Showing posts with label Targeted Attack. Show all posts
Showing posts with label Targeted Attack. Show all posts

Saturday, February 8, 2014

[fireeye] Trends in Targeted Attacks: 2013

FireEye has been busy over the last year. We have tracked malware-based espionage campaigns and published research papers on numerous advanced threat actors. We chopped through Poison Ivy, documented a cyber arms dealer, and revealed that Operation Ke3chang had targeted Ministries of Foreign Affairs in Europe.
Worldwide, security experts made many breakthroughs in cyber defense research in 2013. I believe the two biggest stories were Mandiant’s APT1 report and the ongoing Edward Snowden revelations, including the revelation that the U.S. National Security Agency (NSA) compromised 50,000 computers around the world as part of a global espionage campaign.
In this post, I would like to highlight some of the outstanding research from 2013.
Trends in Targeting
Targeted malware attack reports tend to focus on intellectual property theft within specific industry verticals. But this year, there were many attacks that appeared to be related to nation-state disputes, including diplomatic espionage and military conflicts.
Conflict
Where kinetic conflict and nation-state disputes arise, malware is sure to be found. Here are some of the more interesting cases documented this year:
  • Middle East: continued attacks targeting the Syrian opposition; further activity by Operation Molerats related to Israel and Palestinian territories.
  • India and Pakistan: tenuous relations in physical world equate to tenuous relations in cyberspace. Exemplifying this trend was the Indian malware group Hangover, the ByeBye attacks against Pakistan, and Pakistan-based attacks against India.
  • Korean peninsula: perhaps foreshadowing future conflict, North Korea was likely behind the Operation Troy (also known as DarkSeoul) attacks on South Korea that included defacements, distributed denial-of-service (DDoS) attacks, and malware that wiped hard disks. Another campaign, Kimsuky, may also have a North Korean connection.
  • China: this was the source of numerous attacks, including the ongoing Surtr campaign, against the Tibetan and Uygur communities, which targeted MacOS and Android.

[fireeye] Targeted Attacks in 2013: Asia Pacific



Here at FireEye, the New Year gives us an opportunity to look back at 2013 and analyze what happened in cyber security from a high-level and strategic perspective.
Let’s start with Asia. Cyber attacks against government websites in Southeast Asia and Australia made the front-page news, reminding security professionals that cyber threats are both a global and a regional issue.
While attention-seeking hackers are trying to attract as much press as possible, organized and resourceful cyber criminals and nation-state threat actors are capable of more advanced – and stealthy – attacks. Motivated by economic and political aims, some of the most advanced cyber attacks are designed to steal information (or, like Stuxnet, sabotage critical infrastructure) and evade detection. Therefore, this class of attacks can often go unnoticed for long periods of time.
Advanced Attacks in Asia: 2013
In our research at FireEye Labs, the Asia Pacific as a region is two times more likely to be targeted by advanced cyber attacks than the world as a whole.
Based on our data, here is a list of the top 10 most targeted countries in Asia during the past year. This data represents only those attackers that we regard as “advanced persistent threats” (APT) or targeted attacks.
  1. South Korea
  2. Japan
  3. Taiwan
  4. Thailand
  5. Hong Kong
  6. Philippines
  7. India
  8. Australia
  9. Pakistan
  10. Singapore
Beyond the top 10, Figure 1 highlights APT attacks that FireEye discovered in the region in 2013.
01
Figure 1: APT Heat Map in Asia Pacific. The darker the hue, the higher the number of attacks we found.