A wave of cyber espionage in the Middle East

Kaspersky Lab today announced the results of an investigation carried out jointly with Seculert, a company engaged in advanced threat detection, the "Ms" - an active campaign of cyber espionage, the victims are in the Middle East. Madi - originally discovered by Seculert - a campaign infiltrate computer networks, using the Trojan, which is provided strictly specially chosen goals through social engineering.
Kaspersky Lab has worked with Seculert to perform so. hopper operations aimed at Madi control servers, enabling the monitoring of cybercriminal campaign. Businesses have identified more than 800 victims found in Iran, Israel and some countries in the world, which for the past eight months were connected to servers cybercriminals. Statistics obtained allow to conclude that among the victims were mostly businessmen working on the Iranian and Israeli projects on critical infrastructure, the Israeli financial institutions, engineering students from the Middle East, and various government agencies providing in the Middle East. In addition, the analysis of the malware identified a unique number of religious and political documents and images "distractions" that have been included in the system at a time when there was the first infection.
"Although in comparison with other similar projects, we are dealing here with a very simple malicious software and infrastructure, the people behind the campaign Madi managed to carry out a long-term operation directed against known targets" - said Nicolas Brulez, senior malware analyst at Kaspersky Lab. "Maybe that's what caused the primitiveness of amateurism and that the operation was able to avoid the radar and has not been detected."
"Interestingly, in our analysis, we discovered many common text strings in Persian found in malicious software and tools running on the servers of cyber criminals, which is quite unusual. The attackers no doubt that seamlessly handling the language "- said Aviv Raff, CTO, Seculert.
Madi campaign used the Trojan allows remote attackers to steal confidential files from infected computers running Windows, to monitor confidential communications transmitted via e-mail and instant messaging, record audio, record keystrokes and take screenshots of the victim. The analysis of the data shows that the victims of the computers were stolen many gigabytes of data.
Popular applications and websites that spied, included an account on Gmail, Hotmail, Yahoo! Mail, ICQ, Skype, Google+ and Facebook. Surveillance systems were also integrated ERP / CRM, business contracts and financial management systems.

