Global spy campaign targeting nuclear\, defence companies identified

Global spy campaign targeting nuclear, defence companies identified

IANS  |  San Francisco 

Researchers at cybersecurity have discovered a new global campaign targeting nuclear, defence, and financial companies.

This campaign, while masquerading as legitimate industry job recruitment activity, gathers information to monitor for potential exploitation, the Santa Clara, California-headquartered said in a blog post on Wednesday.

The espionage programme has links to the which is believed to have connections to the

This campaign, dubbed Operation Sharpshooter, leverages an in-memory implant to download and retrieve a second stage implant -- which calls -- for further exploitation.

According to the cybersecurity company's analysis, the implant uses source code from the Lazarus Group's 2015 backdoor Trojan Duuzer in a new framework to infiltrate these key industries.

McAfee researchers found that the implant appeared in 87 organisations across the globe, predominantly in the US, between October and November 2018.

Based on other campaigns with similar behaviour, most of the targeted organisations are English speaking or have an English-speaking regional office, McAfee's and Asheer Malhotra wrote.

The McAfee Advanced Threat Research team found that the majority of targets were defence and government-related organisations.

--IANS

gb/bg

(This story has not been edited by Business Standard staff and is auto-generated from a syndicated feed.)

First Published: Thu, December 13 2018. 14:18 IST