13:29 GMT +312 December 2017
Listen Live
    has discovered that a group of hackers, dubbed the ‘Desert Falcons’ has been actively operating in the Middle

    Middle Eastern Hackers 'Desert Falcons' Stalk Online Prey in 50 Countries

    © AFP 2017/ THOMAS SAMSON
    Tech
    Get short URL
    0 15

    The Russia-based computer security group Kaspersky has made a new revelation – it has discovered that a group of hackers, dubbed the ‘Desert Falcons’ has been actively operating in the Middle East for at least two years, and has targeted more than 3,000 victims in over 50 countries.

    A team of hackers, which Kaspersky Lab's Global Research and Analysis Team has dubbed the ‘Desert Falcons’, has been discovered; they operate from the Middle East.

    It is apparently the first known Arabic hacker group capable of developing and implementing cyber-espionage operations. Kaspersky Lab says it has multiple reasons to believe that the attackers are native Arabic speakers.

    The team has been targeting military and government institutions, leading media outlets, research and education institutions, energy and utilities providers, activists and political leaders, physical security companies, as well as others thought to possess important geopolitical information.

    So far, 100 of the malware samples that have been passed around by the attackers have now been tagged by Kaspersky Lab.

    The Kaspersky team says the Desert Falcons first came into being in 2011 when they started developing and building their operation. However, the real infection was launched in 2013, with the peak of the activity registered last month.

    The hacker group is believed to have at least 30 members who operate in three teams which are spread across different countries.

    The countries targeted the most are said to be Egypt, Palestine, Israel and Jordan. However, victims have also been found in Qatar, United Arab Emirates, Saudi Arabia, Algeria, Lebanon, Turkey and the US. There malware has also penetrated into Europe, infecting Norway, Sweden, France and Russia.

    The group is mostly using the spear phishing method of penetration via e-mails, social media posts and chat messages, targeting primarily Windows computers and Android-based gadgets.

    The attackers are believed to have been using the right-to-left extension override trick to entice victims into running the malicious files accompanying their phishing messages. The trick reverses the order of characters in a file name, hiding the dangerous file extension in the middle of the file name; it puts a harmless-looking file extension at the end to make the malware look like a harmless document or pdf file, prompting the user to open it.

    Once opened, the file infects the gadget, providing hackers with an opportunity to take screenshots, log keystrokes, upload/download files, collect information about all Word and Excel files on the victim's hard disk or connected USB devices, steal passwords stored in the system registry and make audio recordings.

    Earlier in the week, Kaspersky Lab made reports about another cyber-espionage group that infected over 500 computers in more than 30 countries, targeting governments and financial institutions among others.

    Equation Group was not linked to any country, but Kaspersky Lab hinted at links between the recently found malware and Stuxnet, a worm allegedly used by the US National Security Agency against Iran's nuclear facility in 2010.

    Related:

    Pakistan Arrests Two Hackers Wanted by Interpol, FBI
    Obama to Sign Proposal on Private Companies Data Sharing to Deter Hackers
    US Creates Cyber-CIA to Fight Hackers
    New Snowden Docs: Western Spy Agencies Rely on Hackers
    Tags:
    Middle East, malware, spyware, hackers, Kaspersky Lab
    Community standardsDiscussion
    Comment via FacebookComment via Sputnik
    • Сomment