This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies. > Find out more here
by Alastair Stevenson
06 Feb 2013
Security firm FireEye has discovered new malware operating in the wild that boasts similar security-bypassing capabilities to the tools used to attack The New York Times.
FireEye warned that the malware, dubbed Nap Trojan, was using advanced techniques to bypass traditional security tools and this increases the likelihood other firms could see their defences bypassed.
"Nap is yet another piece of malicious software that is being used by attackers in order to compromise PCs and then use them as the base from which to launch attacks," FireEye product manager and architect, Jason Steer, told V3.
"By infecting and then cycling through thousands of infected machines in a very short timeframe, hackers can evade detection; indeed many of the traditional security systems used today are unable to deal with this kind of attack."
Steer said Nap is particularly dangerous as it shares several common traits with the malware used in a recent attack on the New York Times.
"In that breach, the attacker used thousands of university computers as front-end agents, rotating the attack between these machines in order to avoid suspicion" Said Steer.
"Nap also employs extended 'sleep' calls, a classic evasion tactic used by malware writers to help avoid analysis detection by security tools. Effectively this means the malware remains dormant for extended times, this could be 30 minutes or more, making it difficult to predict what it is actually going to do on a victim's PC."
The New York Times revealed it was the target of a prolonged cyber campaign originating from China at the end of January.
The Chinese hackers reportedly mounted the attack as "payback" for a series of articles the paper published about the nation's prime minister Wen Jiabao.
Latest stories from Security
Related videos
Related articles
Related jobs
Poll
How concerned are you by the rising tide of cyber threats?
V3 pits top devices against one another ahead of Samsung Galaxy S4 launch
Updating your subscription status
Connect with V3.co.uk
It's no longer one or other with web security; you can now have a virtualisation and SaaS hybrid model
BYOD is important for employee satisfaction, but poses challenges in terms of security, productivity loss and costs
C# Developer Successful Software Consultancy are looking...
Our client is an international software development organisation...
Our client is an international software development organisation...
£450M+ IT Solutions Company is recruiting for a suitably...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree