Kaspersky Lab: Cyber War between hacker groups in Asia
Kaspersky Lab has identified a rare and unusual case of one cybercriminal attacking another. In 2014, Hellsing, a small and moderately technical cyberespionage group that primarily targeted governments and diplomatic organizations in Asia, was spearphished by another online threat actor and decided to strike back.
Kaspersky Lab believes this could signal the emergence of a new trend in digital crime: “APT wars.”
The discovery was made by Kaspersky Lab experts as part of an investigation into the activity of Naikon, a cyber espionage group also operating in the Asia-Pacific region. The experts noted that one of the targets had detected that the Naikon group had attempted to infect his systems via a spearphishing email that carried a malicious attachment.
The target questioned the authenticity of the email to the sender and, apparently dissatisfied with the response he received, did not open the attached file. Shortly afterwards, the target forwarded the sender an email containing the target’s own malware. This action triggered Kaspersky Lab’s investigation and led to the discovery of the Hellsing Advanced Persistent Threat (APT) group.
The method of the counterattack shows that the Hellsing team wanted to identify the Naikon team and gather information about it.
Moving into a deeper analysis of the Hellsing vector, Kaspersky Lab discovered a series of spearphishing emails with malicious attachments, which were designed to spread spyware to various organizations. If the victim opens the malicious attachment, their system is infected with a custom backdoor, which can download and upload files, update itself, and uninstall itself. According to Kaspersky Lab’s observations, the number of organizations targeted by Hellsing approached 20.
Kaspersky Lab has detected and blocked Hellsing malware in Malaysia, the Philippines, India, Indonesia and the US, with the majority of victims in Malaysia and the Philippines. The attackers are also very selective in the type of organizations they target, seeking to infect primarily government and diplomatic targets.
“The fact that the Hellsing group targeted the Naikon group can be described as a kind of revenge vampire hunt. This in itself makes the attack fascinating for researchers. In the past, we have seen some APT groups accidentally attack each other, stealing address books from victims and then sending mass mailings to everyone on those lists. However, considering the targeting and origin of the attack, it seems more likely that this is an example of a deliberate attack by one APT group on another,” said Costin Raiu, Director of the Research and Analysis Group at Kaspersky Lab.
According to Kaspersky Lab's analysis, the Hellsing threat actor has been – and remains – active since at least 2012.
To protect against Hellsing attacks, Kaspersky Lab recommends the following basic security best practices:
-Do not open suspicious attachments from senders you do not know.
-Be careful with password-protected files that contain SCR files or other executable files.
-If you are unsure about the attached file, try opening it in a sandbox.
-Make sure you have an updated operating system, with all necessary patches installed.
-Update all third-party applications, such as Microsoft Office, Java, Adobe Flash Player, and Adobe Reader.
Source: defencenet.gr


