Site Sponsor:

mcafee_logo.gif
line

Now Available:

Featured Resource:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Dan or post a comment to the blog.

« Beating Phishers the Old Fashioned Way | Main | Microsoft and Google Desktop/Web Integration Offer Too Little, Bring Too Many Risks »

Targeted Attack Steals Confidential Data from Government and Contractors in Transportation Sector

A password stealing program used against government agencies and contractors in the transportation sector netted hundreds of megs of password data. The information at this point indicates a clearly coordinated attack which (a) makes one ask why the transportation sector and (b) makes clear the capabilities of cybercriminals when it comes to stealing highly distributed information. In Government, contractors hit in targeted attack NetowrkWorld reports:

Computers belonging to the U.S. government, contractors and companies in the transportation industry were hit by a targeted computer attack in July that yielded password information for hundreds of Internet and intranet Web sites, a computer security vendor [Prevx] said Tuesday.

Prevx engineers traced the IP addresses and the concentration in the transportation sector was too high to be a coincidence:

"When we reverse-engineered the IP addresses of those computers, we couldn't believe that this was a daisy chain that led to government-associated sites and to other defense contractors, and to American Airlines," Morris said. "This was a very highly targeted attack."

The Trojan RSA-4096 to encrypt user data and gives a message like:

"Hello, your files are encrypted with RSA-4096 algorithm (http://en.wikipedia.org/wiki/RSA). You will need at least few years to decrypt these files without our software. All your private information for last 3 months were collected and sent to us. To decrypt your files you need to buy our software. The price is $300. To buy our software please contact us at: tristanniglam@gmail.com and provide us your personal code -xxxxxxxxx. After successful purchase we will send your decrypting tool, and your private information will be deleted from our system. If you will not contact us until 07/15/2007 your private information will be shared and you will lost all your data -- Glamorous team."

If the attackers wanted just money, why the focus on one industry? That doesn't make sense. Confidential data was the real target of this attack.

TrackBack

TrackBack URL for this entry:
http://www.realtime-websecurity.com/type/mt-tb.cgi/357

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Dan Sullivan's Bio:

Dan Sullivan is a systems architect with 20 years of IT experience that includes engagements in enterprise security, application design, and systems architecture. His experience includes a broad range of industries, including financial services, manufacturing, government, retail, gas and oil production, power generation, and education. Dan’s security-related project work has ranged from requirements analysis for enterprise information security to designing and implementing security for database applications and enterprise portals. Dan has written about information security and other enterprise information management topics for Business Security Advisor, DM Review, Intelligent Enterprise, and E-Business Advisor. You can contact Dan at: dan_sullivan@realtimepublishers.net