08/5/11

APT Attackers Used Chinese-Authored Hacker Tool To Hide Their Tracks

Separate APT research efforts detail ongoing ‘Operation Shady RAT’ cyberespionage attacks.

BLACK HAT USA 2011 — Las Vegas — The advanced persistent threat (APT) attackers behind the newly revealed Operation Shady RAT also deployed a tool called HTran that helps disguise their location.

Joe Stewart, director of malware research for Dell SecureWorks’ counter threat unit research team, has been studying some 60 different families of malware used by APT attackers in their cyberespionage attacks. He recently discovered a pattern in which many of these attackers use HTran, written 10 years ago by a Chinese hacker, to hide their whereabouts. Stewart, who published research on the tool’s use today in APT malware, says the Operation Shady RAT attackers are among those who use the tool for camouflaging purposes.

Read More..> http://www.darkreading.com/advanced-threats/167901091/security/attacks-breaches/231300171/apt-attackers-used-chinese-authored-hacker-tool-to-hide-their-tracks.html

Share on TwitterShare on TumblrSubmit to StumbleUponSave on DeliciousDigg ThisSubmit to reddit