Symantec identifies group behind cyber attacks in Pakistan\, Turkey

Symantec identifies group behind cyber attacks in Pakistan, Turkey

IANS  |  San Francisco 

California-headquartered global cybersecurity company said it has identified the group behind a recent series of cyber attacks designed to gather intelligence from Pakistan, Turkey, Russia, Saudi Arabia, Afghanistan, and some regions in and

Seedworm has been operating since at least 2017, with its most recent activity observed in December 2018, Symantec's (MATI) team said in a blog post on Tuesday.

The researchers found a repository used by the group to store their scripts, as well as several the group uses to exploit victims once they have established a foothold in their network.

"In September 2018, we found evidence of Seedworm and the group (aka Swallowtail, Fancy Bear), on a computer within the Brazil-based embassy of an oil-producing nation," said the researchers.

Access to the victim's email, social media, and chat accounts is one of the group's likely goals, according to the researchers.

"Since its existence first came to light, we've seen Seedworm modify the way it operates. Since early 2017, they have continually updated their Powermud backdoor and other tools to avoid detection and to thwart researchers analysing the tools," the blog post said.

"They've also used to store malware and a handful of publicly available tools, which they then customise to carry out their work," it added.

The researchers analysed data on 131 victims that were compromised by Seedworm's Powermud backdoor from late September to mid-November 2018.

The and IT services sectors were their main targets, the next most common group of victims was in the oil and gas sector, followed by universities and embassies, the findings showed.

--IANS

gb/sed

(This story has not been edited by Business Standard staff and is auto-generated from a syndicated feed.)

First Published: Wed, December 12 2018. 15:46 IST