Chinese VXer malware spreads via BitTorrent

By

Analysts match samples.

Researchers have begun mapping malware samples used by Chinese hacking group APT1  to known malware lists.

Chinese VXer malware spreads via BitTorrent

The malware was revealed in a detailed Mandiant report (pdf) into the alleged state-sponsored hacking group which linked a string of attacks to an office block on the outskirts of Shanghai.

The hackers allegedly hit organisations including SCADA software outfits Telvent and Digital Bond, and security firm Alient Vault which had links to sensitive information on the US' defensive preparedness against hacking, according to the report.

Most of the more than 1000 malware samples found by Mandiant appeared to be custom and unknown to outsiders.

So far 281 malware samples have been matched to known malware repositories and are being distributed via BitTorrent by VirusShare.

Researcher Wesley McGrew has posted a series of matching malware strings found in the Mandiant report to VirusShare's list, although errors in this analysis may exist.

McGrew said he would analyse the malware further before posting a detailed analysis.

Websense wrote that it found more than 2000 unique cases of APT1 attacks since 2011 against all industry segments. It also noted that traffic from US manufacturing organisations to Chinese websites is 20 times as likely to be due to malware than legitimate traffic.

Got a news tip for our journalists? Share it with us anonymously here.

Copyright © SC Magazine, Australia

Tags:

Most Read Articles

Travel eSIMs secretly route traffic over Chinese and undisclosed networks: study

Travel eSIMs secretly route traffic over Chinese and undisclosed networks: study

Greater Western Water's billing system data issues laid bare

Greater Western Water's billing system data issues laid bare

Microsoft plans full quantum-resistant cryptography transition by 2033

Microsoft plans full quantum-resistant cryptography transition by 2033

Attackers weaponise Linux file names as malware vectors

Attackers weaponise Linux file names as malware vectors

Log In

  |  Forgot your password?