- Blue Coat Selects Norman Shark As Malware Analysis Technology Partner
- Norman Shark to Announce Malware Analyzer G2 v4.0 and Updated Network Threat Discovery at Black Hat 2013
- Norman Shark Cyber Research Report Uncovers First Large Cyber Espionage Activity Emanating From India
- Norman Shark to Launch Norman Shark Network Protection Solution at RSA, Demos to be Available
- Norman AS splits company to maximize revenue
- Long Shadow Of Stuxnet Inspires Custom Anti-Malware Project
- Defense In Depth Enables Protection Of Critical Pipeline Assets
- Norman Shark to Sponsor Third Annual Securing Our eCity Cybersecurity Symposium 2012
- Study Shows Israel and Palestinian Territories under Cyber Attack from Same Source for More Than One Year
- Systematic cyber attacks against Israeli and Palestinian targets going on for a year
- Protecting Today’s SCADA-Based Mass Transit Systems Should Begin with a Defense-in-Depth
- The Wake Up Call: Hackers are Reported to have Caught the World’s Major Oil and Gas Companies Napping
- Norman Shark Malware Analyzer G2 Is Industry’s Most Flexible and Powerful Platform for Cyber Threat Discovery and Assessments
- Norman Shark Presents New Episode of Video Series to Continue Focus on Cybercrime Prevention among Executives
- Norman Shark Named as a Gartner “Vendor to Watch” in New Market Trends Report, Cites Norman Shark Network Threat Discovery and Malware Analyzer G2 Network Protection Solutions
- Norman Shark is shifting its U.S. headquarters from Washington, D.C., to San Diego
- Web security firm beefs up San Diego operation
- The Many Faces of Gh0st Rat
- Norman Shark Malware Analyzer G2 Is Industry’s Most Flexible and Powerful Platform for Cyber Threat Discovery and Assessments
- Norman Shark Announces SCADA Security OEM Partnership with Kongsberg Maritime to Protect Critical Oil, Gas and Maritime Industrial Environments Globally
- Norman Shark Customers Secured Against Flamer
Study Shows Israel and Palestinian Territories under Cyber Attack from Same Source for More Than One Year
Recent Trojan Computer Attacks on Israeli Police, Foreign Ministry and Embassies
SAN DIEGO, November 12, 2012 – An in depth analysis of millions of malware samples dating back to October 2011, has revealed that many of the recent attempts by the Israel government to prevent Trojan injections into sensitive police, ministry and embassy computers, may have been too late. According to Norman Shark, a leading malware analysis firm with offices in Oslo, Norway and San Diego, California, multiple malware attacks against Israeli and Palestinian targets have been going on for at least a year—first focused on Palestinian, then Israel. A few weeks ago, Israeli law enforcement discovered messages wrongly identified as coming from Israeli Defense Force Chief of Staff Benny Gantz. This was their first notice of a possible attack. Similar messages had also gone out to Israeli embassies around the world. When unsuspecting recipients opened the email, they found an archive attached containing a surveillance tool camouflaged as a document. When opened, hackers could steal information and remotely take control of the computer.
In an attempt to discover if this was an isolated incident or something more significant, Norman Shark researchers ran samples from Norman Shark’s large database of known malware through the company’s malware analyzer. It appears that the attacks were performed by the same attacker, as the malware in question communicate with the same command-and-control structures, and in many cases are signed using the same digital certificate. While unknown at this point, the purpose is assumed to be espionage and surveillance.
Norman Shark Vice President Einar Oftedal, is available to provide additional details and commentary on this news and Norman Shark’s analysis.
The hackers first directed malware network traffic to command and control servers in the Gaza Strip, and then to hosting companies in the U.S. and U.K. according to the investigation.
“The attacker is still unknown to us” commented Oftedal. “There are several possible alternatives based on the various power blocks in the region. One thing is for certain, with off-the-shelf malware available to anyone, the cost of mounting such an operation is low enough that anyone could be behind it.” The malware used was in most cases shown to be XtremeRat, a commercially-available surveillance and remote administration tool.
Contact Information
Stein Surlien, CEO Norman Shark
Mob:+ 47 911 16 240 Email: stein.surlien@norman.com
Isabella Alveberg, CMO Norman Shark
Mob:+ 47 957 30 578 Email: isabella.alveberg@norman.com

