Global Cyber Espionage Campaign Monitors Actions, Steals Data, Adapts to Avoid Detection

April 13, 2015  Security Suite

A global cyber espionage campaign has been discovered by security vendor Check Point, which reports numerous large targets have been penetrated by a persistent attacker group with possible political ties in Lebanon.  According to Check Point, the highly targeted and well-managed malware quietly watches a network, steals data, and quickly adapts if it is detected by antivirus systems. This attack campaign, called Volatile Cedar, begins with a vulnerability scan of the target server. Once an exploitable vulnerability is located, it is used to inject a web shell code into the server. The web shell is then used by the attacker to control the victim’s server and is the means through which a custom-made trojan, called Explosive, is implanted. This Trojan allows the attackers to send commands, such as keylogging, clipboard logging, screenshots, run commands, etc., to its targets.

News of the Month

