The“MSUpdater”Trojan
AndOngoingTargetedAttacks
AZscalerandSeculertJointReport
©2012ZscalerInc.andSeculertLtd.AllRightsReserved.
Contents
CONTENTS...................................................................................................................1OVERVIEW...................................................................................................................1“MSUPDATER”TROJANINCIDENTSOBSERVED.............................................................2OSINTAGGREGATIONANDCORRELATION...................................................................2INFECTION
VECTOR:
PHISHING
EMAIL
WITH
MALICIOUS
ATTACHMENT........................3RELATED
BACKDOOR
/
BEACONING
PATTERN
..................................................................
3
SEPTEMBER2010CVE-2010-2883PDFPHISH................................................................5SEPTEMBER23,2010ISSNIPPHISHINGEMAILWITHMALICIOUSATTACHMENT………….8RELATED
ANTIVIRUS
VENDOR
“FAMILY”
NAMES..........................................................9“CONFERENCE”LURE.................................................................................................10CLOSINGREMARKS....................................................................................................11APPENDIXA:CONSOLIDATEDLISTOFMALICIOUSMD5HASHES................................13
Overview
ResearchersfromZscalerandSeculertseparatelyidentifiedincidentsandthreatsdiscussedinthisreport.Withinaprivatesecurityforumwediscussedanddeterminedthatwehadidentifiedrelatedincidents.ZscalerandSeculertcollaboratedonthisreporttoaggregateandcorrelateourfindingsalongwithopen-sourceintelligence(OSINT)todetailalesser-known“MSUpdater”remoteaccessTrojan(RAT)anditslinkagetocurrenttargetedattacksandothersdatingbacktoatleastearly2009.Foreignanddomestic(UnitedStates)companieswithintellectualpropertydealinginaero/geospaceanddefenseseemtobesomeoftherecentindustriestargetedintheseattacks.Thegoalofthisreportistoaggregateinformation,drawsomecorrelations,andprovideanoverviewofthisthreattofacilitateitsidentification,detection,andfunctionality.Withthisgoalinmind,wealsoaimnottorevealanythingthatmightdisruptanyinvestigationsorstatesomethingwithoutadditionalopen-sourcecorroboration.Weassecurityresearchersbelievethatoursuccessisnotmeasuredbyhowmuchinformationwecollect,butinhowweuseandsharetheinformationtobettersecureandprotecttheInternetcommunityfromthreats.Wehopethattheinformationwithinthisreporthelpstodetectandremediatethisthreatwithinorganizations.