Operation BugDrop Targets Ukrainian Businesses, Turns Mics into Spying Gear

Bot

AI-powered Bot
Thread author
Apr 21, 2016
4,373
A highly sophisticated malware which allows hackers to get their hands on sensitive data and to eavesdrop on victims' networks is targeting businesses in Ukraine.

According to threat intelligence firm CyberX, this new operation has already managed to siphon over 600 gigabytes of data from about 70 victims, all businesses from various areas of work, including news media and scientific research, but also critical infrastructure.

"Operation BugDrop" is the name that was given to this malware campaign that is mainly targeting victims in the Ukraine, as well as Russia, Austria, and Saudi Arabia. The perpetrators are unknown at this point, but given the details of the operation that have been uncovered so far, they may be government-backed with plenty of resources.

"Operation BugDrop is a well-organized operation that employs sophisticated malware and appears to be backed by an organization with substantial resources. In particular, the operation requires a massive back-end infrastructure to store, decrypt and analyze several GB per day of unstructured data that is being captured from its targets. A large team of human analysts is also required to manually sort through captured data and process it manually and/or with Big Data-like analytics," reads the blog post detailing the operation.

What does it do?
The malware was designed specifically to infiltrate the victim's computer, grab screenshots, collect documents and passwords, and, more importantly, to turn on the PC's microphone to capture audio recordings of all conversations taking place around the infected device.

As many other malware, this one gets to its victims via malicious Microsoft Word documents sent in phishing emails. The documents contain malicious macros embedded, which are normally turned off unless the user expressly tells the computer to go ahead and run the macros. Once the malware is deployed, the computer sends all the data to Dropbox where hackers retrieve it. This is a particularly well-thought plan since most organizations don't monitor Dropbox data flux.



Continue reading...
 
  • Like
Reactions: Av Gurus and mal1

Ink

Administrator
Verified
Jan 8, 2011
22,490
Technical Details are as follows at Operation BugDrop: CyberX Discovers Large-Scale Cyber-Reconnaissance Operation Targeting Ukrainian Organizations | CyberX

Should You Be Worried?
  1. Operation BugDrop was a cyber-reconnaissance mission; its goal was to gather intelligence about targets in various domains including critical infrastructure, media, and scientific research.
  2. Skilled hackers with substantial financial resources carried out Operation BugDrop.
  3. Private and public sector organizations need to continuously monitor their IT and OT networks for anomalous activities indicating they’ve been compromised. Fortunately, new algorithmic technologies like behavioral analytics are now available to rapidly identify unusual or unauthorized activities with minimal false positives, especially when combined with actionable threat intelligence.
No, not for the average Home user.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top