. 24/7 Space News .
CYBER WARS
Updated Qbot virus attacks public sector organizations
by Richard Tomkins
London (UPI) Apr 12, 2016


disclaimer: image is for illustration purposes only

A new strain of Qbot malicious software that self-updates is being used to attack public sector organizations around the world, BAE Systems reports.

More than 54,000 computers in thousands of organizations -- such as police departments, hospitals and universities -- have been infected with the virus so far by cyber-criminals, according to its white paper report.

"Many public sector organizations are responsible for operating critical infrastructure and services, often on limited budgets, making them a prime target for attacks," said Adrian Nish, Head of Cyber Threat Intelligence at BAE Systems. "In this instance, the criminals tripped up because a small number of outdated PCs were causing the malicious code to crash them, rather than infect them. It was this series of crashes that alerted the organization to the spreading problem."

BAE Systems said Nash was referring to an organization that was attacked early this year, with 500 computers infected. An emergency response to the Qbot attack on the public sector organization gave BAE Systems insight into how the updated malware infects hosts, updates itself and hides from all but a very few antivirus and malware defenses.

"Qbot first came to light in 2009, but this new version is equipped with advanced tools to escape detection and infect quickly," he said.

The modified features include a "shape changing" or polymorphic code. Each time the malware's code was issued by the servers controlling it, it was compiled afresh with additional content, making it look like a completely different program to researchers looking for specific signatures.

Automated updates to the malware generated new, encrypted versions every six hours to update software on computers, which helped the virus to spread. It also checks for signs that it is running in a "sandbox" -- a tool used to spot malware before it reaches users' inboxes.

"This case illustrates that organisations must remain alert to, and defend against, new and evolving cyber threats," Nish said.

A BAE Systems specialist team came to understand the malware's command-and-control network to discover how stolen data was being uploaded. It also was able to identify how the programmers altered the destination of the stolen data each time to avoid detection and interception.


Thanks for being here;
We need your help. The SpaceDaily news network continues to grow but revenues have never been harder to maintain.

With the rise of Ad Blockers, and Facebook - our traditional revenue sources via quality network advertising continues to decline. And unlike so many other news sites, we don't have a paywall - with those annoying usernames and passwords.

Our news coverage takes time and effort to publish 365 days a year.

If you find our news sites informative and useful then please consider becoming a regular supporter or for now make a one off contribution.
SpaceDaily Contributor
$5 Billed Once


credit card or paypal
SpaceDaily Monthly Supporter
$5 Billed Monthly


paypal only


.


Related Links
Cyberwar - Internet Security News - Systems and Policy Issues






Comment on this article via your Facebook, Yahoo, AOL, Hotmail login.

Share this article via these popular social media networks
del.icio.usdel.icio.us DiggDigg RedditReddit GoogleGoogle

Previous Report
CYBER WARS
US fight goes on with Apple over iPhone access
New York (AFP) April 9, 2016
The US government is keeping its encryption battle with Apple alive, pressing the high-tech giant to help crack an iPhone in a drug case in New York. The Justice Department filed a letter in a US District Court on Friday telling a judge that it still wants Apple to extract pictures, text messages and other digital data from an iPhone used by someone accused of trafficking in methamphetamines ... read more


CYBER WARS
The Moon thought to play a major role in maintaining Earth's magnetic field

Moon Mission: A Blueprint for the Red Planet

The Lunar Race That Isn't

Earth's moon wandered off axis billions of years ago

CYBER WARS
Help keep heat on Mars Express through data mining

Ancient Mars bombardment likely enhanced life-supporting habitat

Opportunity's Devilish View from on High

Mars Longevity Champion Launched 15 Years Ago

CYBER WARS
Spanish port becomes global 'smart city' laboratory

Silicon Beach: LA tech hub where the sun always shines

New DNA/RNA Tool to Diagnose, Treat Diseases

ASU to develop the next generation science education courseware for NASA

CYBER WARS
China launches SJ-10 retrievable space science probe

Has Tiangong 1 gone rogue

China's 1st space lab Tiangong-1 ends data service

China's aim to explore Mars

CYBER WARS
Russian cargo ship docks successfully with space station

Russia launches cargo ship to space station

Cargo ship reaches space station on resupply run

Unmanned Cygnus cargo ship launches to ISS on resupply run: NASA

CYBER WARS
Orbital ATK receives NASA order for rockets

NASA Progresses Toward SpaceX Resupply Mission to Space Station

SpaceX lands rocket on water platform for first time

SpaceX to launch first cargo since 2015 accident

CYBER WARS
Searching for Far Out and Wandering Worlds

ALMA's most detailed image of a protoplanetary disc

Planet formation in Earth-like orbit around a young star

NASA's Spitzer Maps Climate Patterns on a Super-Earth

CYBER WARS
'Self-healing' plastic could mean better bandages, tougher phone cases

Ruthenium nanoframes open the doors to better catalysts

Artificial molecules

Record-breaking steel could be used for body armor, shields for satellites









The content herein, unless otherwise known to be public domain, are Copyright 1995-2024 - Space Media Network. All websites are published in Australia and are solely subject to Australian law and governed by Fair Use principals for news reporting and research purposes. AFP, UPI and IANS news wire stories are copyright Agence France-Presse, United Press International and Indo-Asia News Service. ESA news reports are copyright European Space Agency. All NASA sourced material is public domain. Additional copyrights may apply in whole or part to other bona fide parties. All articles labeled "by Staff Writers" include reports supplied to Space Media Network by industry news wires, PR agencies, corporate press officers and the like. Such articles are individually curated and edited by Space Media Network staff on the basis of the report's information value to our industry and professional readership. Advertising does not imply endorsement, agreement or approval of any opinions, statements or information provided by Space Media Network on any Web page published or hosted by Space Media Network. General Data Protection Regulation (GDPR) Statement Our advertisers use various cookies and the like to deliver the best ad banner available at one time. All network advertising suppliers have GDPR policies (Legitimate Interest) that conform with EU regulations for data collection. By using our websites you consent to cookie based advertising. If you do not agree with this then you must stop using the websites from May 25, 2018. Privacy Statement. Additional information can be found here at About Us.