ICT Security-Sécurité PC et Internet
87.1K views | +0 today
Follow
ICT Security-Sécurité PC et Internet
ICT Security + Privacy + Piracy + Data Protection - Censorship - Des cours et infos gratuites sur la"Sécurité PC et Internet" pour usage non-commercial... (FR, EN+DE)...
Curated by Gust MEES
Your new post is loading...
Your new post is loading...
Scooped by Gust MEES
Scoop.it!

TR-10 - Red October / Sputnik malware - Recommendations

TR-10 - Red October / Sputnik malware - Recommendations | ICT Security-Sécurité PC et Internet | Scoop.it

Overview

Red October is a malware family, also named Sputnik, which was detected in October 2012 by Kaspersky. It was active since 2007, installations have been spotted around the globe and targets were diplomatic and governmental agencies. The malware usually was sent by email to selected people in the respective organizations.

 

As a cover, different office file formats have been used to transport the loader of the malware, using different exploits to drop the malicious content. After several stages of unpacking, the malware is running persistently on the computer and only when it successfully probes internet connectivity, it decrypts a separate file and starts to behave maliciously: it connects to a Command and Control server, awaiting new commands or downloading and executing specific malware modules.

 

Detection

 

Currently, the domains in this document are known to be used for Command and Control activity.

 

Any hit in your organisation's Proxy or DNS log files or firewall logs during the last 6 years indicate a compromised host in your organization.

 

Proactive measures

 

- Block access to below mentioned domains and IP addresses.

 

- Reactive measures

 

- Review log files, also those from backups regarding hits on the domains / IP addresses. In case of a hit, identify and isolate the machine by unplugging it from the network. CIRCL can assist with the analysis of memory and file system dumps.

 

Read more...

Gust MEES's insight:

Stay informed...

 

Philip Verghese 'Ariel's curator insight, January 18, 2013 1:31 AM

Overview

Red October is a malware family, also named Sputnik, which was detected in October 2012 by Kaspersky. It was active since 2007, installations have been spotted around the globe and targets were diplomatic and governmental agencies. The malware usually was sent by email to selected people in the respective organizations.

Scooped by Gust MEES
Scoop.it!

Octobre Rouge, le vol de données sensibles à l'échelle mondiale

Octobre Rouge, le vol de données sensibles à l'échelle mondiale | ICT Security-Sécurité PC et Internet | Scoop.it

Les chercheurs de Kaspersky ont mis le doigt sur un gigantesque réseau d’espionnage à l’échelle planétaire. Au sein d’une opération baptisée « Octobre Rouge », les attaquants s’en prennent à des cibles de très haute volée. Une opération d’une grande complexité et dont le degré de technicité rappelle Flame.


Gust MEES's insight:

Il ne faut pas sous-estimer... Il semble que ceux qui ont le meilleur savoir se trouvent du mauvais côté, peut être que les états devraient payer mieux ceux qui ont des ===> compétences <===  au-dessus de la moyenne???

 

 

No comment yet.
Scooped by Gust MEES
Scoop.it!

Protecting Against Attacks Similar to "Red October"

Protecting Against Attacks Similar to "Red October" | ICT Security-Sécurité PC et Internet | Scoop.it
F-Secure Security Labs brings you the latest online security news from around the world. Ensure that you are up-to-date with the latest online threats to guarantee your online wellbeing.
Gust MEES's insight:

A MUST read!!!

 

No comment yet.
Scooped by Gust MEES
Scoop.it!

Kaspersky uncovers Red October malware campaign targeting governments for the last 5 years

Kaspersky uncovers Red October malware campaign targeting governments for the last 5 years | ICT Security-Sécurité PC et Internet | Scoop.it
Kaspersky on Monday published an extensive report identifying and detailing a sophisticated espionage campaign pushing malware since May 2007. The spy operation targeted "several ...
Gust MEES's insight:

Kaspersky on Monday published an extensive report identifying and detailing a sophisticated espionage campaign pushing malware since May 2007. The spy operation targeted “several hundreds” of government and diplomatic organizations mainly in Eastern Europe (especially former USSR Republics) and Central Asia, but also in Western Europe and North America.


WOW! Already 5 years active before discovered...


No comment yet.