Report: Cyber Attacks Against Middle East Embassies

Report: Cyber Attacks Against Middle East Embassies

This post is also available in: heעברית (Hebrew)

Recent cyber attacks on Middle East embassies were conducted using targeted e-mail messages. The e-mail subject was the Syrian civil war, in an effort to fool the targets into opening the attached malicious files.

24940638_s featureMicrosoft, in late November 2013, reported zero-day attacks against Windows XP based systems and Server 2003 servers. Investigation revealed that the attackers used advanced backdoor techniques.

According to the Trend Micro blog post the attacks targeted 28 embassies in a certain Middle Eastern capital city. The attacks were conducted using malware attached to targeted e-mail messages. The subject of these messages was the Syrian civil war, in an attempt to fool the targets into opening the attached files.

IHLS – Israel Homeland Security

Company researchers added that in addition to the targeted attacks and the use of anti-analysis techniques there was no other unusual activity. The backdoor technique was identified was BKDR_TAVDIG.GUD, meant to hide it from bug-detection software and make it harder for analysts to identify it.

In addition, according to the list of targets, the high motivation and the capabilities needed to conduct a complex operation, the resources of the attackers are well beyond those of regular hackers. The results of the attack – which embassies were damaged and how severely – couldn’t be verified. Researchers are also not sure if there were any additional targets.