Cyber-Espionage Group That Targeted Palestinian Law Enforcement Last Year Returns With New Attacks (bleepingcomputer.com)
Catalin Cimpanu, writing for BleepingComputer: A cyber-espionage group that has targeted Palestinian law enforcement last year is now back in action targeting Palestinian government officials. These recent attacks started in March 2018, according to evidence surfaced by Israel-based cyber-security firm Check Point. The new attacks seem to fit the same modus operandi of a group detailed in two reports from Cisco Talos and Palo Alto Networks last year.
Those reports detailed a spear-phishing campaign aimed at Palestinian law enforcement. The malicious emails tried to infect victims with the Micropsia infostealer, a Delphi-based malware that contained many strings referencing characters from the Big Bang Theory and Game Of Thrones TV shows. Now, the same group appears to be back, and the only thing they've changed is the malware, which is now coded in C++. The TV shows references are still there, this time with mentions to the Big Bang Theory, but also a Turkish TV series named "Resurrection: Ertugrul."
Those reports detailed a spear-phishing campaign aimed at Palestinian law enforcement. The malicious emails tried to infect victims with the Micropsia infostealer, a Delphi-based malware that contained many strings referencing characters from the Big Bang Theory and Game Of Thrones TV shows. Now, the same group appears to be back, and the only thing they've changed is the malware, which is now coded in C++. The TV shows references are still there, this time with mentions to the Big Bang Theory, but also a Turkish TV series named "Resurrection: Ertugrul."
everyone is in on the cyber game - even fringe groups like this.
nothing to see here - move along
this is like the title of one of the new amazon LOTR series episodes
Even hackers have problems finding good Delphi folks these days.
Harrison's Postulate - "For every action there is an equal and opposite criticism"
Sounds like the Israelis are false flagging again.
How exactly would they be able to tell it was coded in C++? Was the source code included in the malware? If its a binary executable there is no way you could know that without some pretty extensive knowledge of machine code and assembly language.
Simply running "strings" on the executable would probably be sufficient, as it would include names of C++ libraries.
It would also either require or include the C++ standard library.
I'm curious what on earth a "Palestinian Law Enforcement" group does, do they make sure the fire bombs terrorists sail on kites over to Israel have the correct amount of fire starting material or what?
Or maybe they go around to homes making sure the kids are all watching the appropriate amount of cartoons showing jewish people are working with the devil so they are groomed to carry out suicide attacks...
Because it sure doesn't seem like there is any law in Palestine.
"There is more worth loving than we have strength to love." - Brian Jay Stanley
Yes, I would heartily agree that the Big Bang Theory definitely does constitute malware.
0.0.0.0 namylufy.com
0.0.0.0 lindamullins.info
0.0.0.0 spgbotup.club
0.0.0.0 namyyeatop.club
0.0.0.0 namybotter.info
0.0.0.0 sanjynono.website
0.0.0.0 exvsnomy.club
0.0.0.0 ezofiezo.website
0.0.0.0 hitmesanjjoy.pro
0.0.0.0 www.clearskysec.com
0.0.0.0 clearskysec.com
0.0.0.0 support.space
0.0.0.0 falcondefender.com
0.0.0.0 update.ml
0.0.0.0 such.market
0.0.0.0 support.mafy
0.0.0.0 mafy.2waky.com
0.0.0.0 2waky.com
0.0.0.0 smail.otzo.com
0.0.0.0 otzo.com
0.0.0.0 ad.education
0.0.0.0 support.space
0.0.0.0 info.education
0.0.0.0 support.space
0.0.0.0 support.servecounterstrike.com
0.0.0.0 servecounterstrike.com
0.0.0.0 reme.otzo.com
0.0.0.0 supports.esmtp.biz
0.0.0.0 esmtp.biz
0.0.0.0 news.cloudns.cc
0.0.0.0 cloudns.cc
0.0.0.0 speed.ns01.biz
0.0.0.0 ns01.biz
0.0.0.0 space.support
0.0.0.0 reg.space
0.0.0.0 mo.mefound.com
0.0.0.0 mefound.com
0.0.0.0 support.read
0.0.0.0 books.org
0.0.0.0 supports.3utilities.com
0.0.0.0 3utilities.com
0.0.0.0 drive.google.com
0.0.0.0 support.mafy-koren.online
0.0.0.0 mafy-koren.online
* These entries in hosts blocks it.
