Google Search

Showing posts with label China. Show all posts
Showing posts with label China. Show all posts

Tuesday, November 5, 2013

Calling out China on hacking may be working, experts say

SINGAPORE After years of quiet and largely unsuccessful diplomacy, the U.S. has brought its persistent computer-hacking problems with China into the open, delivering a steady drumbeat of reports accusing Beijing's government and military of computer-based attacks against America.

Officials say the new strategy may be having some impact.

In recent private meetings with U.S. officials, Chinese leaders have moved past their once-intractable denials of cyber espionage and are acknowledging there is a problem. And while there have been no actual admissions of guilt, officials say the Chinese seem more open to trying to work with the U.S. to address the problems.

"By going public the administration has made a lot of progress," said James Lewis, a cybersecurity expert at the Center for Strategic and International Studies who has met with Chinese leaders on cyber issues.

Play Video

Play Video

But it will likely be a long and bumpy road, as any number of regional disputes and tensions could suddenly stir dissent and stall progress.

On Wednesday, China's Internet security chief told state media that Beijing has amassed large amounts of data about U.S.-based hacking attacks against China but refrains from blaming the White House or the Pentagon because it would be irresponsible.

The state-run English-language China Daily reported that Huang Chengqing, director of the government's Internet emergency response agency, said Beijing and Washington should cooperate rather than confront each other in the fight against cyberattacks. Huang also called for mutual trust.

President Barack Obama is expected to bring up the issue when he meets with China's new president, Xi Jinping, in Southern California later this week. The officials from the two nations have agreed to meet and discuss the issue in a new working group that Secretary of State John Kerry announced in April. Obama's Cabinet members and staff have been laying the groundwork for those discussions.

Standing on the stage at the Shangri-La Dialogue security conference last weekend, Defense Secretary Chuck Hagel became the latest U.S. official to openly accuse the Chinese government of cyber espionage - as members of Beijing's delegation sat in the audience in front of him. The U.S., he said, "has expressed our concerns about the growing threat of cyber intrusions, some of which appear to be tied to the Chinese government and military."

But speaking to reporters traveling with him to the meeting in this island nation in China's backyard, Hagel said it's important to use both public diplomacy and private engagements when dealing with other nations such as China on cyber problems.

"I've rarely seen that public engagement resolves a problem, but it's important," he said, adding that governments have the responsibility to keep their people informed about such issues.

The hacking issue also featured prominently over two days of meetings between the U.S. Chamber of Commerce and a leading Chinese trade think tank in Beijing.

"This is arguably the single most consequential issue that is serving to erode trust in the relationship," said Jeremie Waterman, the chamber's executive director for greater China. "Over time, it could undermine business support for U.S.-China relations."

According to Lewis and other defense officials familiar with the issue, China's willingness to engage in talks with the U.S. about the problem - even without admitting to some of the breaches - is a step in the right direction.

Cybersecurity experts say China-based instances of cyber intrusions into U.S. agencies and programs - including defense contractors and military weapons systems - have been going on since the late 1990s. And they went along largely unfettered for as much as a decade.

A recent Pentagon report compiled by the Defense Science Board laid out what it called a partial list of 37 programs that were breached in computer-based attacks, including the Terminal High Altitude Area Defense weapon, a land-based missile defense system that was recently deployed to Guam to help counter the North Korean threat. Other programs whose systems were breached include the F-35 Joint Strike Fighter, the F-22 Raptor fighter jet and the hybrid MV-22 Osprey, which can take off and land like a helicopter and fly like an airplane.

The report also listed 29 broader defense technologies that have been compromised, including drone video systems and high-tech avionics. The information was gathered more than two years ago, so some of the data are dated and a few of the breaches - such as the F-35 - had already become public.

According to U.S. officials and cyber experts, China hackers use gaps in software or scams that target users' email systems to infiltrate government and corporate networks. They are then often able to view or steal files or use those computers to move through the network accessing other data.

