Wednesday, Sep 9, 2026
English News
  • Hyderabad
  • Telangana
  • AP News
  • India
  • World
  • Entertainment
  • Sport
  • Science and Tech
  • Business
  • Rewind
  • ...
    • NRI
    • View Point
    • cartoon
    • My Space
    • Education Today
    • Reviews
    • Property
    • Lifestyle
E-Paper
  • NRI
  • View Point
  • cartoon
  • My Space
  • Reviews
  • Education Today
  • Property
  • Lifestyle
Home | Science & Tech | Rare Spy Malware Hits Diplomats Of Ngos From Asia Europe

Rare spy malware hits diplomats of NGOs from Asia, Europe

Based on the affiliation of the discovered victims, the researchers at cyber security firm Kaspersky were able to determine that the malware campaign known as "MosaicRegressor" was used in a series of targeted attacks.

By IANS
Updated On - 11 October 2020, 03:46 PM
Rare spy malware hits diplomats of NGOs from Asia, Europe
whatsapp facebook twitter telegram

New Delhi: A rare spy malware has hit diplomats and members of NGOs from Asia, Africa and Europe in a series of targeted cyber attacks, including spear-phishing documents in Russian language while some were related to North Korea and used as a lure to download malware.

Based on the affiliation of the discovered victims, the researchers at cyber security firm Kaspersky were able to determine that the malware campaign known as “MosaicRegressor” was used in a series of targeted attacks.


The campaign has so far not been linked “to any known advanced persistent threat (APT) actors”.

The researchers uncovered the APT espionage campaign that uses a very rarely seen type of malware known as a firmware bootkit.

The UEFI bootkit used with the malware is a custom version of Hacking Team’s bootkit leaked in 2015.

“Although UEFI attacks present wide opportunities to the threat actors, MosaicRegressor is the first publicly known case where a threat actor used a custom made, malicious UEFI firmware in the wild,” said Mark Lechtik, senior security researcher at Global Research and Analysis Team (GReAT) at Kaspersky.

“This attack demonstrates that, albeit rarely, in exceptional cases actors are willing to go to great lengths in order to gain the highest level of persistence on a victim’s machine”.

UEFI firmware is an essential part of a computer, which starts running before the operating system and all the programs installed in it.

If UEFI firmware is somehow modified to contain malicious code, that code will be launched before the operating system, making its activity potentially invisible to security solutions.

Kaspersky researchers found a sample of such malware used in a campaign that deployed variants of a complex, multi-stage modular framework dubbed as MosaicRegressor.

“The framework was used for espionage and data gathering with UEFI malware being one of the persistence methods for this new, previously unknown malware,” the researchers explained.

The malware initially installed on the infected device is a Trojan-downloader, a programme capable of downloading additional payload and other malware.

“Depending on the payload downloaded, the malware could download or upload arbitrary files from/to arbitrary URLs and gather information from the targeted machine”, the findings showed.

“The use of leaked third-party source code and its customization into a new advanced malware once again raises yet another reminder of the importance of data security,” said Igor Kuznetsov, principal security researcher at Kaspersky’s GReAT.

“Once software — be it a bootkit, malware or something else — is leaked, threat actors gain a significant advantage,” he added.

  • Follow Us :
  • Tags
  • Africa
  • Asia
  • Corona Virus Deaths
  • Coronavirus

Related News

  • India’s enterprise AI investment surges 119%

    India’s enterprise AI investment surges 119%

  • OU student bags five gold medals in Chemistry; Shreya receives Prof J Satyanarayana Memorial Gold Medal

    OU student bags five gold medals in Chemistry; Shreya receives Prof J Satyanarayana Memorial Gold Medal

  • EAGLE Force busts interstate ganja network

    EAGLE Force busts interstate ganja network

  • TGSRTC retirees demand release of long-pending dues

    TGSRTC retirees demand release of long-pending dues

Latest News

  • Traffic comes to grinding halt as container overturns on NH44 in Nizamabad

    8 minutes ago
  • Hyderabad woman harassed over loan repayment, threatened with morphed photos of daughter

    16 minutes ago
  • Kukatpally shops booked for allegedly selling counterfeit Crocs products

    26 minutes ago
  • Financial Intelligence Unit issues notice to 15 crypto service providers, asks to take down URLs

    38 minutes ago
  • BRS women MLAs demand CM apology over assault after Speaker refuses to meet

    55 minutes ago
  • Arunachal integral to India’s unity, Northeast key driver of country”s growth: VP

    1 hour ago
  • US Ambassador Sergio Gor meets UFC star Puja Tomar, calls her journey ‘inspiring’

    1 hour ago
  • Telangana slips into rainfall deficit as monsoon stalls in September

    1 hour ago

company

  • Home
  • About Us
  • Contact Us
  • Privacy Policy

business

  • Subscribe

telangana today

  • Telangana
  • Hyderabad
  • Latest News
  • Entertainment
  • World
  • Andhra Pradesh
  • Science & Tech
  • Sport

follow us

  • Telangana Today Telangana Today
Telangana Today Telangana Today

© Copyrights 2024 TELANGANA PUBLICATIONS PVT. LTD. All rights reserved. Powered by Veegam

Telangana Today App