{"id":303,"date":"2013-06-23T08:51:23","date_gmt":"2013-06-23T08:51:23","guid":{"rendered":"http:\/\/www.3lectrik.com\/normanshark\/?page_id=303"},"modified":"2013-09-26T15:48:43","modified_gmt":"2013-09-26T22:48:43","slug":"study-shows-israel-and-palestinian-territories-under-cyber-attack-from-same-source-for-more-than-one-year","status":"publish","type":"page","link":"https:\/\/www.3lectrik.com\/normanshark\/news-events\/press-releases\/study-shows-israel-and-palestinian-territories-under-cyber-attack-from-same-source-for-more-than-one-year\/","title":{"rendered":"Study Shows Israel and Palestinian Territories under Cyber Attack from Same Source for More Than One Year"},"content":{"rendered":"<h1>Study Shows Israel and Palestinian Territories under Cyber Attack from Same Source for More Than One Year<\/h1>\n<p><em>Recent Trojan Computer Attacks on Israeli Police, Foreign Ministry and Embassies<\/em><\/p>\n<p><strong>SAN DIEGO, November 12, 2012<\/strong>\u00a0\u2013 An in depth analysis of millions of malware samples dating back to October 2011, has revealed that many of the recent attempts by the Israel government to prevent Trojan injections into sensitive police, ministry and embassy computers, may have been too late.\u00a0 According to Norman Shark, a leading malware analysis firm with offices in Oslo, Norway and San Diego, California, multiple malware attacks against Israeli and Palestinian targets have been going on for at least a year\u2014first focused on Palestinian, then Israel. A few weeks ago, Israeli law enforcement discovered messages wrongly identified as coming from Israeli Defense Force Chief of Staff Benny Gantz.\u00a0 This was their first notice of a possible attack.\u00a0 Similar messages had also gone out to Israeli embassies around the world.\u00a0 When unsuspecting recipients opened the email, they found an archive attached containing a surveillance tool camouflaged as a document. When opened, hackers could steal information and remotely take control of the computer.<\/p>\n<p>In an attempt to discover if this was an isolated incident or something more significant, Norman Shark researchers ran samples from Norman Shark\u2019s large database of known malware through the company\u2019s malware analyzer.\u00a0 It appears that the attacks were performed by the same attacker, as the malware in question communicate with the same command-and-control structures, and in many cases are signed using the same digital certificate.\u00a0 While unknown at this point, the purpose is assumed to be espionage and surveillance.<\/p>\n<p>Norman Shark Vice President Einar Oftedal, is available to provide additional details and commentary on this news and Norman Shark\u2019s analysis.<\/p>\n<p>The hackers first directed malware network traffic to command and control servers in the Gaza Strip, and then to hosting companies in the U.S. and U.K. according to the investigation.<\/p>\n<p>\u201cThe attacker is still unknown to us\u201d commented Oftedal.\u00a0 \u201cThere are several possible alternatives based on the various power blocks in the region.\u00a0 One thing is for certain, with off-the-shelf malware available to anyone, the cost of mounting such an operation is low enough that anyone could be behind it.\u201d The malware used was in most cases shown to be XtremeRat, a commercially-available surveillance and remote administration tool.<\/p>\n<section>\n<div>\n<h1>Contact Information<\/h1>\n<\/div>\n<\/section>\n<section>\n<div>\n<div>\n<div>\n<p>Stein Surlien, CEO Norman Shark<br \/>\nMob:+ 47 911 16\u00a0240 Email:\u00a0<a  href=\"mailto:stein.surlien@norman.com\">stein.surlien@norman.com<\/a><\/p>\n<p>Isabella Alveberg, CMO Norman Shark<br \/>\nMob:+ 47\u00a0957 30\u00a0578 \u00a0Email:\u00a0<a  href=\"mailto:isabella.alveberg@norman.com\">isabella.alveberg@norman.com<\/a><\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/section>\n","protected":false},"excerpt":{"rendered":"<p>Study Shows Israel and Palestinian Territories under Cyber Attack from Same Source for More Than One Year Recent Trojan Computer Attacks on Israeli Police, Foreign Ministry and Embassies SAN DIEGO, November 12, 2012\u00a0\u2013 An in depth analysis of millions of malware samples dating back to October 2011, has revealed that many of the recent attempts [&hellip;]<\/p>\n","protected":false},"author":15,"featured_media":0,"parent":66,"menu_order":0,"comment_status":"open","ping_status":"open","template":"","meta":{"footnotes":""},"class_list":["post-303","page","type-page","status-publish","hentry"],"jetpack_shortlink":"https:\/\/wp.me\/P5TlPb-4T","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/www.3lectrik.com\/normanshark\/wp-json\/wp\/v2\/pages\/303","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.3lectrik.com\/normanshark\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.3lectrik.com\/normanshark\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.3lectrik.com\/normanshark\/wp-json\/wp\/v2\/users\/15"}],"replies":[{"embeddable":true,"href":"https:\/\/www.3lectrik.com\/normanshark\/wp-json\/wp\/v2\/comments?post=303"}],"version-history":[{"count":4,"href":"https:\/\/www.3lectrik.com\/normanshark\/wp-json\/wp\/v2\/pages\/303\/revisions"}],"predecessor-version":[{"id":1168,"href":"https:\/\/www.3lectrik.com\/normanshark\/wp-json\/wp\/v2\/pages\/303\/revisions\/1168"}],"up":[{"embeddable":true,"href":"https:\/\/www.3lectrik.com\/normanshark\/wp-json\/wp\/v2\/pages\/66"}],"wp:attachment":[{"href":"https:\/\/www.3lectrik.com\/normanshark\/wp-json\/wp\/v2\/media?parent=303"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}