Chinese officials have long denied any role in cyberattacks and insisted that the law forbids hacking and that their military has no role in it. They have also asserted that they, too, are often the victim.

Cyber experts say some of the breaches that emanate from Internet locations in China may be the product of patriotic hackers who are not working at the behest of Beijing's government or military but in independent support of it.

The Chinese government's control of the Internet, however, suggests that those hackers are likely operating with at least the knowledge of authorities who may choose to look the other way.

U.S. officials have quietly grumbled about the problem for several years but steadfastly refused to speak publicly about it. As the intrusions grew in number and sophistication, affecting an increasing number of government agencies, private companies and citizens, alarmed authorities began to rethink that strategy.

They were pressed on by cybersecurity experts - including prominent former government officials - who argued that using cyberattacks to steal intellectual property, weapons and financial data and other corporate secrets brought great gain at very little cost to the hackers. The U.S. government, they said, had to make it clear to the Chinese that continued bad behavior would trigger consequences.

In November 2011, U.S. intelligence officials for the first time publicly accused China and Russia of systematically stealing American high-tech data for economic gain.

That was followed by specific warnings about Chinese cyberattacks in the last two annual Pentagon reports on China's military power. And in February, the Virginia-based cybersecurity firm Mandiant laid out a detailed report directly linking a secret Chinese military unit in Shanghai to years of cyberattacks against U.S. companies. After analyzing breaches that compromised more than 140 companies, Mandiant concluded that they can be linked to a unit that experts believe is part of the People's Liberation Army's cyber command.

The change in tone from the Chinese leaders came through during recent meetings with Gen. Martin Dempsey, chairman of the Joint Chiefs of Staff, and has continued, according to officials and experts familiar with more recent discussions with Chinese leaders.

Still, experts say that progress with the Chinese will still be slow and that it's naive to think the cyberattacks will stop.

"This will take continuous pressure for a number of years," said Lewis. "We will need both carrots and sticks, and the question is when do you use them."


View the original article here

Tuesday, October 29, 2013

Cyber experts say calling out China may be working

SINGAPORE (AP) -- After years of quiet and largely unsuccessful diplomacy, the U.S. has brought its persistent computer-hacking problems with China into the open, delivering a steady drumbeat of reports accusing Beijing's government and military of computer-based attacks against America.

Officials say the new strategy may be having some impact.

In recent private meetings with U.S. officials, Chinese leaders have moved past their once-intractable denials of cyber espionage and are acknowledging there is a problem. And while there have been no actual admissions of guilt, officials say the Chinese seem more open to trying to work with the U.S. to address the problems.

"By going public the administration has made a lot of progress," said James Lewis, a cybersecurity expert at the Center for Strategic and International Studies who has met with Chinese leaders on cyber issues.

But it will likely be a long and bumpy road, as any number of regional disputes and tensions could suddenly stir dissent and stall progress.

On Wednesday, China's Internet security chief told state media that Beijing has amassed large amounts of data about U.S.-based hacking attacks against China but refrains from blaming the White House or the Pentagon because it would be irresponsible.

The state-run English-language China Daily reported that Huang Chengqing, director of the government's Internet emergency response agency, said Beijing and Washington should cooperate rather than confront each other in the fight against cyberattacks. Huang also called for mutual trust.

President Barack Obama is expected to bring up the issue when he meets with China's new president, Xi Jinping, in Southern California later this week. The officials from the two nations have agreed to meet and discuss the issue in a new working group that Secretary of State John Kerry announced in April. Obama's Cabinet members and staff have been laying the groundwork for those discussions.

Standing on the stage at the Shangri-La Dialogue security conference last weekend, Defense Secretary Chuck Hagel became the latest U.S. official to openly accuse the Chinese government of cyber espionage — as members of Beijing's delegation sat in the audience in front of him. The U.S., he said, "has expressed our concerns about the growing threat of cyber intrusions, some of which appear to be tied to the Chinese government and military."

