy and utility providers, activists and political leaders, personal security companies, and other targets holding sensitive geopolitical information.

In total, Kaspersky Lab experts were able to detect signs of attacks on over 3,000 victims in more than 50 countries, detecting the interception of over one million files. Although the attacker appears to be operating in countries such as Egypt, Palestine, Israel and Jordan, many victims were also found in Qatar, Saudi Arabia, the United Arab Emirates, Algeria, Lebanon, Norway, Turkey, Sweden, France, the United States, Russia and other countries.

The main method used by the Arab group Desert Falcons to deliver malicious payloads was spearphishing via email, social media messages, and chat messages. The phishing messages contained malicious files (or links leading to malicious files) that mimicked legitimate documents or applications. The Desert Falcons group uses various techniques to lure its victims into executing the malicious files. One of the most characteristic techniques used by the group is the so-called “Right-to-Left Override”.

This technique exploits a special Unicode character to reverse the order of characters in a file name, hiding a malicious extension in the middle of the name and placing a fake, seemingly harmless file extension near the end of the file name. Using this technique, malicious files (.exe, .scr) look like a harmless document or PDF file, while even careful users with good technical knowledge can be tricked into running these files. For example, a file ending in “.fdp.scr” would appear as “.rcs.pdf.”.

After successfully infecting the victim, members of the Arab Desert Falcons group use one of two different backdoors, either their main Trojan or the DHS Backdoor, which appear to have been developed from scratch and are in constant development. Kaspersky Lab experts were able to identify over 100 malware samples used by this group for attacks.

The malicious tools used have full Backdoor functionality. Thus, they can take screenshots, intercept keystrokes, upload or download files, collect information about all Word and Excel files on a victim's hard drive or connected USB devices, intercept passwords stored in the system registry (Internet Explorer and Live Messenger), and make audio recordings. Kaspersky Lab experts also managed to detect traces of the activity of a malware, which appears to be a backdoor for Android, with call and SMS logging capabilities.

Using these tools, members from the Arab group Desert Falcons created and managed at least three different malicious campaigns, targeting different victims in different countries.

Kaspersky Lab researchers estimate that at least 30 individuals, in three groups, spread across different countries, are carrying out the malware campaigns related to the Arab group Desert Falcons.

“The individuals behind this group are extremely determined, proactive, technically savvy, and well-informed about political and cultural issues. Using only phishing emails, social engineering techniques, tools, and backdoors they developed themselves, members of the Arab Desert Falcons were able to “infect” hundreds of high-profile victims in the Middle East region via their computers or mobile devices, as well as decrypt sensitive data. We expect that this campaign will continue to develop more Trojans and use even more sophisticated techniques. With sufficient funding, they could acquire or develop exploits, which could increase the effectiveness of their attacks,” said Dmitry Bestuzhev, a security expert and member of Kaspersky Lab’s Global Research and Analysis Team.

Kaspersky Lab, which provides the data presented in this article, claims that its products successfully detect and block the malware used by the Arab group Desert Falcons.

More information about the campaign is available at Securelist.com.

 

Source: gr.pcmag.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS