Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Security

January 13th, 2012, 10:23 GMT · By

Sykipot Trojan Improved to Hijack DoD Smart Cards

SHARE:

Adjust text size:

Sykipot attack scheme
Enlarge picture
Sykipot, the well-known Trojan that’s been targeting US companies since 2007, has been found by security researchers to have an improved version which is able to hijack smart cards utilized by the United States Department of Defense (DoD).

Researchers from AlienVault Labs reveal that cybercriminals attempt to penetrate security systems based on the protection measures implemented by the company they target.

If up until now attackers have been forced to rely on other vulnerable vectors because the authentication systems that relied on smartcards were hard to bypass, recent developments made to the Sykipot Trojan help them access an unauthorized system.

In spear phishing campaigns, the attackers send emails that contain a maliciously crafted PDF file. Once the file is opened, it deploys Sykipot onto the machine and uses a keylogger to steal the PINs of the cards that pass through the computer’s card reader.

In the timeframe during which the card is inserted into the card reader, the malware obtains the same rights as the authenticated user, possessing the necessary rights to access sensitive information that’s otherwise inaccessible.

The attack scenario that spreads using malicious PDF files makes use of a vulnerability found in Adobe Reader, but other methods could also be deployed with the same rate of success.

Trojans that target smartcards are not uncommon, but this particular attack variant originates from servers in China and targets the cards utilized by the DoD.

Due to the fact that unauthorized activity is performed only during the time in which the physical card is found in the card reader, these malicious operations are harder to detect and differentiate from legitimate ones.

“Although smart cards are designed to provide a two factor system of ‘chip and pin’, again we see that true two-factor authentication is not possible without a physical component that is not accessible digitally,” Jaime Blasco said.
FILED UNDER:
Sykipot
Trojan
smart card
DOD


1,702 hits
Link to this article · Print article · Send to friend

MUST-READ RELATED ARTICLES:


ConEdison Billing Notification Emails Hide Zbot Trojan

Carrier IQ Detection Tools Modified to Become SMS Trojans

German Federal Police Hacked As a Result of a Family Feud

2012 International Conference on Cyber Security Held at Fordham University

FBI: Beware of ‘Gameover’ Bank-Account-Stealing Malware

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM