Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Wednesday, 3 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Fresh targeted attack campaign revealed by Kaspersky Labs

by The Gurus
September 10, 2020
in Editor's News
Share on FacebookShare on Twitter

fresh espionage campaign named “Icefog” has been uncovered by Kaspersky Labs, which hit targets in South Korea and Japan and had hosted command and control servers in Asia and the United States.

Described as a small yet energetic advanced persistent threat (APT) group, researchers at the company believed that it began operations in 2011 and based on the list of IP addresses used to monitor and control the infrastructure, Kaspersky Lab’s experts believe that some of those behind this operation are based in at least three countries: China, South Korea and Japan.
Based on the profiles of known targets, the attackers appear to have an interest in the following sectors: military, shipbuilding and maritime operations, computers and software development, research companies, telecom operators, satellite operators, mass media and television. Rather than infiltrate a network, monitor and send information back to the host, the attackers hijack sensitive documents and company plans, email account credentials and passwords to access various resources inside and outside the victim’s network and do it one by one, locating specific information.
Once the desired information has been obtained, they leave and in most cases, the Icefog operators appear to know exactly what they need from the victims. They look for specific filenames, which are quickly identified, and transferred to the C&C.
The attackers use a backdoor set known as “Icefog”, also known as “Fucobha”. The initial infection is via spear phishing where attackers embed exploits for several known vulnerabilities into Microsoft Word and Excel documents. Once opened, a backdoor is dropped onto the system and a decoy document is then showed to the victim. Kaspersky admitted that some of the vulnerabilities used, especially in Java, were patched some time ago.
What makes this different, according to the research, is that this focuses on targets in South Korea and Japan. Kaspersky Labs said that it first became aware of Icefog in June 2013 when it obtained an attack sample used against Fuji TV; further analysis found that this was a new version of the malware that attacked the Japanese Parliament in 2011.
So far Kaspersky Labs has identified that there are more than 3,600 unique infected IPs and several hundred victims, although it has sinkholed 13 of the 70+ domains used by the attackers. Kaspersky Labs researcher Stefan Tanase saidthat there are still multiple active command and control servers, with live victims connecting to them.
Tanase called the attackers “cyber-mercenaries [who] acted with great precision, targeting specific documents or credentials, then leaving the network within weeks”. Costin Raiu, director of the global research and analysis team at Kaspersky Lab, said: “The ‘hit and run’ nature of the Icefog attacks demonstrate a new emerging trend: smaller hit-and-run gangs that are going after information with surgical precision.
“The attack usually lasts for a few days or weeks and after obtaining what they were looking for, the attackers clean up and leave. In the future, we predict the number of small, focused ‘APT-to-hire’ groups to grow, specialising in hit-and-run operations; sort of ‘cyber mercenaries’ of the modern world.”
ShareTweet
Previous Post

Data providers hit by attackers

Next Post

AT&T, Verizon face shareholder revolt over NSA spying program

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol