Slashdot Mirror


Nation-backed Hackers Using Evercookie and Web Analytics To Profile Targets (securityledger.com)

chicksdaddy writes: There's such a fine line between clever and criminal. That's the unmistakable subtext of the latest FireEye report on a new "APT" style campaign that's using methods and tools that are pretty much indistinguishable from those used by media websites and online advertisers. The difference? This time the information gathered from individuals is being used to soften up specific individuals with links to international diplomacy, the Russian government, and the energy sector.

The company released a report this week that presented evidence of a widespread campaign (PDF) that combines so-called "watering hole" web sites with a tracking script dubbed "WITCHCOVEN" and Samy Kamkar's Evercookie, the super persistent web tracking cookie. The tools are used to assemble detailed profiles on specific users including the kind of computer they use, the applications and web browsers they have installed, and what web sites they visit.

While the aims of those behind the campaign aren't known, FireEye said the use of compromised web sites and surreptitious tracking scripts doesn't bode well. "While many sites engage in profiling and tracking for legitimate purposes, those activities are typically conducted using normal third-party browser-based cookies and commercial ad services and analytics tools," FireEye wrote in its report. "In this case, while the individuals behind the activity used publicly available tools, those tools had very specific purposes....This goes beyond 'normal' web analytics," the company said.

1 of 47 comments (clear)

  1. Re:Applications? by oneiros27 · · Score: 4, Interesting

    Maybe not simply 'installed', but if you use multiple browers to authenticate to the same website, and they have ways to insert tracking code on that website (such as from ad networks), they could easily link the two browsers.

    Snowden's advice about blocking ad networks for security purposes actually makes perfect sense.

    --
    Build it, and they will come^Hplain.