跳到主要內容

Professional hackers for hire - Hidden Lynx

LAST June, one of the world's most advanced hacker groups hit a problem. The US defence contractor whose systems it wanted to access only allowed a small set of trusted IP addresses to connect to their network. In an unusual move – hackers typically go for the low-hanging fruit – the group hacked the company that provided the IP whitelisting service, enabling it to forge access certificates.
This group, which calls itself Hidden Lynx, was given a vague face last week when antivirus software-maker Symantec released a report profiling it. Believed to be based in China, the group is known only through traces of malicious software bearing its mark found in the compromised computers of some of the world's largest companies.



One of the best known exploits of the so-called Hidden Lynx group was the devastating compromise of security firm Bit9 in 2012. The Waltham, Massachusetts, company provides an "application whitelisting" service that allows customers to run only a small set of approved software on their PCs and networks. By hacking into the company's servers and stealing the private cryptographic keys Bit9 used to digitally sign legitimate apps, the intruders were able to infect more valuable targets inside military contracting firms who used the service.
Until now, little has been known about the group responsible for the Bit9 attack. Now, a detailed report released by security firm Symantec reveals it was a highly organized gang of hackers that has breached some 100 companies and government organizations around the world since 2009. They're dubbed the Hidden Lynx gang, based on a text string found on one of the command and control (C&C) servers they use to communicate with infected machines inside the organizations they compromise.
"From the evidence seen, it's clear that Hidden Lynx belongs to a professional organization," the report stated.

Currently, Hidden Lynx primarily uses two backdoor trojans: Moudoor – a customized version of Gh0st RAT malware that the group used against a wide range of industries, including financial, government, health care and education sectors; and Naid, specially-crafted malware used to infiltrate entities in the defense sector. 

the  group is skilled and highly resourced given the fact they've been quick to “throw away” zero-days after details about the threats become public knowledge, unlike some hacker groups that continue to make use of vulnerabilities with available patches.

Haley warned that watering hole attacks appear to be the attack vector of choice for Hidden Lynx hackers, meaning the group infects legitimate websites frequently visited by their targets.

留言

這個網誌中的熱門文章

CMOS sensor trends and astrophotography, from amateur astronomers perspective

Nowadays, even in low light conditions, digital camera can quality pictures with higher ISO, noise and hot pixels have been gradually reduced. Sony has introduced back illumination process for consumer market. Sony BSI sensors evolved  from Exmor to now Exmor RS( stacked) technology. This stacked technology allows further chip size reduction, which has strong demands in smartphone camera market. Digital astrophotography is also benefited from such advances, utilising Back Side Illumination technology Exmor: Within the CMOS sensor, it outputs low-noise digital signals by "on-chip column AD conversion" and "dual noise reduction" to suppress noise in the first half of the process In low light conditions, when a wide aperture is desirable to collect as much light as possible. At apertures wider than f/2.0, back-illuminated Exmor R sensors are significantly more efficient at collecting light than conventional, front-illuminated sensor...

ultrafast rendezvous to ISS

    14 Oct 2020,  being the first to use a new “ultrafast” rendezvous” scheme with the ISS. Following a flawless ascent to the correct orbit, Soyuz 2 .1a , Soyuz MS-17 caught up with the orbiting laboratory in only two orbits (three hours), halving the time it takes for crew to get to the Station.   The three space travelers of the Soyuz MS-17 mission launched on a six-month mission the International Space Station.  previous 3/4 orbit rendezvous: Soyuz MS-16 4 orbit rendezvous A three-orbit profile was deemed possible without major flight design changes after inauguration of the Soyuz 2-1A rocket that provides a much higher orbit injection accuracy than its predecessors and would allow the two correction maneuvers on Orbit #2 to be eliminated while the Automated Rendezvous Phase would still remain untouched. The deletion of the Orbit #2 maneuvers was expected to slightly tighten the already restrictive phase angle window from and upper limit of 30-35° to 25-28°...

Scythians 斯泰基 塞種 西古提人

900 BC - 200 AD British museum   Tomb of scythe prince, Buktarma valley, 1200 masl, Google map Herodotus   絲路上的帝國 Biblegeography   哥羅西書 3:11  在此並不分希利尼人、猶太人、受割禮的、未受割禮的、化外人、 西古提人 、為奴的、自主的.惟有基督是包括一切、又住在各人之內。 塞種 塞迦  saka 史記漢書 西域傳: 塞種  ctext 昔匈奴破大月氏,大月氏西君大夏,而塞王南君罽賓。塞種分散,往往為數國。自疏勒以西北,休循、捐毒之屬,皆故 塞種 也。 匈奴列傳 Ctext :塞王 《史記》在《大宛列傳》與《匈奴列傳》中, 詳細 記錄了中亞至天山一帶的塞種(塞王、塞地)狀況。例如,文中記載了月氏西破走塞王,導致塞人南遷越過懸度(今帕米爾高原及克什米爾一帶) Baike Genetic history   Genetics  Nih griffin  ? Scytho-Siberian  world 塞迦 saka  wiki Disappeared? Sarmatians ( 薩爾馬泰 , 奄蔡 史記 ,  Aorsi )and goths YouTube