Support / Feedback
  • Edition:
  • Global
  • |
  • North America
  • |
  • Central & South America
  • |
  • UK & Ireland
  • |
  • Europe
  • |
  • Middle East & Africa
  • |
  • Australia & New Zealand
  • |
  • Asia
Over 137,000 Members
Login
Invalid Login
Username
Password

Forgot Password?

Register FREE
Over 137,000 Members
  • Groups
    • Interest Areas
    • Agent Zone
    • Association
    • Awards
    • Benchmarking
    • Best Practices
    • CRM
    • HR
    • Infrastructure
    •  
    • Legal
    • Outsourcing
    • Performance
    • Quality
    • Technology
    • Telecom
    • Training
    • Workforce Management
    • Industry Sector
    • Aerospace
    • Automotive
    • Banking / Finance / Credit
    • Charity / Not For Profit
    • Computer Hardware / Software
    • Government
    • Healthcare / Pharmaceutical
    • Insurance
    •  
    • Manufacturing
    • Retail
    • Service Industry
    • Travel / Transportation / Tourism
    • Utilities
  • Conferences & Events
    • Best Practice Conferences
    • Other Events
    Rosen Plaza Hotel. Orlando
    The best contact center practitioners from North & South America (AMERICAS) will be sharing their best practices and networking with delegates
    Hard Rock Hotel, Resorts World, Singapore
    The best contact center practitioners from all over Asia Pacific, Australia and New Zealand (APAC) will be sharing their best practices and networking with delegates
    Intercontinental Hotel, Vienna
    The best contact center practitioners from the entire region of Europe, Middle East & Africa (EMEA) will be sharing their best practices and networking with delegates
    Vdara Resort Las Vegas
    We invite award winners from around the World to share their best practices - these are the best from over 50+ nations who had to compete to earn a speaking spot! Learn from the best in the World 2013
  • Certification
    • Customer Satisfaction (For vendors)
    • TopPlace2Work
  • For Your Center
    • Global Benchmarking Study
    • Industry Solutions Directory
    • International Contact Center Week
    • Post your Jobs (free)
  • Awards
    • Best Practice Awards
    • 2012 Americas Winners
    • 2012 EMEA Winners
    • 2012 APAC Winners
    • 2012 GLOBAL Winners
    • Top Outsourcer
    • 2011 Winners
    • Industry Champion
    • 2011 Champions
    • 2010 Champions
    • Members' Choice Awards
    • Top Ranking Vendors
  • Tools & Utilities
    • Find a Career
    • Glossary
    • Link to Us
    • RSS Feeds
    • Sponsorship Opportunities
    • Submit Editorial
    • Forums/Discussions
    • Association Directory
    • Demo's and Tutorials
    • Feeds for Your Website

News : AlienVault Spots Weaponised Doc Files Targeting Apple Mac Users

AlienVault has discovered a family of weaponised doc (MS-Office) files - in the wild - that are targeting the Apple Mac platform, which the company says is highly unusual given the low incidence of Apple Mac vulnerabilities.

According to Jaime Blasco, a researcher at AlienVault, the Security Information and Event Management (SIEM) solutions provider, the fact that the weaponised attacks are already in the wild is of concern, as it means that regular Mac users - many of whom do not have the kind of IT security software on their machines that their Windows colleagues do - are vulnerable to infection and computer hijacking.

The hackers behind this latest family of attacks are the same anti-Tibetan group that Blasco has been tracking and written about in several weeks. The pro-Chinese hackers are, he says, continuing to escalate the cold war - which has existed between the two countries for more than 60 years - into cyberspace.

"What is interesting about this latest attack vector is that, whilst the hacker group is the same one we have been tracking previously, they are now delivering two different Mac trojans - the first one that we detailed in an earlier posting – along with a new one with better capabilities," he said.

"We have also found some `debug symbols' in the program code that give us information about the identities of the hackers and their `Longgege' project. We also have a name for the new trojan - MacControl," he added.

The AlienVault researcher went on to say that, whilst direct information on the origins and target audience of these weaponised Doc files is scarce, the indications are that this element of the Longgege project is targeting the same Internet users and political pitch as seen with previous attacks.

Blasco says that the group behind this latest Longgege attack is almost certainly the same people identified by colleagues at Trend Micro earlier in the week and who are now turning their attention to vulnerable Apple Mac users.

This is, he adds, one of the few times we have ever seen a malicious Office file used to deliver Malware on to the Apple Mac platform and which exploits a remote code execution vulnerability that exists in the way that MS-Word handles a specially crafted file that includes a malformed record.

An attacker who successfully exploits this vulnerability, he explained, could take complete control of the user's Mac and networked computers plus other resources - potentially even an entire corporate network.

Put simply, says Blasco, this means that attackers could then install programs; view, change or delete data; or create new accounts with full user rights.

It's important to note, he adds, that users whose accounts have been configured to support fewer user rights on a given system are likely to be less impacted than users who operate with administrative user rights.

The MacControl trojan

Initial research by Blasco and his team suggests that several versions of the new MacControl trojan have been coded, including one with paths to debugging symbols, which may indicate the code has been written using a development package.

