About Me

Archive

Archive

Read More

Corporate Blogs

Feeds & Podcasts

Meet the Bloggers

Archive

Tags

12 Scams of Christmas, 2012 Virtual Sales Kickoff, Accredited Channel Engineer, ACE, ACE certification partner, Acquisition, Alex Thurber, Annual Partner Survey, Apple, ASIC, attacks, Australia, automobile, automotive, award, awards, beyond the PC, Biological Computer, Blackhat, C-SAVE program, Change Control, channel partner, Channel Partners, Channel Partner Town Hall, Channel Program, Channels Town Hall, chromebook, CIO Insomnia Project, Citrix, Civil War, cloud, Cloud computing, cloud security, Commercial/SMB, Commercial and Enterprise Deal Registration, Compliance, Consumer, consumerization, consumerization of IT, Continuing Education, Corporate Responsibility, critical infrastructure, cyberattacks, Cybercrime, Cyber risks, cybersafety, cybersecurity, cyber security awareness, Cyber Security Mom, cyberthreats, Database, database security, data breach, data center, data center security, Data Loss Prevention, Data Protection, Dave DeWalt, Dave Marcus, David Small, Deal Registration, Deep Command, DeepDefender, Deep Defender, DeepSAFE, DLP, Dmitri Alperovitch, education, Email & Web Security, Email Protection, embedded, EMEA, encryption, Endpoint Protection, Endpoint security suite upgrade, Enhanced Deal Registration, enterprise, epo, ePO DeepCommand, ePolicy Orchestrator, Family Safety, Focus, Focus11, FOCUS 2011, Foundstone, France, France Law, French Law, Gartner, Gavin Struthers, George Kurtz, Global Risk 2012 report, global threat intelligence, gold software support, google, government, GTI, Hackers, heidi klum, identity fraud, identity protection, IDF 2011, Incumbency Advantage Program, India, Initiative to Fight Cybercrime, innovation, integration, intel, intellectual property, intrusion prevention, iPad, IPv6, I Series, IT as a Service, IT Security market, Joe Sexton, julian Assange, kurtz, labs, law, LCEN, mac, Mac OS X, malware, Marc Olesen, mcaf.ee, McAfee, McAfee Application Control, McAfee Channel, McAfee Channel Partner, McAfee Cloud Security Platform, McAfee Data Loss Prevention, McAfee Employees, McAfee Firewall Enterprise, McAfee FOCUS, McAfee Identity Protection, McAfee Initiative to Fight Cybercrime, McAfee Labs, McAfee Labs Q3 Threat Report, McAfee Network Security Platform, McAfee Network Threat Response, McAfee Partner, McAfee Partner Learning Center, McAfee Partner of the Year Award, McAfee Partner Program, McAfee Partner Summit, McAfee Rewards, McAfee Security Management, mcafee total protection, McAfee Vulnerability Manager, Microsoft, Microsoft Security Bulletin, Mid-Market, Middle East, Mike Decesare, Mike Fey, Mobile, mobile applications, Mobile Data Protection, mobile malware, mobile security, MS12-020, M Series, national cybersecurity awareness month, National Cyber Security Awareness Week, NCSA, Network Security, Next Generation, next generation data center, Night Dragon, NitroSecurity, Nitro Security, north america, OCTO, Operation Aurora, Operation Shady RAT, PARC, Partner Acceleration Resource Center, Partner Care, partners, Partner Summit, Patch Tuesday, Paul Otellini, PCI, PCI DSS, Pemberton, peter king, policies, president obama, privacy, Products, promotion, Public Sector, quarterly threat report, regulation, regulations, Renee James, risk, risk and, Risk and Compliance, Risk Management, Riverbed, ROI, RSA, RSA 2010, s, SaaS, SaaS Monthly Specialization, safe, SAIC, Saudi Arabia, SCADA, scareware, security, Security-as-a-Service, Security Connected, security management, short url, SIEM, Small Business, Smart Grid, smartphones, SMB, SMB Advisor Tool, SMB Extravaganza, SMB Specialization, social media, social networking, social networks, social responsibility, solid state drive, spam, Steve Jobs, Stop.Think.Connect, Support, targeted attacks, TCO, Tech Data, technology trends, Telecommunications, The VARGuy, threat reduction, thurber, Todd Gebhart, Trust and Safety, twitter, UAE, Ultrabook, Underground Economies, United Arab Emirates, Vanity Fair, Virtualization, Virtual Sales Kickoff 2012, virus, VMworld 2011, WAN, Web 2.0, web security, wikileaks

Vietnamese Speakers Targeted In Cyberattack by George Kurtz

Tuesday, March 30, 2010 at 4:28pm by Archive
Archive

By now, you may have seen the Google blog post talking about the targeted attacks against the computers of Vietnamese speakers and others. The botnet, which McAfee identified while investigating Operation Aurora, has commandeered these computers in what appears to be a politically motivated attack. McAfee has been sharing the results of its investigation with Google as it unfolded.