APK
P.S.=> SOURCES https://research.checkpoint.co... https://www.clearskysec.com/wp... https://www.bleepingcomputer.c...
APK said something interesting, but it sure would be easier to read of this paragraph was broken into sentences:
See subject: Many disassemblers/hackers of code (for GOOD or BAD purposes) have issues w/ Delphi VCL statically built-in design (separating data from instructions for 1 thing) & it's DEFAULT is statically built programs vs. MARSHALLING (ole type load via GUID) libs external to the program (ala .DLL or .OCX for example) OR std. DLL loads (non-OLE type/oldschool/traditional) & w/ a MSVC++ program, it's interface @ THE VERY LEAST is run by MSVC*#Version.DLL libs (easy to identify) & Delphi's is built as a I said (statically compiled in source libs for all things by default on std. .exe file).
Even better, easier to read and understand, would be no more than one parenthetical per sentence. Maybe I'll give a try:
--
Many disassemblers/hackers have issues w/ Delphi VCL's statically built-in design. For one thing, separating data from instructions is an issue. Also, by default, it statically links, building the library into the executable. Compare Microsoft MSVC, which by default loads an external DLL file.
--
See subject & APK Hosts File Engine 2.0++ 64-bit for Linux h t t p : / / a p k . i t - m a t e . c o . u k / A P K H o s t s F i l e E n g i n e F o r L i n u x . z i p (remove spaces between characters & download).
Yields more security/speed/reliability/anonymity vs. any SINGLE solution (99% of threats = hostnames vs. IP address that most firewalls use) more efficiently/FASTER + NATIVELY 4 less!
(Vs. "Bolt on 'MoAr' illogic-logic" competitors slowing you, hosts speed you up 2 ways (adblocks + hardcodes u spend most time @) vs. competition loaded w/ security bugs (DNS/AntiVir) + overheads (messagepass ('souled-out' to advertiser addons) + filtering drivers) & their complexity leads to exploitation).
* ONLY 1 of its kind in GUI on Linux!
Better vs. Windows model in speed/efficiency/merge.
APK
P.S.=> Best program of its kind, bar-none, & better vs. browser addons + other competitors (full of bugs, excess resource use, slowdown & complexity)... apk
Your software is just fine - well written, functional... I'm going to continue using the Host File Engine by mmell February 17, 2017
Your premise that hostfiles are a good way to deal with advertising and malvertising is quite valid - by JazzLad April 20, 2016
his hosts program is actually pretty good by xenotransplant August 10 2015
his hosts tool is actually useful for those cases in which one does indeed want to locally block stuff outright while consuming minimum system resources by alexgieg September 25 2015
I like your host file system by Karmashock September 09 2015
that APK guy, I use his host file by rogoshen1 Tuesday March 03, 2015
I personally use a HOSTS file blocker produced from a genius called APK by 110010001000 October 27 2017
* Best part's Linux 64-bit model's faster/more efficient (2x work & 1/2 the time)
APK
P.S.=> For a faster/safer/more reliable internet... apk
See subject: You WISH you were me (lol) & you STALK me by UNIDENTIFIABLE anonymous posts threatening it https://slashdot.org/comments....
"Imitation = sincerest form of flattery" as you are now, impersonating me via clearly INFERIOR imitation of myself GIVING YOU AWAY!
HOWEVER:
You do make good on your "threat" (& I've caught you doing it already this week saying things I NEVER WOULD (APK="God's gift" etc.)) but that very 'threat' makes you look like the PSYCHO LOON you clearly are...
* You need SERIOUS "loony-bin QUALITY time" imo...
APK
P.S.=> You're the one "descending into madness" COMPLETELY OFF-TOPIC in some weirdo attempt to "make me look bad" but EVERYONE KNOWS I only post on hosts where they apply ON TOPIC & I certainly don't say what you are saying now - that's for sure... apk
See subject: Thank you & thanks again for your other comment here too https://ask.slashdot.org/comme...
* I try not "water it down" & /. (whipslash) makes it HARD on AC posters to get into detail (very important imo especially for novices) as our posts are SUPERSMALL (f's w/ my original posting, makes me SHRED it/compress it)!
I don't expect others here to NOT understand what I write, especially "techno geek speek", but I don't take chances by omitting detail!
Which I did & HAD TO per the above!
As there are MANY other ways to detect "the detectives" ala VM usage as another I omitted + OTHER more "insidious ways" to get debuggers to f'up etc. too (due to my being unable to do LARGER posts (you can as a reg'd luser (lol) vs. myself EVEN IF you submit AC for example))
APK
P.S.=> ORDINARILY I'd get on your ass for this 'cutdown' attempt of yours raymorris... but You're not the "ORDINARY" troller!