But speaking to reporters traveling with him to the meeting in this island nation in China's backyard, Hagel said it's important to use both public diplomacy and private engagements when dealing with other nations such as China on cyber problems.

"I've rarely seen that public engagement resolves a problem, but it's important," he said, adding that governments have the responsibility to keep their people informed about such issues.

The hacking issue also featured prominently over two days of meetings between the U.S. Chamber of Commerce and a leading Chinese trade think tank in Beijing.

"This is arguably the single most consequential issue that is serving to erode trust in the relationship," said Jeremie Waterman, the chamber's executive director for greater China. "Over time, it could undermine business support for U.S.-China relations."

According to Lewis and other defense officials familiar with the issue, China's willingness to engage in talks with the U.S. about the problem — even without admitting to some of the breaches — is a step in the right direction.

Cybersecurity experts say China-based instances of cyber intrusions into U.S. agencies and programs — including defense contractors and military weapons systems — have been going on since the late 1990s. And they went along largely unfettered for as much as a decade.

A recent Pentagon report compiled by the Defense Science Board laid out what it called a partial list of 37 programs that were breached in computer-based attacks, including the Terminal High Altitude Area Defense weapon, a land-based missile defense system that was recently deployed to Guam to help counter the North Korean threat. Other programs whose systems were breached include the F-35 Joint Strike Fighter, the F-22 Raptor fighter jet and the hybrid MV-22 Osprey, which can take off and land like a helicopter and fly like an airplane.

The report also listed 29 broader defense technologies that have been compromised, including drone video systems and high-tech avionics. The information was gathered more than two years ago, so some of the data are dated and a few of the breaches — such as the F-35 — had already become public.

According to U.S. officials and cyber experts, China hackers use gaps in software or scams that target users' email systems to infiltrate government and corporate networks. They are then often able to view or steal files or use those computers to move through the network accessing other data.

Chinese officials have long denied any role in cyberattacks and insisted that the law forbids hacking and that their military has no role in it. They have also asserted that they, too, are often the victim.

Cyber experts say some of the breaches that emanate from Internet locations in China may be the product of patriotic hackers who are not working at the behest of Beijing's government or military but in independent support of it.

The Chinese government's control of the Internet, however, suggests that those hackers are likely operating with at least the knowledge of authorities who may choose to look the other way.

U.S. officials have quietly grumbled about the problem for several years but steadfastly refused to speak publicly about it. As the intrusions grew in number and sophistication, affecting an increasing number of government agencies, private companies and citizens, alarmed authorities began to rethink that strategy.

They were pressed on by cybersecurity experts — including prominent former government officials — who argued that using cyberattacks to steal intellectual property, weapons and financial data and other corporate secrets brought great gain at very little cost to the hackers. The U.S. government, they said, had to make it clear to the Chinese that continued bad behavior would trigger consequences.

In November 2011, U.S. intelligence officials for the first time publicly accused China and Russia of systematically stealing American high-tech data for economic gain.

That was followed by specific warnings about Chinese cyberattacks in the last two annual Pentagon reports on China's military power. And in February, the Virginia-based cybersecurity firm Mandiant laid out a detailed report directly linking a secret Chinese military unit in Shanghai to years of cyberattacks against U.S. companies. After analyzing breaches that compromised more than 140 companies, Mandiant concluded that they can be linked to a unit that experts believe is part of the People's Liberation Army's cyber command.

The change in tone from the Chinese leaders came through during recent meetings with Gen. Martin Dempsey, chairman of the Joint Chiefs of Staff, and has continued, according to officials and experts familiar with more recent discussions with Chinese leaders.

Still, experts say that progress with the Chinese will still be slow and that it's naive to think the cyberattacks will stop.

"This will take continuous pressure for a number of years," said Lewis. "We will need both carrots and sticks, and the question is when do you use them."


View the original article here

Saturday, September 14, 2013

China calls U.S. the "real hacking empire" after Pentagon report

BEIJING (Reuters) - China on Wednesday accused the United States of sowing discord between China and its neighbors after the Pentagon said Beijing is using espionage to fuel its military modernization, branding Washington the "real hacking empire".

