<br />
<b>Deprecated</b>:  Function create_function() is deprecated in <b>/home/hidefide/public_html/blog/wp-content/plugins/wr-pagebuilder/core/core.php</b> on line <b>127</b><br />
{"id":289,"date":"2012-01-15T14:27:19","date_gmt":"2012-01-15T14:27:19","guid":{"rendered":"https:\/\/icaruspressblog.wordpress.com\/?p=289"},"modified":"2019-04-17T11:59:39","modified_gmt":"2019-04-17T11:59:39","slug":"us-cert-hooked-by-us-cert-phishing-attack","status":"publish","type":"post","link":"https:\/\/hidefideas.com\/blog\/2012\/01\/15\/us-cert-hooked-by-us-cert-phishing-attack\/","title":{"rendered":"US-CERT Hooked by US-CERT Phishing Attack"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"  wp-image-291 alignright\" src=\"http:\/\/hidefideas.com\/blog\/wp-content\/uploads\/2016\/03\/phishing-3.jpg\" alt=\"phishing (3)\" width=\"223\" height=\"318\" srcset=\"https:\/\/hidefideas.com\/blog\/wp-content\/uploads\/2016\/03\/phishing-3.jpg 290w, https:\/\/hidefideas.com\/blog\/wp-content\/uploads\/2016\/03\/phishing-3-210x300.jpg 210w, https:\/\/hidefideas.com\/blog\/wp-content\/uploads\/2016\/03\/phishing-3-105x150.jpg 105w\" sizes=\"auto, (max-width: 223px) 100vw, 223px\" \/>This week, a phishing attack landed in the inboxes of several US government agencies, spoofing the US government\u2019s cyber security watchdog and response agency. Complete with attachments, the e-mail\u2019s payload was a nasty little virus that has already been tracked back to Mother Russia. To make matters a little embarrassing, perhaps, it\u2019s not enough that the agency which was spoofed in the attack has reported a disruption of its own systems, but it\u2019s also the government body <!--more-->responsible for identifying and mitigating just this type of thing.<\/p>\n<p>No, that headline above is not typo-ridden, though at first blush it might seem to be. On January 11, <a href=\"http:\/\/www.scmagazineuk.com\/phishing-campaign-disrupts-us-cert\/article\/222649\/\">news<\/a> <a href=\"http:\/\/www.net-security.org\/malware_news.php?id=1958\">erupted<\/a> of a rather malicious little spoof e-mail that circulated through the mail servers of several national, state and local government agencies and even private sector employees. The scam in question was an e-mail pretending to be the product of US-CERT, the United States Computer Emergency Readiness Team, a division of the Department of Homeland Security.<\/p>\n<p>Sent with fake source addresses that included <strong>soc@us-cert.gov<\/strong> and the subject line <strong>\u201cPhishing incident report call number: PH000000XXXXXXX\u201d<\/strong> and an attachment named <strong>\u201cUS-CERT Operation Center Report XXXXXXX.zip\u201d<\/strong>, a nasty little file which was anything but a report. In fact, after some quick investigation, the attachment \u2013 which executes a file named <strong>\u201c<\/strong><strong>US-CERT Operation CENTER Reports.eml.exe\u201d <\/strong>\u2013 was discovered to be a variant of the infamous Zeus virus known as \u2018Ice-IX\u2019, a keylogger that steals banking and other personal information. As if that isn\u2019t enough, the worm also bypasses firewalls and other protection schemes.<\/p>\n<p><strong>Oh, the Irony!<\/strong><\/p>\n<p>US-CERT responding by doing what it\u2019s supposed to do: it posted a <a href=\"http:\/\/www.us-cert.gov\/current\/#phishing_campaign_using_spoofed_us\">bulletin<\/a> and notified agencies. And while not admitting that anyone at US-CERT actually opened the little bugger, an operator at the agency has stated \u201cdifficulty receiving emails due to the phishing campaign,\u201d according to <a href=\"http:\/\/www.scmagazineuk.com\/phishing-campaign-disrupts-us-cert\/article\/222649\/\">SC Magazine<\/a>. A little embarrassing, considering that this is just the type of thing US-CERT has been mandated to protect against, it\u2019s a forgivable fumble considering that the scam artists continue to get <a href=\"http:\/\/www.allspammedup.com\/2011\/08\/phishin%E2%80%99-magicians-think-the-spammers-are-getting-smarter-you%E2%80%99re-right\/\">wilier<\/a> and more creative in their attacks.<\/p>\n<p>In an \u2018it never hurts to state the obvious\u2019 moment, US-CERT included the following advisories in its security bulletin:<\/p>\n<p>US-CERT encourages users to do the following to reduce the risks associated with this and other phishing campaigns.