As you actually do a few useful things & YOU are TRYING TO BETTER YOURSELF (unlike most of my 'detractors') as I've seen you do a single contrib to the kernel code iirc & some articles on NORTON/SYMANTEC (China) securityfocus (or they pointed @ you, not sure) - vs. ME though? You're still MILES behind, lol... apk
Linux model will be @ Malwarebytes' hpHosts website soon (BSD & MacOS X vers too + Win32/64 there already for ages) https://hosts-file.net/?s=Down... near bottom of the page...
* Updates of that site are SLOW now due to (unfortunate) the site owner Mr. Steven Burn having had a stroke recently a few months back (good guy, & the WORST THINGS happen to the nicest folks I've found) so I have to wait out him updating Malwarebytes' DL site (the server I point to is Mr. Burn's though outta the UK).
(IF /.'s NEW owner wouldn't put FILTERS on my link to it, I wouldn't have to put spaces between chars - you can THANK HIM (not) for doing it but I understand it's @ THE BEHEST OF HIS MAIN SPONSOR Google since I block malvertising (where they make $ from but INFECT/TRACK/SLOW us too)).
APK
P.S.=> Hope that helps - I don't like it but it's "hurry up & wait" in life sometimes is all due to unforseen circumstances... apk
I wonder who this could be? What is the only country on earth that has a problem with the Palestinians? Yes. Israel.
"according to evidence surfaced by Israel-based cyber-security firm Check Point..."
This is kind of like Israel investigating itself over the Flotilla attacks and the Rachel Corrie murder and finding itself not guilty.
Or maybe their police do exactly what police do in any other country.
Are you saying the police in ANY other country would sit idly by while masses of "protesters" armed with AK-47's, sent kites loaded with firebombs into the sky with the sole purpose off burning property and hopefully killing a few people?
I doubt that is true, at all, so I'd say my question stands stronger than ever before. They aren't upholding even the most basic of laws (i.e. randomly setting fire to properties) so what DO they do?
Maybe try to get Israel to stop continually annexing land
There are plenty of property disputes in civilized countries not settled by burning the innocent are targeting hospitals with rockets. Which again, these "police" are apparently cool with. Makes me wonder what OTHER "fun" things you could do in Palestine that police in other countries would arrest you for.
Which all leads me to wonder why on earth you support a group of people as inherently despicable as modern day Palestinians.
"There is more worth loving than we have strength to love." - Brian Jay Stanley
Going to make more sockpuppets to stalk & troll me with you LITERALLY ADMITTED loon https://slashdot.org/comments.... + sending me postcards w/ threats too https://slashdot.org/comments.... you little STALKING whacko??
... apk
Zontar, take your meds you ADMITTED mentalcase https://slashdot.org/comments....
&
You're also a druggie too https://slashdot.org/comments....
* You're a butthurt loon freak, plain & simple - you did it to yourself, loser... see below for proof.
APK
P.S.=> Still trying to live down how I shot you to pieces in the art & science of computing Mr. Butthurt https://slashdot.org/comments.... ?
How about proving hosts & my program that builds them are useless too https://slashdot.org/comments.... ?
It's just the worst when victims fight back.
Hey everyone, here's someone who thinks that when you believe you are being annexed unfairly, you should set fire to houses and try to blow up hospitals or crowds of random civilians!
Again, what police force would agree with you? Why apparently the Palestinian "police force".
Don't get me wrong, Hamas and the like are bad people. It's just that Hamas wouldn't exist if it weren't for Israeli zionism.
Bullshit, plenty of people on earth have similar issues and solve them without such extreme violence. Hamas exists because *any* Jews are alive, period. "Zionism" is only a pretext used to kill as many jews as possible by any means handy.
I'll let you have the last response as you continue your descent into madness, I wouldn't want to make you really mad as I'm sure you'd find it fair to set fire to my house or slaughter me while I slept simply for disagreeing with you.
"There is more worth loving than we have strength to love." - Brian Jay Stanley
people would take you more seriously if you didn't spam these threads so much.
---->.............AC
See subject: u WISH u were me (lol) & u STALK me by UNIDENTIFIABLE anonymous posts threatening this https://slashdot.org/comments....