The latest salvo came a day after China's foreign ministry dismissed as groundless a Pentagon report which accused China for the first time of trying to break into U.S. defense computer networks.

The Pentagon also cited progress in Beijing's effort to develop advanced-technology stealth aircraft and build an aircraft carrier fleet to project power further offshore.

The People's Liberation Army Daily called the report a "gross interference in China's internal affairs".

"Promoting the 'China military threat theory' can sow discord between China and other countries, especially its relationship with its neighboring countries, to contain China and profit from it," the newspaper said in a commentary that was carried on China's Defense Ministry's website.

The United States is "trumpeting China's military threat to promote its domestic interests groups and arms dealers", the newspaper said, adding that it expects "U.S. arms manufacturers are gearing up to start counting their money".

The remarks in the newspaper underscore the escalating mistrust between China and the United States over hacking, now a top point of contention between Washington and Beijing.

A U.S. computer security company, Mandiant, said in February a secretive Chinese military unit was likely behind a series of hacking attacks that targeted the United States and stole data from more than 100 companies.

That set off a war of words between Washington and Beijing.

China has said repeatedly that it does not condone hacking and is the victim of hacking attacks -- most of which it claims come from the United States.

"As we all know, the United States is the real 'hacking empire' and has an extensive espionage network," the People's Daily, a newspaper regarded as a mouthpiece of the Chinese Communist Party, said in a commentary.

The article -- which was published under the pen name "Zhong Sheng", meaning "Voice of China" -- said "in recent years, the United States has continued to strengthen its network tools for political subversion against other countries".

"Cyber weapons are more frightening than nuclear weapons," the People's Daily said. "To establish military hegemony on the Internet by repeatedly smearing other countries is a dangerous and wrong path to take and will ultimately end up in shooting themselves in the foot."

(Reporting by Sui-Lee Wee; Editing by Michael Perry)


View the original article here

Wednesday, July 31, 2013

Mac malware found in malformed Word documents - is China to blame?

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Our friends at F-Secure have blogged today about a boobytrapped Word document, that appears to be designed to infect computer systems running Mac OS X.

The malicious Word file, examined by the experts in SophosLabs, claims to be about the "6th International Uyghur Women's Seminar & 1st World Uyghur Women's Congress", run by the International Uyghur Human Rights & Democracy Foundation.

Boobytrapped Word file

Vulnerabilities, exploited in malformed Word documents, install malicious code onto the recipients' computer and a legitimate-seeming Word file with content relevant to the victim is displayed as a smoke screen.

It's clear that the attack is targeted against Uyghur Mac users, and we have seen similar attacks in the past.

Sophos products detect the malware as OSX/Agent-AADL and Troj/DocOSXDr-B.

The obvious question people are likely to ask is... are China to blame for this attack? After all, we have seen several attacks in the past which have targeted minority groups in the country.

There's no 100% proof connecting this attack with the-powers-that-be in Beijing, but you would be a brave man to bet against it.

All Mac users need to keep in mind that its important that all computers, regardless of operating system, are properly secured - and to be on their guard against attacks.

Whether it's likely that you aren't in China's good books or not, there are more and more cybercriminals investigating how they might infect the many Mac computers out there.

It is true that there is much less malware for OS X than there is for Windows, but that's not going to make you feel any better if you end up targeted in an attack like this.

Mac users, just like Windows users, need to ensure that they install the latest security patches and keep their software properly up-to-date.

If you're not already doing so, run anti-virus software on your Macs. If you're a home user, there really is no excuse at all as we offer a free anti-virus for Mac consumers.

Follow @gcluley

View the original article here

Monday, July 1, 2013

US swipes at China for hacking allegations

WASHINGTON (AP) — The U.S. has taken its first real swipe at China following accusations that the Beijing government is behind a widespread and systemic hacking campaign targeting U.S. businesses.