<\/p>\n<ul>\n<li>Do not open the attachments in email messages from unknown sources.<\/li>\n<li>Install anti-virus software and keep virus signatures files up to date.<\/li>\n<li>Refer to&nbsp;<a href=\"http:\/\/www.us-cert.gov\/reading_room\/emailscams_0905.pdf\">Recognizing and Avoiding Email Scams<\/a>&nbsp;(pdf) documents for more information on avoiding email scams.<\/li>\n<li>Refer to the&nbsp;<a href=\"http:\/\/www.us-cert.gov\/cas\/tips\/ST04-014.html\">Avoiding Social Engineering and Phishing Attacks<\/a>&nbsp;document for information on social engineering attacks.<\/li>\n<li>Refer to&nbsp;<a href=\"http:\/\/www.us-cert.gov\/cas\/tips\/ST05-006.html\">Recovering from Viruses, Worms, and Trojan Horses<\/a>&nbsp;document for additional information on how to recover from malware.<\/li>\n<\/ul>\n<h2><strong>From Russia with Malice<\/strong><\/h2>\n<p>The story gets a little more interesting from here, when Nextgov.com <a href=\"http:\/\/cybersecurityreport.nextgov.com\/2012\/01\/fake_us-cert_e-mails_contain_banking_virus_traced_to_russia.php\">reported<\/a> on Wednesday that \u201cResearchers outside of US-CERT traced the malicious software to a botnet \u2013 a remotely-controlled network of infected computers \u2013 that is taking commands from computers located in Russia.\u201d It\u2019s not clear why researchers <em>outside<\/em> of US-CERT traced the location \u2013 it would seem natural that US-CERT was capable of doing that sort of thing. Isn\u2019t it logical to assume that\u2019s what the \u201cresponse\u201d part of their name is for?<\/p>\n<p>Regarding the attack and its location, there\u2019s clearly no love here, only malice. So why <em>was<\/em> an e-mail from Russia so specifically targeted at and around US-CERT and US government agencies? It\u2019s extremely unlikely that this was state sponsored \u2013 the method used and speed at which it was detected suggest something far too ham-handed to be anything <em>that<\/em> nefarious. So taking that into consideration, the incident still poses something of an oddity. If a group, say organized crime \u2013 which is alive and well in Mother Russia \u2013 was responsible for the attack, what could they possibly hope to gain by phishing government agencies in the US? And if it was some cyberdude named Boris, who figured he\u2019d take time from his daily routine of scamming innocents to pry into US-CERT\u2019s activities, he certainly isn\u2019t the brightest cyberdude in cyberspace.<\/p>\n<p>It\u2019s very mysterious, this one, and it will be interesting to see what, if anything, comes from the follow-up investigations.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>This week, a phishing attack landed in the inboxes of several US government agencies, spoofing the US government\u2019s cyber security watchdog and response agency. Complete&hellip; <\/p>\n","protected":false},"author":3,"featured_media":291,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[13,14],"tags":[11,9,10,8,7],"class_list":["post-289","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","category-spam","tag-allspammedup","tag-bot","tag-botnet","tag-malware","tag-spam","jsn-master"],"_links":{"self":[{"href":"https:\/\/hidefideas.com\/blog\/wp-json\/wp\/v2\/posts\/289","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/hidefideas.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/hidefideas.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/hidefideas.com\/blog\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/hidefideas.com\/blog\/wp-json\/wp\/v2\/comments?post=289"}],"version-history":[{"count":3,"href":"https:\/\/hidefideas.com\/blog\/wp-json\/wp\/v2\/posts\/289\/revisions"}],"predecessor-version":[{"id":1823,"href":"https:\/\/hidefideas.com\/blog\/wp-json\/wp\/v2\/posts\/289\/revisions\/1823"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/hidefideas.com\/blog\/wp-json\/wp\/v2\/media\/291"}],"wp:attachment":[{"href":"https:\/\/hidefideas.com\/blog\/wp-json\/wp\/v2\/media?parent=289"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/hidefideas.com\/blog\/wp-json\/wp\/v2\/categories?post=289"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/hidefideas.com\/blog\/wp-json\/wp\/v2\/tags?post=289"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}