Home / Business Scene / ‘Safe’ Attacks on Ministries and Media

‘Safe’ Attacks on Ministries and Media

The targeted attack campaign, named Safe, threatens government ministries, technology companies, media, academic and scientific institutions, and non-governmental organizations.

Whether it involves spyware attacks or something considered a persistent and increasingly dangerous attempt at successful long-term security compromise of organizations and companies – it is something that can no longer be ignored. While ‘louder’ security campaigns are becoming more well-known in the security community, new, smaller campaigns that utilize new tools and attack methods are constantly emerging.

The document provides a list of attack campaigns and operations capable of compromising the security of these types of organizations:

• government ministries
• technology companies
• media
• academic and scientific institutions
• non-governmental agencies

The method of distributing attack campaigns that threaten security consists of carefully targeted email messages that carry a dangerous attachment, a piece of malware that exploits vulnerabilities in Microsoft Office (CVE-2012-0158) and aims to steal user identities (so-called phishing).

An investigation by Trend Micro, which focused on C&C servers found to be linked to this campaign, revealed software archives consisting of source code written in PHP, which attackers use to create C&C servers, and code written in C, which they use to write malware that was utilized in the executed attacks.

Although it is very difficult to ascertain the true intentions and identity of the attackers, Trend Micro estimates that the campaign is targeted and utilizes malware developed by professional software engineers who may be connected to the criminal cyber underground in China. However, it cannot be said with complete certainty whether those conducting the attack campaigns and those who wrote the malware are connected.

This document (white paper) was written to better understand and describe the tools, tactics, and methods used in the campaign. All findings that Trend Micro has reached through research on new threats, along with everything that indicates that there has been a compromise of the security of the attacked company or organization, and recommendations on what to do to protect oneself, can be found in our research report which you can download here.

Targeted attacks are attacks that appear to be aimed at compromising specific entities or organizations. Unlike non-selective, arbitrary cyber attacks carried out by criminals, spam messages (commercial email messages, unwanted content), web threats, and similar threats, targeted attacks are much harder to detect due to the nature of the methods they employ and the software components they consist of. To protect companies from these targeted attacks and threats that are constantly occurring in real-time, Trend Micro recommends comprehensive risk management as a strategy that goes far beyond advanced protection.