Buried in a spending bill signed by President Barack Obama on Tuesday is a provision that effectively bars much of the federal government from buying information technology made by companies linked to the Chinese government.

It's unclear what impact the legislation will have, or whether it will turn out to be a symbolic gesture. The provision only affects certain non-defense government agency budgets between now and Sept. 30, when the fiscal year ends. It also allows for exceptions if an agency head determines that buying the technology is "in the national interest of the United States."

Still, the rule could upset U.S. allies whose businesses rely on Chinese manufacturers for parts and pave the way for broader, more permanent changes in how the U.S. government buys technology.

"This is a change of direction," said Stewart Baker, a former senior official at the Homeland Security Department now with the legal firm Steptoe and Johnson in Washington. "My guess is we're going to keep going in this direction for a while."

Rep. Dutch Ruppersberger of Maryland, the top Democrat on the House Intelligence Committee, said he supports the restriction and doesn't think it would be too cumbersome for federal agencies. The Defense and Energy departments already are mindful of how its networks are built.

"Anything we can do to call awareness to the fact that we're continuing to be cyberattacked, we're continuing to lose jobs, and that billions of dollars in American money is being stolen," Ruppersberger said in an interview Wednesday.

In March, the U.S. computer security firm Mandiant released details on what it said was an aggressive hacking campaign on American businesses by a Chinese military unit. Since then, Treasury Secretary Jacob Lew has used high-level meetings with Beijing officials to press the matter. Beijing has denied the allegations.

Congressional leaders have promised to push comprehensive legislation that would make it easier for industry to share threat data with the government. But those efforts have been bogged down amid concerns that too much of U.S. citizens' private information could end up in the hands of the federal government.

As Congress and privacy advocates debate a way ahead, lawmakers tucked "section 516" into the latest budget resolution, which enables the government to pay for day-to day operations for the rest of the fiscal year. The provision specifically prohibits the Commerce and Justice departments, NASA and the National Science Foundation from buying an information technology system that is "produced, manufactured or assembled" by any entity that is "owned, operated or subsidized" by the People's Republic of China.

The agencies can only acquire the technology if, in consulting with the FBI, they determine that there is no risk of "cyberespionage or sabotage associated with the acquisition of the system," according to the legislation.

The move might sound like a no-brainer. If U.S. industry and intelligence officials are right, and China is stealing America's corporate secrets at a breathtaking pace, why reward Beijing with lucrative U.S. contracts? Furthermore, why install technical equipment that could potentially give China a secret backdoor into federal systems?

Last fall, Ruppersberger and House Intelligence Committee Chairman Mike Rogers, R-Mich., released a report urging U.S. companies and government agencies to drop any business with Chinese telecommunications companies Huawei Technologies Ltd. and ZTE Corp. because of the security risks they pose.

"Any bug, beacon or backdoor put into our critical systems could allow for a catastrophic and devastating domino effect of failures throughout our networks," Rogers said in a statement accompanying the report.

But a blanket prohibition on technology linked to the Chinese government may be easier said than done. Information systems are often a complicated assembly of parts manufactured by different companies around the globe. And investigating where each part came from, and if that part is made by a company that could have ties to the Chinese government could be difficult.

Huawei, the third-largest maker of smartphones, says it is owned by its employees and rejects claims that it is controlled by the communist government or China's military.

Depending on how the Obama administration interprets the law, Baker said it also could cause problems for the U.S. with the World Trade Organization, whose members include U.S. allies like Germany and Britain that might rely on Chinese technology to build computers or handsets.

But in the end, Baker says it could make the U.S. government safer and wiser.

"We do have to worry about buying equipment from companies that may not have our best interests at heart," he said.

___

Follow Anne Flaherty on Twitter at https://twitter.com/AnneKFlaherty.


View the original article here

Saturday, June 29, 2013

US Treasury's Lew presses China over hacking allegations, asks for more help on North Korea

BEIJING, China - U.S. Treasury Secretary Jacob Lew pressed Chinese leaders over computer hacking and for help with North Korea during two days of talks that ended Wednesday.

