Author Topic: Old malware targets government computers (used digitally signed TeamViewer )  (Read 178 times)

Offline menotu

  • PCLinuxOS Tester
  • Super Villain
  • *******
  • Posts: 15304
  • ┌∩┐(◕_◕)┌∩┐
by Dan Goodin - Mar 20, 2013 - arstechnica

Decade-old espionage malware found targeting government computers

"TeamSpy" used digitally signed TeamViewer remote access tool to spy on victims.

Researchers have unearthed a decade-long espionage operation that used the popular TeamViewer remote-access program and proprietary malware to target high-level political and industrial figures in Eastern Europe.

TeamSpy, as the shadow group has been dubbed, collected encryption keys and documents marked as "secret" from a variety of high-level targets, according to a report published Wednesday by Hungary-based CrySyS Lab.

Targets included a Russia-based Embassy for an undisclosed country belonging to both NATO and the European Union, an industrial manufacturer also located in Russia, multiple research and educational organizations in France and Belgium, and an electronics company located in Iran. CrySyS learned of the attacks after Hungary's National Security Authority disclosed intelligence that TeamSpy had hit an unnamed "Hungarian high-profile governmental victim."

Malware used in the attacks indicates that those responsible may have operated for years and may have also targeted figures in a variety of countries throughout the world. Adding intrigue to the discovery, techniques used in the attacks bear a striking resemblance to an online banking fraud ring known as Sheldon, and a separate analysis from researchers at Kaspersky Lab found similarities to the Red October espionage campaign that the Russia-based security firm discovered earlier this year.

arstechnica

crysys.hu
« Last Edit: March 21, 2013, 07:29:14 AM by menotu »
PCLinuxOS 32bit KDE 4.10.1; kernel-3.4.11-pclos1.bfs & 64bit 3.2.18bfs; NVidia GeForce 8400GS 1GB 310.19 driver

Sony Vaio SVE1513A4ESI Laptop, Intel Core i5, 2.6GHz, 6GB RAM, 750GB, 15.6" Intel HD Graphics 4000

Online trevatxtal

  • Full Member
  • ***
  • Posts: 72
    • The Home of Xtal
That really concerns me as TeamViewer has a Linux version.
So some folk have been leaving their backdoor open for years!
That is bad news for a lot of people.
My recent post
http://www.pclinuxos.com/forum/index.php/topic,114409.0/topicseen.html
also is concerned with Linux security.
Trev

Offline kjpetrie

  • PCLinuxOS Tester
  • Hero Member
  • *******
  • Posts: 3991
The report doesn't say TeamViewer is spyware, just that a version of TeamViewer modified by substituting a DLL (Linux doesn't use DLLs) was one of the tools used.
-----------
KJP
-----------------------------------------------------------
PClos64 RC1 on Intel D945GCLF2 motherboard (Atom 330), 2GB DDR2 RAM, Maxtor STM325031, HL-DT-ST DVDRAM GSA-H42N, Amilo LSL 3220T monitor. Also Acer 5810TG (with custom kernel) and Asus eeePC 2G surf

Online trevatxtal

  • Full Member
  • ***
  • Posts: 72
    • The Home of Xtal
The report doesn't say TeamViewer is spyware, just that a version of TeamViewer modified by substituting a DLL (Linux doesn't use DLLs) was one of the tools used.
Thank you  kjpetrie
That clears that up.
 I am glad we have so many folks willing to put ones mind at rest on PcLinuxOs forum.
This is a great site!
Trev ;D ;D