Cyber-Espionage Group That Targeted Palestinian Law Enforcement Last Year Returns With New Attacks (bleepingcomputer.com)
Catalin Cimpanu, writing for BleepingComputer: A cyber-espionage group that has targeted Palestinian law enforcement last year is now back in action targeting Palestinian government officials. These recent attacks started in March 2018, according to evidence surfaced by Israel-based cyber-security firm Check Point. The new attacks seem to fit the same modus operandi of a group detailed in two reports from Cisco Talos and Palo Alto Networks last year.
Those reports detailed a spear-phishing campaign aimed at Palestinian law enforcement. The malicious emails tried to infect victims with the Micropsia infostealer, a Delphi-based malware that contained many strings referencing characters from the Big Bang Theory and Game Of Thrones TV shows. Now, the same group appears to be back, and the only thing they've changed is the malware, which is now coded in C++. The TV shows references are still there, this time with mentions to the Big Bang Theory, but also a Turkish TV series named "Resurrection: Ertugrul."
Those reports detailed a spear-phishing campaign aimed at Palestinian law enforcement. The malicious emails tried to infect victims with the Micropsia infostealer, a Delphi-based malware that contained many strings referencing characters from the Big Bang Theory and Game Of Thrones TV shows. Now, the same group appears to be back, and the only thing they've changed is the malware, which is now coded in C++. The TV shows references are still there, this time with mentions to the Big Bang Theory, but also a Turkish TV series named "Resurrection: Ertugrul."
everyone is in on the cyber game - even fringe groups like this.
nothing to see here - move along
Even hackers have problems finding good Delphi folks these days.
Harrison's Postulate - "For every action there is an equal and opposite criticism"
Sounds like the Israelis are false flagging again.
Simply running "strings" on the executable would probably be sufficient, as it would include names of C++ libraries.
It would also either require or include the C++ standard library.
I'm curious what on earth a "Palestinian Law Enforcement" group does, do they make sure the fire bombs terrorists sail on kites over to Israel have the correct amount of fire starting material or what?
Or maybe they go around to homes making sure the kids are all watching the appropriate amount of cartoons showing jewish people are working with the devil so they are groomed to carry out suicide attacks...
Because it sure doesn't seem like there is any law in Palestine.
"There is more worth loving than we have strength to love." - Brian Jay Stanley
How exactly would they be able to tell it was coded in C++?
a) strings (especially compiler string)
b) vtables (they can be generated slightly differently between compilers/languages)
c) linked to C++ libraries
d) every compiler generates code in a slightly different way, so they could probably tell you the exact version of the compiler and the arguments used if they had to (and the compiler string was removed).
It's really not very complicated to figure out which language a program is written in.
Anons need not reply. Questions end with a question mark.
APK said something interesting, but it sure would be easier to read of this paragraph was broken into sentences:
See subject: Many disassemblers/hackers of code (for GOOD or BAD purposes) have issues w/ Delphi VCL statically built-in design (separating data from instructions for 1 thing) & it's DEFAULT is statically built programs vs. MARSHALLING (ole type load via GUID) libs external to the program (ala .DLL or .OCX for example) OR std. DLL loads (non-OLE type/oldschool/traditional) & w/ a MSVC++ program, it's interface @ THE VERY LEAST is run by MSVC*#Version.DLL libs (easy to identify) & Delphi's is built as a I said (statically compiled in source libs for all things by default on std. .exe file).
Even better, easier to read and understand, would be no more than one parenthetical per sentence. Maybe I'll give a try:
--
Many disassemblers/hackers have issues w/ Delphi VCL's statically built-in design. For one thing, separating data from instructions is an issue. Also, by default, it statically links, building the library into the executable. Compare Microsoft MSVC, which by default loads an external DLL file.
--
I wonder who this could be? What is the only country on earth that has a problem with the Palestinians? Yes. Israel.
"according to evidence surfaced by Israel-based cyber-security firm Check Point..."
This is kind of like Israel investigating itself over the Flotilla attacks and the Rachel Corrie murder and finding itself not guilty.
Or maybe their police do exactly what police do in any other country.
Are you saying the police in ANY other country would sit idly by while masses of "protesters" armed with AK-47's, sent kites loaded with firebombs into the sky with the sole purpose off burning property and hopefully killing a few people?
I doubt that is true, at all, so I'd say my question stands stronger than ever before. They aren't upholding even the most basic of laws (i.e. randomly setting fire to properties) so what DO they do?
Maybe try to get Israel to stop continually annexing land
There are plenty of property disputes in civilized countries not settled by burning the innocent are targeting hospitals with rockets. Which again, these "police" are apparently cool with. Makes me wonder what OTHER "fun" things you could do in Palestine that police in other countries would arrest you for.
Which all leads me to wonder why on earth you support a group of people as inherently despicable as modern day Palestinians.
"There is more worth loving than we have strength to love." - Brian Jay Stanley
It's just the worst when victims fight back.
Hey everyone, here's someone who thinks that when you believe you are being annexed unfairly, you should set fire to houses and try to blow up hospitals or crowds of random civilians!
Again, what police force would agree with you? Why apparently the Palestinian "police force".
Don't get me wrong, Hamas and the like are bad people. It's just that Hamas wouldn't exist if it weren't for Israeli zionism.
Bullshit, plenty of people on earth have similar issues and solve them without such extreme violence. Hamas exists because *any* Jews are alive, period. "Zionism" is only a pretext used to kill as many jews as possible by any means handy.
I'll let you have the last response as you continue your descent into madness, I wouldn't want to make you really mad as I'm sure you'd find it fair to set fire to my house or slaughter me while I slept simply for disagreeing with you.
"There is more worth loving than we have strength to love." - Brian Jay Stanley
What's next: cops eating donuts, doctors playing golf?
I do not believe in karma. "Funny"=-6. Do good and forbid evil. Yours, Oft-Offtopic Flamebaiting Troll.
Hamas spun out of the Muslim Brotherhood in 1987 in direct response to events relating to Israeli occupation of the Palestinian Territories.
"I'll let you have the last response as you continue your descent into madness, I wouldn't want to make you really mad as I'm sure you'd find it fair to set fire to my house or slaughter me while I slept simply for disagreeing with you."
Hahaha, what a ridiculous person you are. Now you can tell your Mom you got the last word in on the internet!
I ignore Anonymous Coward posts. If you want to discuss something, that's awesome. Log in.
It's the last week of the semester for the Israeli Anti-Palestine-Cyber class of 2018.
It's their final test.
Just how desperate do you have to be to not mention Micropsia only runs on Microsoft Windows.