2013 Top Ranking Performers conferences

Once installed, the malware copies itself into the Library directory, as well as creating a new version in order to maintain persistence when the computer reboots.

After this, the trojan opens a connection to a remote command-and-control server, routing a variety of data to the remote destination, which resolves to an IP connection on the China Unicom Beijing province network.

"So far, so nasty, but the really bad news is that all the malware samples we have see to date have a 0/0 rate of detection. The weaponised doc files also seem to pass detection, suggesting the use of new and never-before-seen hacker coding techniques," he said.

"Our observations suggest that the hackers involved in this latest anti-Tibet hacker initiative are highly innovative in their malware obfuscation and coding techniques, as well as almost certainly having access to powerful coding platforms," he added.


About AlienVault:
AlienVault’s mission is to create an open and collaborative security paradigm, a total shift from today’s closed, proprietary and expensive systems.

Published: Monday, April 02, 2012

Printer Friendly Version Printer friendly version
 Recommend to a friend

Editorial Comments

Reply
Username:
Email:
Password:
Forgot Password?
Don't have a current membership with ContactCenterWorld.com?

become a member and connect with the rest of the Contact Center Industry at ContactCenterWorld.com here
Forum Profile
Job Title:(Display this on the Forum)
Company:(Display this on the Forum)
 
Neither the Administrators of these forums, or the Moderators participating, are responsible for the privacy practices of any user. Remember that all information that is disclosed in these areas becomes public information and you should exercise caution when deciding to share any of your personal information. Any user who finds material posted by another user objectionable is encouraged to contact us via e-mail. We are authorized by you to remove or modify any data submitted by you to these forums for any reason we feel constitutes a violation of our policies, whether stated, implied or not.

This site may contain links to other web sites and files. We have no control over the content and can not ensure it will not be offensive or objectionable. We will, however, remove links to material that we feel is inappropriate as we become aware of them.

By pressing the "Agree" button, you agree that you, the user, are 13 years of age or over. You are fully responsible for any information or file supplied by this user. You also agree that you will not post any copyrighted material that is not owned by yourself or the owners of these forums. In your use of these forums, you agree that you will not post any information which is vulgar, harassing, hateful, threatening, invading of others privacy, sexually oriented, or violates any laws.

If you do agree with the rules and policies stated in this agreement, and meet the criteria stated herein, proceed to press the "Agree" button below, otherwise press "Cancel".

If you have any questions about this privacy statement or the use of these forums, you can contact the forum administrator at: rajw@contactcenterworld.com

Your comments on this item:

Related Editorial

  • IE Zero Day Targets Defence And Industrial Companies
  • World Economic Forum Names AlienVault a 2013 Technology Pioneer
  • AlienVault Unveils Latest Unified Security Management Platform
  • Major Far Eastern Human Rights Portal Cracked to Serve Up Malware
  • AlienVault Research Shows China Escalating Tibetan Cold War Into Cyberspace
  • AlienVault Launches Open Threat Exchange, Largest Community-Sourced Information Security Threat Feed & Database

More Editorial From AlienVault

  • IE Zero Day Targets Defence And Industrial Companies
  • World Economic Forum Names AlienVault a 2013 Technology Pioneer
  • AlienVault Unveils Latest Unified Security Management Platform
  • AlienVault Closes Funding Round
  • Major Far Eastern Human Rights Portal Cracked to Serve Up Malware
  • AlienVault Warns on New Sykipot Malware Campaign

Members Online

« PreviousNext »
Ana Calcada Montepio
Tyler Zawacki contactcenterworld.com
Shane Abeyratne Telstra Corporation
Vega Pita
Aqeel Jatoi MCR Pvt. Ltd Franchisee of PizzaHut in Pakistan
Chyntia Arthaviena Bank Mandiri
Pedro Fragoso Montepio
Tomoko Inoue SOFTBANK TELECOM Corp.
Cristal Fernandez Telstra Corporation LTD
Pushpalatha Balan QNet Ltd
Bridgett Oldman Optus Inc
Wally MacTavish
Vancyon Van Zyl Teleperformance
Osman Firat BSH
Tholakele Ndlane Clientele Limited
Sasikumar Gunasekaran Tata Consultancy
Anton G DTL
Oksana Iashchuk VisoTeco
Kern Carson NETCAST BPO Services
A. Rakhmat Taufiq Directorate General of Taxes
Showing 1 - 20 of 51526 items

Newsletter Registration




RSS FeedLinkedinFacebookTwitter
About ContactCenterWorld
Advertise CRM & Contact Center Solutions | Link to this site
Submit CRM and Contact Center Content | Contact Us | Privacy Policy
Recommend this site to other CRM & Contact Center Professionals | Disclaimer

ContactCenterWorld.com 1999 - Present The Global Support Organization For Contact Center Professionals & the place for information on:
Offshore Outsourcing, On Hold, Outsourcing, Predictive Dialers, Quality Monitoring, Recruitment, Self Service, Speech Recognition, Telemarketing, Virtual Contact Center, VoIP, Web Chat, Work at Home, Workforce Management, ACD's, Address Management, Assessment Solutions, Attrition