This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

UK Critical Infrastructure - Trojan Attacks

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://isc.sans.org/diary.php?date=2005-06-16
Updated June 16th 2005 23:01 UTC
"Britain's NISCC has issued "Breaking News" and is "warning that vital computer networks are at risk of attack." "The attackers’ aim appears to be covert gathering and transmitting of commercially or economically valuable information." "To learn more see the NISCC briefing Targeted Trojan Email Attacks"
http://www.uniras.gov.uk/niscc/index-en.html
http://www.uniras.gov.uk/niscc/docs/ttea.pdf

UPDATE: Other Governments issue warnings. A principle concern is:

"The subject line and text of the e-mails appear relevant to the recipient’s work, or may be copied from a previous legitimate e-mail;

"The attachment name and type appear relevant to the text and to the recipient’s work."(1)

(1) Canadian Cyber Incident Response Centre CCIRC
http://www.ocipep.gc.ca/opsprods/info_notes/IN05-001_e.asp
Australian Department of Defence DSD Advisory DA-2005-01
http://www.dsd.gov.au/_lib/pdf_doc/advisories/DA-2005-01.pdf …"

:ph34r:
More…

- http://www.theregister.com/2005/06/16/uk_cyber-blitz/
16th June 2005
"…Approximately 300 UK government departments and businesses critical to the country's infrastructure have been the subject of Trojan horse attacks, many reportedly originating in the Far East. "The attackers' aim appears to be covert gathering or transmitting of commercially or economically valuable information," NISCC warns. The attacks seek to compromise computers so that remote hackers can steal privileged information and potentially launch further attacks. Infected email employ social engineering tricks, for example posing as information relevant to a target's job. "Once installed on a user's machine, Trojans may be used to obtain passwords, scan networks, exfiltrate [send out] information and launch further attacks," according to NISCC. "Anti-virus software and firewalls do not give complete protection. Trojans may communicate with the attackers using common ports (eg HTTP, DNS, SSL) and can be modified to avoid anti-virus detection."
Paul King, principal security consultant at Cisco Systems UK, said the attacks demonstrated how conventional anti-virus scanning software was ineffective at stopping new and unknown attacks. "The role of anti-virus has become to throw away known bad stuff. Other technologies, such as host-based intrusion prevention, are needed to defend against previously unseen attacks"…"

:ph34r: