Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 83 guests and 1 member online
EH-Net News Feeds
Latest Additions
 
Advertisement

You are here: Home arrow Forum arrow Resourcesarrow News from the Outside Worldarrow Stealing data from ~50 companies with PoisonIvy trojan?!
EH-Net
May 26, 2012, 10:55:06 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Advertise on EH-Net!! - Reasonable Rates, Highly Targeted Audience.
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Stealing data from ~50 companies with PoisonIvy trojan?!  (Read 2284 times)
0 Members and 2 Guests are viewing this topic.
p0et
Full Member
***
Offline Offline

Posts: 197



View Profile
« on: November 01, 2011, 09:32:49 PM »

Talk about an old trojan...  Can't believe this easily detected old trojan got through all of the ~50 companies defenses (if they had any)

http://www.eweek.com/c/a/Security/Nitro-CyberSpying-Campaign-Stole-Data-From-Chemical-Defense-Companies-863610/
Logged

GCIH, Security+, Network+, A+, MCP, DCSE
pseud0
Recruiters
Full Member
*
Offline Offline

Posts: 204



View Profile
« Reply #1 on: November 02, 2011, 04:17:04 AM »

I'll comment on it since I spent the better part of 4 months working on the issue:

-First, Symantec's timeline is wrong.  I know of at least two very large chemical companies that were hit as early as August last year. Same MO.  Same emails. Same malware. Same targeted data.

-Second, yes, PoinsonIvy, but a highly modified one.  We recovered original versions of it and it was modified enough from the original form that AV and IDS didn't pick it up. VirusTotal only had 2 products that flagged it.  It was also VM aware as we couldn't get the emails to dump the payload in our vmworkstations.  We actually had to have the client put one of their images on a laptop in order to get the malware samples.

-Third, the attackers were persistent.  Every time they were pushed out of the environment they'd use information they'd gathered to find a new way back in.  Note to admins: don't be cute and use the same password for web apps and remote access as you do for AD and systems. 
Logged

CISSP, CISM, CISA, GCIH, CEH, HMFIC, KTHXBIROFLCOPTER
p0et
Full Member
***
Offline Offline

Posts: 197



View Profile
« Reply #2 on: November 02, 2011, 10:26:44 AM »

Whoa!  That's quite a bit more advanced than it initially reads (just mentioning the PoisonIvy rat).  Man, I'd love to get my hands on their modified version and have a look.  Sounds like they did a good job of modifying it.

I'm jealous.. I'd love to have your job if it involves working with issues such as this one!  Smiley
Logged

GCIH, Security+, Network+, A+, MCP, DCSE
pseud0
Recruiters
Full Member
*
Offline Offline

Posts: 204



View Profile
« Reply #3 on: November 02, 2011, 07:59:43 PM »

I've got a sample of it on a usb drive in the lab.  It has a ball of duct tape the size of a soft ball wrapped around the body of it with skulls drawn on it because every time someone wanted to move files they'd grab that drive every time. We'd have 50 usb drives sitting on the table and this one would be hidden under a box and still someone would find it and stick it in their laptop.
Logged

CISSP, CISM, CISA, GCIH, CEH, HMFIC, KTHXBIROFLCOPTER
eth3real
Sr. Member
****
Offline Offline

Posts: 295



View Profile WWW
« Reply #4 on: November 02, 2011, 08:36:12 PM »

I've heard about this. I believe this is the same attack that breached the RSA earlier this year.

http://blogs.rsa.com/rivner/anatomy-of-an-attack/
Logged

Put that in your pipe and grep it!
p0et
Full Member
***
Offline Offline

Posts: 197



View Profile
« Reply #5 on: November 02, 2011, 10:48:47 PM »

Wow!  I heard all about the RSA breach but I guess I forgot or didn't see that it was also Poison Ivy... man that trojan gets around.  Wink
Logged

GCIH, Security+, Network+, A+, MCP, DCSE
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.16 | SMF © 2011, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.063 seconds with 20 queries.
 

gk_static-ad_feb2012.jpg
Global Knowledge: Build Security Skills to Protect & Defend

els_130x200fixed2.gif
eLearnSecurity Student Course Now Live!
5% Off with Code
ELS-EH-5

SANS Deals 4 EH-Netters
$150 OFF Any SANS Course in Any Format!
Coupon Code: EHN_Connect Including SANS Security West 2012 & SANSFIRE 2012
Recent Forum Topics

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!

Vote For EH-Net

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2012 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.