Breaking News

Noctua introduces NF-A12x25 G2 next-generation 120mm fan INNO3D DELIVERS HIGH PERFORMANCE FOR LESS WITH THE NEW GEFORCE RTX 5050 CORSAIR Unveils RS-R Fans with Reverse Rotors for Unobstructed RGB Lighting ATP Electronics 11K Cycles PCIe Gen 4x4 Industrial SSDs TerraMaster Launches F4 SSD

logo

  • Share Us
    • Facebook
    • Twitter
  • Home
  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map

Search form

Hackers Target Banks in the Middle East

Hackers Target Banks in the Middle East

Enterprise & IT May 23,2016 0

In the first week of May 2016, security research firm FireEye identified a wave of emails containing malicious attachments being sent to multiple banks in the Middle East region. The threat actors appear to be performing initial reconnaissance against would-be targets, and the attacks caught the researchers' attention since they were using unique scripts not commonly seen in crimeware campaigns.

The attackers sent multiple emails containing macro-enabled XLS files to employees working in the banking sector in the Middle East. The themes of the messages used in the attacks are related to IT Infrastructure such as a log of Server Status Report or a list of Cisco Iron Port Appliance details. In one case, the content of the email appeared to be a legitimate email conversation between several employees, even containing contact details of employees from several banks. This email was then forwarded to several people, with the malicious Excel file attached.

One of the interesting techniques observed in this attack was the display of additional content after the macro executed successfully. This was done for the purpose of social engineering – specifically, to convince the victim that enabling the macro did in fact result in the "unhiding" of additional spreadsheet data.

This malicious file is used to collect important information from the system, including the currently logged on user, the hostname, network configuration data, user and group accounts, local and domain administrator accounts, running processes, and other data, FireEye said.

Another interesting technique leveraged by this malware was the use of DNS queries as a data exfiltration channel. This was likely done because DNS is required for normal network operations. The DNS protocol is unlikely to be blocked (allowing free communications out of the network) and its use is unlikely to raise suspicion among network defenders.

The identity of the hackersis not known.

FireEye said Qatar National Bank was not one of the "several banks" in the Middle East where researchers had found the malware.

This attack also demonstrates that macro malware is effective even today. FireEye says that users can protect themselves from such attacks by disabling Office macros in their settings and also by being more vigilant when enabling macros (especially when prompted) in documents, even if such documents are from seemingly trusted sources.

Tags: Hacking
Previous Post
AMD, ARM, Huawei, IBM, Mellanox, Qualcomm, Xilinx Unite To Form CCIX Accelerator Consortium
Next Post
Google Showcases "Soli" Gesture Control Technology, Project Ara And Levi's Smart Jacket Coming Next Year

Related Posts

  • MSI has been hacked, be warned about where you download files

  • Hackers gain access to PS5 Debug Menu and show decrypted PS5 firmware files

  • HP Threat Research Shows Attackers Exploiting Zero‐Day Vulnerability Before Enterprises Can Patch

  • EA Gets hacked - 780GB of data and sourcecode stolen

  • European Supercomputers Researching Covid-19 Report Hacking Attacks

  • Microsoft Offers You $100,000 If You Can Hack the Linux-based Azure Sphere

  • Zoom Users' Data have Been on Sale on Dark Web: report

  • Indonesia's Tokopedia Inverstigates Alleged Data Leak of 91 Million Users

Latest News

Noctua introduces NF-A12x25 G2 next-generation 120mm fan
Cooling Systems

Noctua introduces NF-A12x25 G2 next-generation 120mm fan

INNO3D DELIVERS HIGH PERFORMANCE FOR LESS  WITH THE NEW GEFORCE RTX 5050
GPUs

INNO3D DELIVERS HIGH PERFORMANCE FOR LESS WITH THE NEW GEFORCE RTX 5050

CORSAIR Unveils RS-R Fans with Reverse Rotors for Unobstructed RGB Lighting
Cooling Systems

CORSAIR Unveils RS-R Fans with Reverse Rotors for Unobstructed RGB Lighting

ATP Electronics 11K Cycles PCIe Gen 4x4 Industrial SSDs
Enterprise & IT

ATP Electronics 11K Cycles PCIe Gen 4x4 Industrial SSDs

TerraMaster Launches F4 SSD
Enterprise & IT

TerraMaster Launches F4 SSD

Popular Reviews

be quiet! Light Loop 360mm

be quiet! Light Loop 360mm

be quiet! Dark Mount Keyboard

be quiet! Dark Mount Keyboard

Arctic Liquid Freezer III 420 - 360

Arctic Liquid Freezer III 420 - 360

be quiet! Light Mount Keyboard

be quiet! Light Mount Keyboard

Soundpeats Pop Clip

Soundpeats Pop Clip

Crucial T705 2TB NVME White

Crucial T705 2TB NVME White

Noctua NH-D15 G2

Noctua NH-D15 G2

be quiet! Light Base 600 LX

be quiet! Light Base 600 LX

Main menu

  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map
  • About
  • Privacy
  • Contact Us
  • Promotional Opportunities @ CdrInfo.com
  • Advertise on out site
  • Submit your News to our site
  • RSS Feed