Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Sunday, 5 February, 2023
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Events
    • Most Inspiring Women in Cyber 2022
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Events
    • Most Inspiring Women in Cyber 2022
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Kaspersky Lab's Own Network Hit by Cyber-Attack

by The Gurus
June 11, 2015
in Editor's News
Share on FacebookShare on Twitter

It came to light yesterday afternoon that, in early spring 2015, Kaspersky Lab detected a cyber-intrusion affecting several of its internal systems. Following this finding, the company launched an intensive investigation, which led to the discovery of a new malware platform from one of the most skilled threat actors in the APT world: Duqu. The attack exploited zero-day vulnerabilities and after elevating privileges to domain administrator, the malware was spread in the network through MSI files. The attack didn’t leave behind any disk files or change system settings, making detection difficult.
Eugene Kaspersky himself named the APT malware Duqu 2.0, given its relation to the 2011 state-sponsored malware of the same name. During a live Webcast press conference from London, Kaspersky talked in detail about the Duqu 2.0 exploit without attributing it to a particular nation-state. Not only did it target Kaspersky Lab, Duqu 2.0 also hit recent P5+1 Iranian nuclear arms negotiations, which has meant that some now speculate that the State of Israel is somehow connected.
The Duqu 2.0 attack used three different zero-day exploits in Microsoft, all of which were patched on June 9.
“The attack is extremely sophisticated, and this is a new generation of what is most likely state-sponsored malware,” Kaspersky said during the press conference. “It’s a kind of a mix of Alien, Terminator and Predator, in terms of Hollywood. Alien, Terminator and Predator are three famous movies with a relentless evil character bent on destruction.”
Gavin Reid, VP of threat intelligence at Lancope commented, “This attack is unique and one of the first times we have seen a nation-state attack on the private security industry. Kaspersky is credited with finding the original Duqu, so it is not too surprising the authors would want to add Kaspersky to the list of companies it targeted with the newer harder-to-detect Duqu 2.0. This compromise shows how at risk the private sector is from advanced adversaries – even companies that are expert in this area. The fact this malware runs completely in memory makes many host-based detection capabilities ineffective.”
Gavin Millard, technical director at Tenable Network Security added, “The fact that Kaspersky, one of the top vendors on the bleeding edge of malware research, were hit with a successful attack shows how advanced the threats we are all facing. The methods used leveraged some of the biggest vulnerabilities found in Microsoft in the last few months including MS14-068 which enabled privilege escalation to domain administrator and MS15-061 that was only patched this week. Hopefully the transparency that Kaspersky have demonstrated so far will continue with them sharing further details on how the attack was undertaken and finally uncovered for us all to learn more about the techniques used.”

FacebookTweetLinkedIn
Tags: Cyber SecurityDuquDuqu 2.0infosecinfosecurityit securityKasperskyMalwarenation stateZero-day
ShareTweetShare
Previous Post

Plenty of phish in the sea, warns ESC Global Security

Next Post

IT Security Guru News – Kaspersky and Duqu 2.0

Recent News

london-skyline-canary-wharf

Ransomware attack halts London trading

February 3, 2023
Ransomware conversations: Why the CFO is pivotal to discussing and preparing for risk

Ransomware conversations: Why the CFO is pivotal to discussing and preparing for risk

February 2, 2023
JD Sports admits data breach

JD Sports admits data breach

January 31, 2023
Acronis seals cyber protection partnership with Fulham FC

Acronis seals cyber protection partnership with Fulham FC

January 30, 2023

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2019 IT Security Guru - Website Managed by Calm Logic

  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Events
    • Most Inspiring Women in Cyber 2022
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2019 IT Security Guru - Website Managed by Calm Logic

This site uses functional cookies and external scripts to improve your experience.

Privacy settings

Privacy Settings / PENDING

This site uses functional cookies and external scripts to improve your experience. Which cookies and scripts are used and how they impact your visit is specified on the left. You may change your settings at any time. Your choices will not impact your visit.

NOTE: These settings will only apply to the browser and device you are currently using.

GDPR Compliance

Powered by Cookie Information