Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Security > Virus alerts

March 6th, 2012, 15:06 GMT · By Eduard Kovacs

Malware Used to Spy on Syrians Detailed by Experts

SHARE:

Adjust text size:

DarkComet is used to spy on the citizens of Syria
Enlarge picture
Last month CNN reported that supporters of the Syrian regime developed a computer virus to spy on those who opposed the government. Trend Micro experts analyzed the DarkComet Remote Access Trojan (RAT) and revealed the way it's utilized along with its spreading mechanism.

Apparently, the malware spreads via the popular instant messaging platform Skype, in many situations bearing a Facebook icon.

After it’s executed, the piece of malware connects to a command and control (C&C) server hosted by Syrian Telecommunications Establishment.

The DarkComet RAT is highly complex, allowing its masters not only to take pictures with the infected machine’s webcam and record conversations via the attached microphone, but also to record keystrokes and transfer files.

While DarkComet’s developers are still working on improving it, recent reports claim that they regret their work is being used against the people of Syria. They also expressed their intent to create a DarkComet detector to aid Syrians protect their devices.

One of the variants of the malware analyzed by Trend Micros, identified as Bkds_Zapchast.SG, was DarkComet 5 and another version, Bkdr.Breut.A, was appointed as being DarkComet 3.3.

The latter drops two executable files, one of which is the Mac Address Changer tool. The second file is the one that actually causes all the damage, since it immediately connects to the C&C server and starts doing what it knows best.

“To date, we have analyzed 10 samples that connect to the same IP address and display this type of functionality. While some are 'downloaders' that display various decoy images 4, the ultimate payload in these attacks is either DarkComet RAT version 3.3 or version 5,” Trend Micro experts wrote.

Twitter is flooded with messages that reveal not only moral, but also material support for the people of Syria. Now, it remains to be seen if the efforts of the Syrian Electronic Army (a group that supports the local government) and state officials can be defeated by the Anonymous and the masses.
FILED UNDER:
DarkComet
RAT
Syria
spyware


2,744 hits · 1 comment
Link to this article · Print article · Send to friend

MUST-READ RELATED ARTICLES:


Hackers Around the World: It’s No TriCk, He’s Among the Best in the UK

TeaMp0isoN Leaks Military Bank Accounts in Support for Syria

Anonymous Egypt Takes Down Police and Government Sites

Anonymous Hacks Syrian Ministry of Public Administration

200,000 Webpages Compromised to Lead Visitors to Fake AV Sites

READER COMMENTS:


Comment #1 by: cantor on 07 Mar 2012, 21:36 UTC reply to this comment

Telecomix found that the spyware was DarkComet. The write up can be found here:
https://telecomix.ceops.eu/material/reports/2012-02-20-DarkComet-Spyware.html

Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM