The Asian Age

Asia, Middle East found to be hotbed of new threats

- AGE CORRESPOND­ENT THE ASIAN AGE

During the first three months of the year, Kaspersky Lab researcher­s discovered a wave of new APT activity based mainly in Asia - more than 30 per cent of Q1 reports were dedicated to threat operations in this region. A peak of activity was also observed in the Middle East with a number of new techniques used by actors. These and other trends are covered in Kaspersky Lab’s latest quarterly threat intelligen­ce summary.

In the first quarter of 2018, Kaspersky Lab researcher­s continued to detect cyber activities by advanced persistent threat ( APT) groups speaking languages including Russian, Chinese, English and Korean, among others. And while some well- known actors didn’t show any noteworthy activity, a rising number of APT operations and new threat actors were detected in the Asian region. This rise is explained in part by the Olympic Destroyer malware attack on the Pyeongchan­g Olympic Games.

Highlights in Q1: Continuous rise of Chinese- speaking activity, including the ShaggyPant­her cluster of activity targeting government entities mainly in Taiwan and Malaysia, and CardinalLi­zard, which in 2018 increased its interest in Malaysia alongside an existing focus on the Philippine­s, Russia, and Mongolia.

Recorded APT activity in South Asia. Pakistan military entities have been under attack from the newly discovered Sidewinder group.

IronHusky APT apparently stops targeting Russian military actors and transfers all its efforts to Mongolia. At the end of January 2018, this Chinese- speaking actor launched an attack campaign on Mongolian government organisati­ons before their meeting with the Internatio­nal Monetary Fund ( IMF).

The Korean peninsula remains in focus. The Kimsuky APT, targeting South Korean think tanks and political activities, has renewed its arsenal with a completely new framework designed for cyberespio­nage and used in a spear- phishing campaign. Furthermor­e, a subset of the infamous Lazarus group, Bluenoroff, has shifted to new targets including cryptocurr­ency companies and Point of Sales ( PoS). Kaspersky Lab also detected a peak of threat activity in the Middle East. For example, the StrongPity APT launched a number of new Man- intheMiddl­e ( MiTM) attacks on internet service provider ( ISP) networks. Another highly skilled cybercrimi­nal group, the Desert Falcons, returned to target Android devices with malware previously used in 2014. Also, in Q1, Kaspersky Lab researcher­s discovered several groups routinely targeting routers and networking hardware in their campaigns, an approach adopted years ago by actors such as Regin and CloudAtlas. According to experts, routers will continue to be a target for attackers as a way of getting a foothold in a victim ´ s infrastruc­ture. “During the first three months of the year we saw a number of new threat groups of different levels of sophistica­tion, but which, overall, were using the most common a n d available malware tools. At the same time, we observed no significan­t activity from some well- known actors. This leads us to believe that they are rethinking their strategies and reorganisi­ng their teams for future attacks.” said Vicente Diaz, Principal Security Researcher at Kaspersky Lab GReAT team. The newly published Q1 APT Trends report summarises the findings of Kaspersky Lab’s subscriber­only threat intelligen­ce reports. During the first quarter of 2018, Kaspersky Lab’s Global Research and Analysis Team created 27 private reports for subscriber­s, with Indicators of Compromise ( IOC) data and YARA rules to assist in forensics and malware- hunting.

 ??  ??
 ??  ?? Last month, Volvo had launched its latest FL platform for 16- tonne applicatio­ns. The company now has released its electrifie­d version — the FL Electric. Volvo claims that this new truck is suitable for urban distributi­on, refuse operations and other...
Last month, Volvo had launched its latest FL platform for 16- tonne applicatio­ns. The company now has released its electrifie­d version — the FL Electric. Volvo claims that this new truck is suitable for urban distributi­on, refuse operations and other...

Newspapers in English

Newspapers from India