ie8 fix
madison

Shady RAT not so sophisticated: Symantec

Michael Lee, ZDNet Australia | August 5, 2011 6:43 AM PDT

Summary

Symantec has conducted its own investigation into the global hacking operation that McAfee has dubbed Operation Shady RAT, and called into question whether the attacks were really all that sophisticated.

Building on top of McAfee's report on a global hacking operation nicknamed Shady Rat, Symantec's investigation, written by Hon Lau on the security company's blog, explains how organizations were initially targeted, using emails with attachments that contained exploit code. The attachments seemed typically harmless, being Word, Excel, PowerPoint and PDF documents; however, when opened on unpatched systems, it dropped a trojan at the same time as displaying the expected document.

The trojan itself downloaded images and HTML pages from remote sites, which seemed innocent enough, but according to Lau, actually contained hidden or encrypted instructions that allowed it to contact the command and control server and let attackers know it has compromised its target.

While this level of infiltration might seem highly sophisticated, McAfee noted in its report that "this is not a new attack". Lau stated that "while this attack is indeed significant, it is one of many similar attacks taking place daily". In fact, Lau has raised the question of whether the hackers were really all that sophisticated to begin with.

"The attackers not only failed to secure their server properly, they had also installed various web traffic analysis tools on it too," he wrote. "For example, on one of the sites, we were able to see the statistics about computers contacting the command and control server to download command files."

For more on this story, read Shady RAT not so sophisticated: Symantec on ZDNet Australia.

9
Comments

Join the conversation!

Just In

RE: Shady RAT not so sophisticated: Symantec
Metin2 17th Mar
Each system is a deficit. Certainly this has something to do. Before them the availability of important gaps in the u

http://m2oyna.com http://pvp-serverlar.in
Typical McAfee scare tactics. Wonder how many of us, including myself, got emails from McAfee offering good deals on their security system. I regard this as spam.
0 Votes
+ -
@ITOdeed Is there anyone on ZDNet who doesn't believe a subset of companies (Microsoft, Apple, HP, McAfee, Symantec, Adobe, Nokia, RIM, Sony, and/or Google) are out to get them and literally sit down and plan to intentionally introduce bugs into their products, spy on them, steal their information, steal their money, invent false products or false claims against their competitors, and conduct elaborate frauds worthy of a Bernie Madoff/Steven Spielburg co-production?

ITO - how is it a "scare tactic"? Symantec is confirming operation Shady RAT is REAL. It HAPPENED. The server McAfee talked about is REAL. All they're saying is that they don't think this was that hard to do. That's EVEN SCARIER.
If you want a conspiracy theory at all, it should be to say that Symantec is showing sour grapes because they didn't take credit for uncovering this systemic IP theft first.
@ITOdeed
Then get off ther mailing lists; they'll honor the request if you smply use the link to their URLs.
I find McAfee quite user unfriendly and hard to understand what it's doing though it's been three years since I last tested them.
Symantec/Norton however are right on top of the situatioin and to date I've never had anything noted elsewhere to not be on Norton unless it was a one-up. Even hoaxes are listed. Their heurstics are also great, I've found, and though I've only had two heurstc hits, both were spot-on.
My only complaint about Symantec/Norton is they're getting too expensive, especially their subscriptions. I would have already switched, but so far no one gives me the turn-key effective relability that Norton does.
- Get fome free AVG
- Keep your Computer up to dates with Auto-Updates
- Live behind a firewall
- Don't be a dumbass with offers 'too good to be true', they are.
- Back your PC up
- Set your AV to do a daily sweep

You will have little real chance of an virus/malware etc infestation on your kit.

The number of friends with expired trial AV, and Windows updates off and a laptop with leoprosy is hugely frustrating, esp. when they rock up and expect me to fix it, though it saves on beer costs happy
Mt2 turk MMO PvP game download online game servers
metin2 - metin2 indir - metin2 hile - metin2 gm komutlari - metin2 at gorevleri
MMO online games, game related content turk mt2 pvp servers
metin 2 - pvp - server - knight
Mt2 turk MMO PvP game servers online
metin2 pvp sererler - serverlar - pvp serverler - metin2 pvp sererlar - pvp kenti

download http://www.metin2oyunu.org game servers online http://www.metin2pvpserver.net turk mt2 pvp servers http://www.metin2pvpserverlar.com
Each system is a deficit. Certainly this has something to do. Before them the availability of important gaps in the u

http://m2oyna.com http://pvp-serverlar.in
0 Votes
+ -
Get professional results GHD Straighteners with ghd's brand new GHD Hair Australia collection of 10 brushes GHD Hair Straighteners Cheap and 2 combs ? developed GHD Collection with professional stylists Ghd Kiss to give you a smooth Ghd Pink 2009 and sleek finish Ghd Purple Sale to your style. yongfengying2
0 Votes
+ -
Collection sale in 2011 Tod Sale Stylish womens Tods Tods Bags Sale Shoes on Todsonsale Tods Outlet Online Store. Brand Cheap Tods Floral Lace New & Authentic Quality. Tods Flats Free Shipping + Best Discount, Tod's Gommino About 9 business days To Tod's Mens Shoes Your Door! Feature of Tods Snakeskin Tods Gommno Shoes Black Red. yonfengying2

Join the conversation!

Formatting +
BB Codes - Note: HTML is not supported in forums
  • [b] Bold [/b]
  • [i] Italic [/i]
  • [u] Underline [/u]
  • [s] Strikethrough [/s]
  • [q] "Quote" [/q]
  • [ol][*] 1. Ordered List [/ol]
  • [ul][*] · Unordered List [/ul]
  • [pre] Preformat [/pre]
  • [quote] "Blockquote" [/quote]
ie8 fix

The best of ZDNet, delivered

ZDNet Newsletters

Get the best of ZDNet delivered straight to your inbox

Facebook Activity

ie8 fix