Attackers created the botnet by targeting Vietnamese speakers with malware that was disguised as software that allows Windows to support the Vietnamese language. The keyboard driver known as VPSKeys is popular with Vietnamese Windows users and is needed to be able to insert accents at the appropriate locations when using Windows.  

The bot code masquerading as a keyboard driver finds its way onto computers that, once infected, join a botnet with command and control systems located around the globe that are accessed predominantly from IP addresses inside Vietnam.

We suspect the effort to create the botnet started in late 2009, coinciding by chance with the Operation Aurora attacks. While McAfee Labs identified the malware during our investigation into Operation Aurora, we believe the attacks are not related. The bot code is much less sophisticated than the Operation Aurora attacks.  It is common bot code that could use infected machines to launch distributed denial of service attacks, monitor activity on compromised systems and for other nefarious purposes.

We believe the attackers first compromised www.vps.org, the Web site of the Vietnamese Professionals Society (VPS), and replaced the legitimate keyboard driver with a Trojan horse.  The attackers then sent an e-mail to targeted individuals which pointed them back to the VPS Web site, where they downloaded the Trojan instead.

The rogue keyboard driver, dubbed W32/VulcanBot by McAfee, connected the infected machines to a network of compromised computers. During our investigation into the botnet we found about a dozen command and control systems for the network of hijacked PCs. The command and control servers were predominantly being accessed from IP addresses in Vietnam.

The Trojan installs the following malware on the infected system:

    * %UserDir%Application DataJavajre6binjucheck.exe

    * %UserDir%Application DataJavajre6binzf32.dll

   * %UserDir%Application DataMicrosoftInternet ExplorerQuick LaunchVPSKEYS 4.3.lnk

    * %RootDir%Program FilesAdobeAdobeUpdateManager.exe

    * %RootDir%Program FilesJavajre6binjucheck.exe

    * %RootDir%Program FilesMicrosoft OfficeOffice11OSA.exe

    * %SysDir%mscommon.inf

    * %SysDir%msconfig32.sys

    * %SysDir%zf32.dll

    * %SysDir%SetupAdobeUpdateManager.exe

    * %SysDir%Setupjucheck.exe

    * %SysDir%SetupMPClient.exe

    * %SysDir%SetupMPSvc.exe

    * %SysDir%SetupOSA.exe

    * %SysDir%Setupwuauclt.exe

    * %SysDir%Setupzf32.dll

These files, when executed, initiate connections to the following domains:

    * google.homeunix.com

    * tyuqwer.dyndns.org

    * blogspot.blogsite.org

    * voanews.ath.cx

    * ymail.ath.cx

While originally some of these domains and files had been reported to be associated with Operation Aurora, we have since come to believe that this malware is unrelated to Aurora and uses a different set of Command & Control servers.

We believe that the perpetrators may have political motivations and may have some allegiance to the government of the Socialist Republic of Vietnam. The charter of the Vietnamese Professionals Society is to increase the knowledge and understanding of the social and economic conditions in the Southeast Asian country, according to Wikipedia.

McAfee added detection of the malware in January, around the same time we provided protection for Operation Aurora related malware.  The botnet is still active and attacks from the botnet continue today.

This incident underscores that not every attack is motivated by data theft or money. This is likely the latest example of hacktivism and politically motivated cyberattacks, which are on the rise and a topic we at McAfee have often discussed in our publications. In an excellent paper on Cybercrime and Hacktivism published this month, Researcher Francois Paget discusses the topic at length. It is also covered in our most recent Quarterly Threat Report.

As these events unfold, we will continue to keep you updated.  

You can follow McAfee CTO George Kurtz on Twitter

Bookmark and Share

Tags:

Comments are temporarily suspended due to blog maintenance, comments will be available again from Monday 21st May.