{"id":319,"date":"2013-06-23T09:10:23","date_gmt":"2013-06-23T09:10:23","guid":{"rendered":"http:\/\/www.3lectrik.com\/normanshark\/?page_id=319"},"modified":"2013-11-10T19:51:18","modified_gmt":"2013-11-11T03:51:18","slug":"norman-shark-cyber-research-report-uncovers-first-large-cyber-espionage-activity-emanating-from-india","status":"publish","type":"page","link":"https:\/\/www.3lectrik.com\/normanshark\/news-events\/press-releases\/norman-shark-cyber-research-report-uncovers-first-large-cyber-espionage-activity-emanating-from-india\/","title":{"rendered":"Norman Shark Cyber Research Report Uncovers First Large Cyber Espionage Activity Emanating From India"},"content":{"rendered":"<h1>Norman Shark Cyber Research Report Uncovers First Large Cyber Espionage Activity Emanating From India<\/h1>\n<p>Report Shows Worldwide Attacks on Commercial Businesses and National Security Interests<\/p>\n<p><strong>OSLO and SAN DIEGO, May 21, 2013<\/strong>\u00a0&#8211; Norman Shark, the global security leader in malware analysis solutions for enterprise, service providers and government, today released a report detailing a large and sophisticated cyber-attack infrastructure that appears to have originated from India.\u00a0 The attacks, conducted by private threat actors over a period of three years and still ongoing, showed no evidence of state-sponsorship but the primary purpose of the global command-and-control network appears to be intelligence gathering from a combination of national security targets and private sector companies.<\/p>\n<p>\u201cThe data we have appears to indicate that a group of attackers based in India may have employed multiple developers tasked with delivering specific malware,\u201d commented Snorre Fagerland, head of research for Norman Shark labs in Oslo, Norway. \u201cThe organization appears to have the resources and the relationships in India to make surveillance attacks possible anywhere in the world.\u00a0 What is surprising is the extreme diversity of the sectors targeted, including natural resources, telecommunications, law, food and restaurants, and manufacturing.\u00a0 It is highly unlikely that this organization of hackers would be conducting industrial espionage for just its own purposes\u2014which makes this of considerable concern.\u201d<\/p>\n<p>The investigation revealed evidence of professional project management practices used to design frameworks, modules, and subcomponents.\u00a0 It seems that individual malware authors were assigned certain tasks, and components were \u201coutsourced\u201d to what appear to be freelance programmers.\u00a0 \u201cSomething like this has never been documented before\u201d, Fagerland added.<\/p>\n<p>The discovery is currently under investigation by national and international authorities.<\/p>\n<p>The discovery began on March 17th when a Norwegian newspaper reported that Telenor, one of the world\u2019s largest mobile phone operators, a member of the world\u2019s top 500 companies, and Norway\u2019s major telecommunications company, had filed a criminal police case for an unlawful computer intrusion.\u00a0 Spear phishing emails targeting upper management appeared to be the source of the infection.<\/p>\n<p>The behavior pattern and file structure of malware files made it possible, for security analysts at Norman Shark, to search internal and public databases for similar cases utilizing Norman Shark\u2019s Malware Analyzer G2 automatic analysis systems.\u00a0 The amount of malware found by Norman Shark analysts and their partners was surprisingly large and it became clear the Telenor intrusion was not a single attack, but part of a continuous effort to compromise governments and corporations worldwide.<\/p>\n<p>Norman Shark titled the report \u201c<a  href=\"http:\/\/enterprise.norman.com\/resource_center\/unveiling_an_indian_cyberattack_infrastructure-a_special_report\">Operation Hangover<\/a>\u201d after one of the cyber espionage malwares most frequently used in this case.<\/p>\n<p>Based on an analysis of IP addresses collected from criminal data stores discovered during the investigation, it appears that potential victims have been targeted in more than a dozen countries.\u00a0 Specific targets include government, military and business organizations.\u00a0 Attribution to India was based on an extensive analysis of IP addresses, website domain registrations, and text-based identifiers contained within the malicious code itself.<\/p>\n<p>Despite all of the recent media attention on so-called \u201czero day\u201d exploits encompassing brand new attack methods, Operation Hangover appears to have relied on well-known, previously identified vulnerabilities in Java, Word documents, and web browsers.<\/p>\n<p>\u201cThis type of activity has been associated primarily with China over the past several years but to our knowledge, this is the first time that evidence of cyber espionage has shown to be originating from India,\u201d Fagerland concluded.\u00a0 \u201cOur study, available on the Norman Shark website (www.norman.com) provides assistance in what security teams need to look for.\u201d<\/p>\n<section>\n<div>\n<h1>Contact Information<\/h1>\n<\/div>\n<\/section>\n<section>\n<div>\n<div>\n<div>\n<p>Stein Surlien, CEO Norman Shark<br \/>\nMob:+ 47 911 16\u00a0240 Email:\u00a0<a  href=\"mailto:stein.surlien@norman.com\">stein.surlien@norman.com<\/a><\/p>\n<p>Kellyn Bartlett, VP Marketing, Norman Shark<br \/>\nEmail:\u00a0<a  href=\"mailto:kellyn.bartlett@3lectrik.com\/normanshark\">kellyn.bartlett@3lectrik.com\/normanshark<\/a><\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/section>\n","protected":false},"excerpt":{"rendered":"<p>Norman Shark Cyber Research Report Uncovers First Large Cyber Espionage Activity Emanating From India Report Shows Worldwide Attacks on Commercial Businesses and National Security Interests OSLO and SAN DIEGO, May 21, 2013\u00a0&#8211; Norman Shark, the global security leader in malware analysis solutions for enterprise, service providers and government, today released a report detailing a large [&hellip;]<\/p>\n","protected":false},"author":15,"featured_media":0,"parent":66,"menu_order":0,"comment_status":"open","ping_status":"open","template":"","meta":{"footnotes":""},"class_list":["post-319","page","type-page","status-publish","hentry"],"jetpack_shortlink":"https:\/\/wp.me\/P5TlPb-59","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/www.3lectrik.com\/normanshark\/wp-json\/wp\/v2\/pages\/319","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.3lectrik.com\/normanshark\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.3lectrik.com\/normanshark\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.3lectrik.com\/normanshark\/wp-json\/wp\/v2\/users\/15"}],"replies":[{"embeddable":true,"href":"https:\/\/www.3lectrik.com\/normanshark\/wp-json\/wp\/v2\/comments?post=319"}],"version-history":[{"count":4,"href":"https:\/\/www.3lectrik.com\/normanshark\/wp-json\/wp\/v2\/pages\/319\/revisions"}],"predecessor-version":[{"id":1257,"href":"https:\/\/www.3lectrik.com\/normanshark\/wp-json\/wp\/v2\/pages\/319\/revisions\/1257"}],"up":[{"embeddable":true,"href":"https:\/\/www.3lectrik.com\/normanshark\/wp-json\/wp\/v2\/pages\/66"}],"wp:attachment":[{"href":"https:\/\/www.3lectrik.com\/normanshark\/wp-json\/wp\/v2\/media?parent=319"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}