Lew's visit to Beijing was the first high-level contact between the two governments in six months as they re-engage following a hiatus during the Chinese leadership transition.

The White House has called for Beijing to take action to stop computer attacks aimed at stealing company secrets. Hundreds of cyberattacks have been traced to China, and a security firm said last month that it found a wave of attacks on 140 companies that originated in a building in Shanghai housing a military unit.

"This is a very serious threat to our economic interests. There was no mistaking how seriously we take this issue," Lew told reporters.

Chinese officials have denied their government is involved and say China also is a victim of cyberattacks.

In talks with Chinese leaders, Lew emphasized that Washington sees a distinction between criminal cyberattacks, which are a common threat, and spying by state-sponsored enterprises, said a senior American official who spoke on condition of anonymity in order to brief reporters. The official declined to say how Chinese officials responded.

On North Korea, Washington wants Beijing to use its status as the North's main source of trade and aid to press Pyongyang to discard its nuclear program.

"We made clear that the U.S. views the provocative actions of North Korea as very serious and we will continue to pursue methods available to change the policy perspective in Pyongyang," Lew said. "We share a common objective of a denuclearized Korean Peninsula and we will continue to discuss it."

However, asked whether Washington was considering sanctions that might affect Chinese banks, Lew said U.S. leaders want to avoid imposing burdens on the Chinese economy.

This week's talks were the start of a series of meetings that will test the potential for co-operation between the world's largest- and second-largest economies. Lew is the U.S. economic envoy to an annual high-level strategic and economic dialogue between Washington and Beijing that is due to hold its next round this summer.

Although the relationship is colored by mutual suspicion, the two sides now discuss an ever-broadening agenda, from military co-operation to food safety. Last year, they swiftly resolved a diplomatic standoff when Beijing agreed to allow a Chinese legal activist, Chen Guangcheng, to leave for the United States after he sought refuge in the American Embassy.

Despite frictions over North Korea, computer hacking and human rights, both sides sounded positive notes during Lew's visit and stressed their wide array of mutual interests.

China's new president, Xi Jinping, said Tuesday that the two sides have "some differences" but "enormous shared interests."

Xi has visited the United States a half-dozen times but also is seen as a nationalist who is willing to defend what he considers China's core interests regardless of the cost to its reputation. Beijing is locked in territorial feuds with Japan and several Southeast Asian nations that threaten to draw in the United States.

On Wednesday, Lew stressed their common interests in a meeting with China's new top economic official, Premier Li Keqiang.

"We have a shared interest in making sure global growth continues," Lew told Li at Beijing's Zhongnanhai compound, where Chinese leaders live and work.

Li said Lew's visit would further "understanding, communication and trust" between the two sides.

Lew also met with his new Chinese counterpart, Lou Jiwei, and the head of China's main economic planning agency. He also spoke with Wang Qishan, a member of the country's ruling seven-member Standing Committee with extensive experience in finance and trade issues who dealt regularly with Lew's predecessors, Henry Paulson and Timothy Geithner.


View the original article here

Thursday, April 25, 2013

China blamed for EADS and ThyssenKrupp hack attacks

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Two more major organisations have gone public about, what they claim, were attempts by Chinese hackers to infiltrate their networks and steal sensitive information.

EADS, the European Aeronautic Defense and Space company, and steelmaker ThyssenKrupp are said to have become the targets of hack attacks originating in China, according to Der Spiegel.

EADS - who makes the Eurofighter jet, as well as spy drones, surveillance satellites, and even rockets for French nuclear weapons - are said to have contacted the German government last year to warn them that the military contractor's computer network has been hacked.

Eurofighter

Officially, EADS have described the attack as "standard" and insisted that no harm has been done.

However, the attacks is against a backdrop created over the last few years of of other hacks against the defence industry including the likes of Lockheed Martin, L-3 Communications and Northrop Grumman.

