Featured Articles

AMD SVP John Byrne named turnaround exec of the year

AMD SVP John Byrne named turnaround exec of the year

Director of AMD’s PR Chris Hook has tweeted and confirmed later in a conversation with Fudzilla that John Byrne, Senior Vice…

More...
Shield Tablet 8 launching on Tuesday July 22nd

Shield Tablet 8 launching on Tuesday July 22nd

We knew the date for a while but as of right now we can confirm that Nvidia’s new Shield Tablet 8,…

More...
AMD confirms 20nm in 2015

AMD confirms 20nm in 2015

Lisa Su, Senior Vice President and Chief Operating Officer, AMD, has confirmed what we told you back in May 2014 – …

More...
AMD reports loss, shares tumble

AMD reports loss, shares tumble

AMD’s debt load is causing huge problems for the chipmaker -- this quarter it had another substantial loss. The tame Apple Press…

More...
AMD A8-7600 Kaveri APU reviewed

AMD A8-7600 Kaveri APU reviewed

Today we'll take a closer look at AMD's A8-7600 APU Kaveri APU, more specifically we'll examine the GPU performance you can…

More...
Frontpage Slideshow | Copyright © 2006-2010 orks, a business unit of Nuevvo Webware Ltd.
Thursday, 07 November 2013 12:26

Office zero day exploited by two groups

Written by Nick Farrell



Graphics component in Word docs

A zero-day vulnerability, which was discovered that exploits a Microsoft graphics component using malicious Word documents, appears to be attacking Indian and Pakistan targets.

FireEye’s Research team has analysed this zero-day exploit and found a connection between these attacks and earlier attacks in India and Pakistan. Information obtained from a command-and-control server (CnC) used in recent attacks indicateds that the Hangover group, believed to operate from India, has compromised 78 computers, 47 percent of those in Pakistan.

FireEye has also found that another group also has access to this exploit and is using it to deliver the Citadel Trojan malware. This group, which we call the Arx group, may have had access to the exploit before the Hangover group did. Information obtained from CnCs operated by the Ark group revealed that 619 targets have been compromised. The majority of the targets are in India (63 percent) and Pakistan (19 percent).

This seems to indicate that use of this zero-day exploit is more widespread than previously believed and two different groups are using this exploit: Hangover and Ark. Hangover has been previously connected with a targeted malware campaign, and the Ark group is operating a Citadel-based botnet for organised crime.

Nick Farrell

E-mail: This e-mail address is being protected from spambots. You need JavaScript enabled to view it
blog comments powered by Disqus

 

Facebook activity

Latest Commented Articles

Recent Comments