"Imitation = sincerest form of flattery" as you are now, impersonating me via clearly INFERIOR imitation of myself GIVING YOU AWAY!
HOWEVER:
You do make good on your "threat" & I caught you doing it already this week saying things I NEVER WOULD (APK="God's gift" etc.) but that very 'threat' makes you look like the PSYCHO LOON you clearly are!
APK
P.S.=> You need SERIOUS "loony-bin QUALITY time" imo after that OFF-TOPIC cut & paste of my replies to Zontar The Mindless (fake name for his FAKE LIE of a so-called 'life' (wasted life))... apk
What's next: cops eating donuts, doctors playing golf?
I do not believe in karma. "Funny"=-6. Do good and forbid evil. Yours, Oft-Offtopic Flamebaiting Troll.
Going to make more sockpuppets to stalk & troll me with you loon https://slashdot.org/comments.... ?
... apk
Sending me postcards with threats too https://slashdot.org/comments.... ??
Take your meds mentalcase https://slashdot.org/comments.... & You're a druggie too https://slashdot.org/comments....
* You're a butthurt loon freak, plain & simple - you did it to yourself, loser... see below for proof.
APK
P.S.=> Still trying to live down how I shot you to pieces in the art & science of computing Mr. Butthurt https://slashdot.org/comments.... ?
How about proving hosts & my program that builds them are useless too https://slashdot.org/comments.... ?
Hamas spun out of the Muslim Brotherhood in 1987 in direct response to events relating to Israeli occupation of the Palestinian Territories.
"I'll let you have the last response as you continue your descent into madness, I wouldn't want to make you really mad as I'm sure you'd find it fair to set fire to my house or slaughter me while I slept simply for disagreeing with you."
Hahaha, what a ridiculous person you are. Now you can tell your Mom you got the last word in on the internet!
I ignore Anonymous Coward posts. If you want to discuss something, that's awesome. Log in.
See my subject line above: Registered /.ers take me seriously enough liking/using/praising my work OR me vs. your bs https://it.slashdot.org/commen...
* So trust me: I DON'T TAKE YOU SERIOUSLY @ ALL (& I doubt anyone else does either).
APK
P.S.=> "Onwards & UPWARDS" & now? It's "Miller Time" here on a HOT summer day, bills paid + lawn's freshly cut on a HOT SUMMER DAY, so it's time to relax... apk
See subject line above & this post to you doing the exact same as you did before in this thread here https://it.slashdot.org/commen... addressing your lunacy!
You NEED serious "quality-time" @ YOUR LOCAL "loony-bin" imo what-with all the STALKING of myself you do by UNIDENTIFIABLE anonymous posts + impersonating me YOU DO just as you did now like the CLEARLY OBSESSED LOON you prove yourself to be...
* GROW UP!
APK
P.S.=> Get on topic - I am by HELPING vs. this threat unquestionably via hosts file power to STALL & NULLIFY it https://it.slashdot.org/commen... ... apk
It's the last week of the semester for the Israeli Anti-Palestine-Cyber class of 2018.
It's their final test.
No, you are unquestionably spamming hosts file garbage. As always all your efforts do a poor job of securing anything long after the threat began and were incapable of preventing it. - by UNIDENTIFIABLE Anonymous STALKER of APK on Monday July 09, 2018 @06:30PM (#56919816)
See subject & this works vs. this threat + its "relatives' (many of these share servers etc.) https://it.slashdot.org/commen...
* Even IF you had it already? It'd be crippled but it also stops anyone from getting it being as current as possible of data...
APK
P.S.=> Either way, I win & so do my users - you as always, lose... apk
See subject: ...by your kind's multiple sockpuppets on /. (like you downmod bomb farming points that way) : I'm here to win based on fact in technical merit (clearly, I am). Look @ the BS you pull but you don't cite any specifics - you do that? I stomp you. It's that simple. Always is.
* I'm not concerned if a user has personal issues w/ me (Plenty of folks do w/ Linus Torvalds & Theo DeRaadt, but personally I like 'em, lol - @ least they're honest hard working dudes who did something folks LIKE & USE (just like me or vice-a-versa)).
APK
P.S.=> I don't overstate anything about hosts abilities & I'm certainly no failure in this project of mine per its REGISTERED users saying they like & use my work (facts) https://it.slashdot.org/commen... - you've done better? PROVE IT as you STALK me by UNIDENTIFIABLE anonymous posts... apk
Just how desperate do you have to be to not mention Micropsia only runs on Microsoft Windows.