Featured Articles

AMD Never Settle Forever bundle hits 200-series cards

AMD Never Settle Forever bundle hits 200-series cards

AMD’s Never Settle bundles have been around for a while and the community response has been extremely positive. When AMD launched…

More...
AMD shipping Beema APUs

AMD shipping Beema APUs

According to Lisa Su, SVP & GM, Global Business Units at AMD, Beema notebook parts have started shipping to manufacturers last…

More...
IHS teardown reveals Galaxy S5 BOM

IHS teardown reveals Galaxy S5 BOM

Research firm IHS got hold of Samsung’s new flagship smartphone and took it apart to the last bolt to figure out…

More...
Galaxy S5, HTC One M8 available selling well

Galaxy S5, HTC One M8 available selling well

Samsung’s Galaxy S5 has finally gone on sale and it can be yours for €699, which is quite a lot of…

More...
KFA2 GTX 780 Ti Hall Of Fame reviewed

KFA2 GTX 780 Ti Hall Of Fame reviewed

KFA2 gained a lot of overclocking experience with the GTX 780 Hall of Fame (HOF), which we had a chance to…

More...
Frontpage Slideshow | Copyright © 2006-2010 orks, a business unit of Nuevvo Webware Ltd.
Thursday, 07 November 2013 12:26

Office zero day exploited by two groups

Written by Nick Farrell



Graphics component in Word docs

A zero-day vulnerability, which was discovered that exploits a Microsoft graphics component using malicious Word documents, appears to be attacking Indian and Pakistan targets.

FireEye’s Research team has analysed this zero-day exploit and found a connection between these attacks and earlier attacks in India and Pakistan. Information obtained from a command-and-control server (CnC) used in recent attacks indicateds that the Hangover group, believed to operate from India, has compromised 78 computers, 47 percent of those in Pakistan.

FireEye has also found that another group also has access to this exploit and is using it to deliver the Citadel Trojan malware. This group, which we call the Arx group, may have had access to the exploit before the Hangover group did. Information obtained from CnCs operated by the Ark group revealed that 619 targets have been compromised. The majority of the targets are in India (63 percent) and Pakistan (19 percent).

This seems to indicate that use of this zero-day exploit is more widespread than previously believed and two different groups are using this exploit: Hangover and Ark. Hangover has been previously connected with a targeted malware campaign, and the Ark group is operating a Citadel-based botnet for organised crime.

Nick Farrell

E-mail: This e-mail address is being protected from spambots. You need JavaScript enabled to view it
blog comments powered by Disqus

To be able to post comments please log-in with Disqus

 

Facebook activity

Latest Commented Articles

Recent Comments