Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Security > Security Blog

February 22nd, 2013, 10:32 GMT · By

BLOG

Cybercriminals Use Chinese Cyber Espionage Report to Spread Malware

SHARE:

Adjust text size:


Malicious emails carry fake Mandiant report Enlarge picture - Malicious emails carry fake Mandiant report
Everyone’s talking these days about the “APT1: Exposing One of China's Cyber Espionage Units” report released by Mandiant. Cybercriminals are also leveraging the story in an attempt to spread a piece of malware.

According to Symantec, it all starts with an apparently innocent email that contains an attachment called “Mandiant.pdf.” When opened, a blank PDF is shown, while an Adobe Reader exploit is triggered in the background.

Interestingly, the exploit analyzed by Symantec failed to drop any malware onto the computer. However, Brandon Dixon, a security intelligence engineer at VERISIGN, has identified a different variant.

In his case, the attachment, a file called “Mandiant_APT2_Report.pdf,” was password-protected. When executed, the genuine Mandiant report is opened, while a new process is executed.

The payload connects to a domain that’s been previously seen in attacks against human rights activists. The domain in question was flagged as hosting malware on both Mac and Windows systems.
FILED UNDER:
malware
spam
scam

TELL US WHAT YOU THINK:

1,413 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Experts Criticize Report on Cyberattacks Launched by Chinese Military

US Says Trade Secrets Are at Risk of Being Stolen by China, Russia and WikiLeaks

Mandiant Used Data Leaked by Anonymous in 2011 to Investigate Chinese Hackers

Chinese Defense Ministry: We Are Not Hacking the US, Mandiant Is Wrong

Hackers Working for Chinese Military: Ugly Gorilla, DOTA, SuperHard

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM