Pakistanis angry over detentions in Times Sq. case Monday, May 24, 2010
ISLAMABAD – Relatives of three men detained by Pakistan for alleged links to the suspect in the attempted Times Square bombing say the men are innocent.
They
AFP - Thursday, August 6TAIPEI (AFP) - - Taiwan's Beijing-friendly government on Wednesday denied boycotting an Australian film festival amid a row over the e
BERLIN (Reuters) - Chancellor Angela Merkel suffered a double blow on Thursday as a senior party ally in east German
Minister seeks closure of anti-Berlusconi websites Wednesday, December 16, 2009
ROME (AFP) - – The Italian government moved Tuesday to close down Internet sites encouraging further violence against Prime Minister Silvio Berlusconi, who
By ELAINE KURTENBACH,AP Business Writer AP - Wednesday, March 18SHANGHAI - Asia's stock market rally seemed to be running out of steam Wednesday, despite an
Edition:
U.S.
Africa
Arabic
Argentina
Brazil
Canada
China
France
Germany
India
Italy
Japan
Latin America
Mexico
Russia
Spain
United Kingdom
Home
Business
Business Home
Economy
Technology
Media
Small Business
Legal
Deals
Earnings
Social Pulse
Business Video
The Freeland File
Aerospace & Defense
Markets
Markets Home
U.S. Markets
European Markets
Asian Markets
Global Market Data
Indices
M&A
Stocks
Bonds
Currencies
Commodities
Futures
Funds
peHUB
World
World Home
U.S.
Brazil
China
Euro Zone
Japan
Mexico
Russia
India Insight
World Video
Reuters Investigates
Decoder
Politics
Politics Home
Election 2012
Campaign Polling
Political Punchlines
Supreme Court
Politics Video
Tech
Technology Home
MediaFile
Science
Tech Video
Tech Tonic
Social Pulse
Opinion
Breakingviews
Money
Money Home
Tax Break
Lipper Awards 2012
Global Investing
MuniLand
Unstructured Finance
Linda Stern
Mark Miller
John Wasik
James Saft
Analyst Research
Alerts
Watchlist
Portfolio
Stock Screener
Fund Screener
Personal Finance Video
Money Clip
Investing 201
Life
Health
Sports
Arts
Faithworld
Business Traveler
Entertainment
Oddly Enough
Lifestyle Video
Pictures
Pictures Home
Reuters Photographers
Video
Reuters TV
Reuters News
Article
Comments (0)
Follow Reuters
Facebook
Twitter
RSS
YouTube
Read
New Orleans withstands Isaac's wrath, for now
|
5:32pm EDT
Navy SEAL's book gives different account of bin Laden death
2:46pm EDT
U.S. cases of West Nile virus set record, deaths soar-CDC
12:47pm EDT
Loss of radio contact prompts Amsterdam plane hijack scare
|
12:11pm EDT
Analysis: China's aircraft carrier: in name only
|
28 Aug 2012
Discussed
138
Obama’s lead over Romney grows despite voters’ pessimism
122
Romney to announce vice presidential choice Saturday
94
Analysis: Are Israelis tough enough for a long war with Iran?
Sponsored Links
Pictures
Reuters Photojournalism
Our day's top images, in-depth photo essays and offbeat slices of life. See the best of Reuters photography. See more | Photo caption
In the path of Isaac
Hurricane Isaac drove water over the top of a levee on the outskirts of New Orleans. Slideshow
Protesting the RNC
Activists shout anti-Republican slogans outside of the Republican National Convention. Slideshow
Cyber spying spreads in Iran after operation blown: researchers
Tweet
Share this
Email
Print
Related News
UPDATE 7-IAEA gets no deal with Iran on bomb research suspicions
Fri, Aug 24 2012
U.N. nuclear watchdog pushes Iran to open up military site
Fri, Aug 24 2012
Exclusive: Iran looks to Armenia to skirt bank sanctions
Tue, Aug 21 2012
Insight: Experts hope to shield cars from computer viruses
Mon, Aug 20 2012
Virus found in Mideast can spy on bank transactions
Thu, Aug 9 2012
Analysis & Opinion
Risk spills over in Middle East
Is the U.S. picking on our banks?
Related Topics
Tech »
By Jim Finkle
BOSTON |
Wed Aug 29, 2012 2:33pm EDT
BOSTON (Reuters) - The scope of a cyber espionage campaign targeting Iran and other parts of the Middle East has widened, even after security experts blew the operation's cover last month, according to the research firm that discovered the Mahdi Trojan.
Israeli security company Seculert said it had identified about 150 new victims over the past six weeks as developers of the Mahdi virus had changed the code to evade detection by anti-virus programs. That has brought the total number of infections found so far to nearly 1,000, the bulk of them in Iran.
"These guys continue to work," Seculert Chief Technology Officer Aviv Raff said via telephone from the company's headquarters in Israel.
The decision to keep the operation running implies that Mahdi's operators were not particularly worried about getting caught, said Roel Schouwenberg, a senior researcher with Kaspersky Lab, which has collaborated with Seculert to analyze Mahdi.
Schouwenberg said some viruses are designed for stealth because they become useless if they are discovered. He pointed to the Stuxnet Trojan that targeted Iran's nuclear program in 2010. After that customer-built virus was uncovered by a security researcher in Belarus, authorities in Iran discovered it in a uranium enrichment facility that it had targeted.
Mahdi is a "less professional" operation that runs on technology built with widely available software, according to Schouwenberg.
"If the quality of your operation is not that high, then maybe you don't care about being discovered," he said. "But the scary thing is that it can still be effective."
The Mahdi Trojan allows remote attackers to steal files from infected PCs, and monitor emails and instant messages, Seculert and Kaspersky said. It can also record audio, log keystrokes and take screen shots of activity on those computers.
The firms said they believed multiple gigabytes of data have been uploaded from targeted machines.
Targets of Mahdi include critical infrastructure firms, engineering students, financial services firms and government embassies located in five Middle Eastern countries, with the majority of the infections in Iran, according to the two security firms.
The bulk of the new victims were also in Iran, according to Seculert, though a few were identified in the United States and Germany.
The two firms have declined to identify specific victims.
Seculert's Raff said he suspected the campaign was being run by hacker activists, or "hactivists," who were either funded by a government or who provide information they collect to a nation for ideological reasons. He declined to say which country might be involved.
Seculert and Kaspersky dubbed the campaign Mahdi after a term referring to the prophesied redeemer of Islam because evidence suggests the attackers used a folder with that name as they developed the software to run the project.
They also included a text file named mahdi.txt in the malicious software that infected target computers.
(Editing by Cynthia Osterman and Bernadette Baum)
Tech
Tweet this
Link this
Share this
Digg this
Email
Reprints
We welcome comments that advance the story through relevant opinion, anecdotes, links and data. If you see a comment that you believe is irrelevant or inappropriate, you can flag it to our editors by using the report abuse links. Views expressed in the comments do not represent those of Reuters. For more information on our comment policy, see http://blogs.reuters.com/fulldisclosure/2010/09/27/toward-a-more-thoughtful-conversation-on-stories/
Comments (0)
Be the first to comment on reuters.com.
Add yours using the box above.
Edition:
U.S.
Africa
Arabic
Argentina
Brazil
Canada
China
France
Germany
India
Italy
Japan
Latin America
Mexico
Russia
Spain
United Kingdom
Back to top
Reuters.com
Business
Markets
World
Politics
Technology
Opinion
Money
Pictures
Videos
Site Index
Legal
Bankruptcy Law
California Legal
New York Legal
Securities Law
Support & Contact
Support
Corrections
Connect with Reuters
Twitter
Facebook
LinkedIn
RSS
Podcast
Newsletters
Mobile
About
Privacy Policy
Terms of Use
AdChoices
Copyright
Our Flagship financial information platform incorporating Reuters Insider
An ultra-low latency infrastructure for electronic trading and data distribution
A connected approach to governance, risk and compliance
Our next generation legal research platform
Our global tax workstation
Thomsonreuters.com
About Thomson Reuters
Investor Relations
Careers
Contact Us
Thomson Reuters is the world's largest international multimedia news agency, providing investing news, world news, business news, technology news, headline news, small business news, news alerts, personal finance, stock market, and mutual funds information available on Reuters.com, video, mobile, and interactive television platforms. Thomson Reuters journalists are subject to an Editorial Handbook which requires fair presentation and disclosure of relevant interests.
NYSE and AMEX quotes delayed by at least 20 minutes. Nasdaq delayed by at least 15 minutes. For a complete list of exchanges and delays, please click here.