And, of course, it's only 18 months since the then US Deputy Defense Secretary William Lynn claimed that a foreign intelligence agency was behind a hack attack that stole classified information about a top secret weapons system.

Meanwhile, ThyssenKrupp has also said to have confirmed that it was attacked by hackers - adding the detail that the attack occurred in the United States, and appeared to originate from a Chinese internet address.

According to Der Spiegel, the attacks against ThyssenKrupp were described as "massive" and of "a special quality", and the company was not sure of what (if any) information had been stolen by the hackers.

It is becoming increasingly clear that organisations need to defend themselves not only from the day-to-day financial-orientated cybercrime attacks which can impact anyone with a computer, but also from sophisticated targeted attacks that may be designed to spy and surreptitiously steal information.

BlueprintThe truth is that these hacking stories aren't really describing a technological problem. They're describing a human problem. It's remarkably easy to dupe someone into clicking on a link or opening an attachment in an email, and for their computer to become compromised.

You can reduce the chances of a targeted attack working by keeping your software (such as your PDF reader, your web browser, your word processor, as well as your operating system) up-to-date with the latest patches.

Furthermore, you should run a layered defence - that means not just running up-to-date anti-virus software, but also firewalls, email filtering technologies, vulnerability assessment, using DLP (data loss protection) technology and strong encryption to secure your most sensitive data.

Also, it's amazing how many people re-use passwords, and use the same weak password in multiple places. That means if you get hacked in one place, and your password is compromised, it may also unlock accounts elsewhere on the net. It's shocking how many people don't use different passwords for different places.

All of these methods can reduce your chances of suffering from a targeted attack.

But ultimately, there's no 100% technological solution as human beings can still make bad decisions. And that's why it's important to train users about threats, and warn them to be suspicious of unsolicited links and attachments and to always report suspicious activity.

Follow @gcluley

View the original article here

Friday, April 19, 2013

More Mac malware attacking minority groups in China

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Microsoft WordOver the last year, SophosLabs, has talked about attacks against minority groups in China that use old vulnerabilities in Microsoft Office, that already have patches available for them.

We have seen several attacks in the past.

Earlier this week, the folks at AlienVault saw another attack using the same vulnerability in Office products on Mac OS X, targeting the Uyghur people of East Turkestan.

The vulnerability, known as MS09-027, was patched by Microsoft back in June 2009, and allowed remote code execution in Microsoft Word.

That means simply opening a boobytrapped Word document on an unpatched computer could run malicious code on your Mac. While you are distracted, reading the contents of a Word file, malware is being invisibly and silently installed onto your computer.

Contents of Word document

Although many Mac users might clutch onto the hope that their operating system will ask for an administrator's username and password before installing any software, you won't see any such message pop-up with an attack like this as it is a userland Trojan and you will not be prompted for administrator credentials.

This is because neither the /tmp/ nor /$HOME/Library/LaunchAgents folders on Mac OS X require root privileges. Software applications can run in userland with no difficulties, and even open up network sockets to transfer data.

Word DOC code

Sophos products detect the malicious documents as Troj/DocOSXDr-B and the dropped malware as the Mac Trojan horse OSX/Agent-AADL.

OSX/Agent-AADL obviously went through some development during this campaign because we saw three distinct versions. The first was the most interesting:

Word DOC Trojan code

In later versions of the Trojan, the function and variable names were stripped out and the shell script filenames were further hidden/obfuscated.

Once again, Mac users need to remember to not be complacent about the security of their computers. Although there is much less malware for Mac than there is for Windows, that is going to be no compensation if you happen to be targeted by an attack like this.

Mac users, just like Windows users, need to pay attention to the latest security patches and ensure that their software is kept properly up-to-date.

If you're not already doing so, run anti-virus software on your Macs. If you're a home user, there really is no excuse at all as we offer a free anti-virus for Mac consumers.

Follow @SophosLabs

View the original article here