Slashdot Mirror


'Madi' Cyber Espionage Malware Hits Middle East Targets

DavidGilbert99 writes "Following the discovery of the highly-complex Flame virus in May, two security companies (Seculert and Kaspersky Lab) have uncovered a new cyber-espionage threat against the Middle East. Madi, or Madhi, is an information-stealing trojan which is technically a lot simpler than Flame or Stuxnet but is specifically targeting people in critical infrastructure companies, financial services and government embassies, which are mainly located in Iran, Israel and Afghanistan. The Madi creators use social engineering techniques to spread, embedding the malware in various documents including text files and PowerPoint presentations. It is unclear if the malware is state-sponsored or not, but it has already stolen several gigabytes of information and is still active."

10 of 45 comments (clear)

  1. Digital Spies by sandytaru · · Score: 5, Funny

    The more I hear about these sophisticated spying viruses with the cute names, the more I imagine them as the digital equivalent of James Bond, little tuxedos and all. "My name is Bond. James Bond.zip. I'm an international attachment of mystery."

    --
    Occasionally living proof of the Ballmer peak.
    1. Re:Digital Spies by Vlad_the_Inhaler · · Score: 2

      You have to wonder if - based in Russia as they are - they are the only ones allowed to report this stuff. I'm not particularly surprised that Norton are useless here but there are two companies based in Germany who should be doing better work, assuming the viruses (virii?) show their elegant haaircuts in Germany.
      As to the GP, how do the viruses take their martinis? A tuxedo alone does not make a secret agent.

      --
      Mielipiteet omiani - Opinions personal, facts suspect.
  2. Iran again? by tokencode · · Score: 2, Insightful

    Given that the spear-phishing targets are mostly in Iran, I'm going to go out on a limb and say this is probably not the work of some 15 year old playing around or russia organized crime...

  3. Text files? Go on.... by davidwr · · Score: 3, Interesting

    "embedding the malware in various documents including text files"

    I assume they mean word-processing or other "not quite plain text" files, or perhaps "text files that are really textual representations of computer instructions" e.g. text files that embed macros that are interpreted by the text-processing software.

    While it's theoretically possible for a carefully-crafted plain-text file to exploit a security vulnerability in a particular text-processing program, it would have to be a narrowly targeted attack and it would be easily defeated by now-alert customers who simply change to a different text-processing program.

    It's also theoretically possible that there is an exploit in the text-handing APIs of the operating environment in use by the intended targets.

    --
    Knowledge is how to play a game, intelligence is how to win, wisdom is knowing what game to play.
  4. Mon dieu! Several Gigabytes! by jpapon · · Score: 2
    Oh no! Several GIGABYTES of information?

    That means they've stolen anywhere from half of a South Park season to several millions of pages of plain text!

    What a useful measure!

    --
    -- Let us endeavor so to live that when we pass even the undertaker shall be sorry. -- M. Twain
  5. Re:Text files? Go on.... by Baloroth · · Score: 4, Informative

    It's possible they mean files that appear as text to the user. Ars Technica mentions they use "Right to Left Override" to make it look like executable files aren't (they might show up as a .jpg, for example, complete with a jpg icon) to the end user. If the creators are clever, they could even have it launch the appropriate viewer to make it look like they opened the kind of file they did. So it isn't hard to imagine they did the same with .txt files, although given the context with "PowerPoint" they probably did mean .doc files or the like.

    --
    "None can love freedom heartily, but good men; the rest love not freedom, but license." --John Milton
  6. Re:'Mahdi' eh? by LordGr8one · · Score: 2

    None of the above. They're just Dune fanatics.

  7. Re:Text files? Go on.... by gmuslera · · Score: 2

    If they used advanced enough social engineering techniques could be plain ascii txt files with an instruction to i.e. base64 decode them and execute it for a nice surprise. The main executable part in social engineering attacks is the people.

  8. Re:MAH-DI!! by scorp1us · · Score: 3, Informative

    Mahdi - redeemer of Islam.

    --
    Slashdot's rate-of-post filter: Preventing you from posting too many great ideas at once.
  9. News article spelling the name wrong :-) by billstewart · · Score: 3, Informative

    They probably got it wrong because of translating from Russian and back, but it's "Mahdi" in the source code and the file directory shown in the article. Also, that's the standard English-language spelling for the Mahdi, who's approximately the Muslim version of the Messiah (depending on which branch of Islam you're talking to - it comes from hadiths and tradition rather than directly from the Quran.) So it's kind of an arrogant thing to name your program - does that mean it was really done by the Israelis, or by some Arab haxx0r-k1dd13?

    --

    Bill Stewart
    New Fast-Compression-only CPR http://preview.tinyurl.com/dy575ks