{"id":10215,"date":"2017-11-01T07:30:24","date_gmt":"2017-11-01T15:30:24","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2017\/11\/01\/news-3988\/"},"modified":"2017-11-01T07:30:24","modified_gmt":"2017-11-01T15:30:24","slug":"news-3988","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2017\/11\/01\/news-3988\/","title":{"rendered":"Silence like a cancer grows"},"content":{"rendered":"<p><strong>Credit to Author: Nikolay Pankov| Date: Wed, 01 Nov 2017 15:14:20 +0000<\/strong><\/p>\n<p>Our experts have discovered a new targeted attack using a Trojan by the name of Silence against financial institutions. Russian banks are first in the line of fire, but Malaysian and Armenian organizations have also been infected.<\/p>\n<p>Tactically, the attack is very similar to the canonical financial APT campaign, the notorious Carbanak: a phishing e-mail with a malicious attachment sent to employees of banks and financial organizations, followed by spying on employees and then, suddenly, a fraudulent transaction. This proven method has already <a href=\"https:\/\/www.kaspersky.com\/blog\/billion-dollar-apt-carbanak\/7519\/\">brought its operators billions of dollars<\/a>, so why not try it again?<\/p>\n<p>This time around, however, the attackers have perfected the e-mail hook. Having infected and firmly infiltrated the infrastructure of an organization, the attackers start e-mailing &#8220;contracts&#8221; to the bank&#8217;s partners. The next victim receives a phishing message from the address of a real person who works at the bank. This greatly increases the likelihood of a malicious attachment being clicked.<br \/> <a href=\"https:\/\/d1srlirzdlmpew.cloudfront.net\/wp-content\/uploads\/sites\/92\/2017\/11\/01110802\/Silence_Financial_APT.jpg\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/d1srlirzdlmpew.cloudfront.net\/wp-content\/uploads\/sites\/92\/2017\/11\/01110802\/Silence_Financial_APT-1024x672.jpg\" alt=\"\" width=\"1024\" height=\"672\" class=\"aligncenter size-large wp-image-20003\" \/><\/a><\/p>\n<h2>How Silence works<\/h2>\n<p>The victim, a financial employee, opens the attached &#8220;contract,&#8221; which is a file with the .chm extension, a Microsoft help file. The embedded HTML file contains malicious JavaScript code, which loads and activates a <a href=\"https:\/\/securelist.com\/threats\/trojan-droppers-glossary\/\">dropper<\/a> that then loads the modules of the Silence Trojan, which operate as Windows services. We have found modules for control and monitoring, screen recording, and communication with control servers, plus a program for remote execution of console commands.<\/p>\n<p>The modules let the attackers collect data about the infected network and record images from employees&#8217; screens. At first, they monitor everyone, but then they shift focus to those most likely to possess useful financial information. Once the intruders have a thorough understanding of how the victim&#8217;s information systems work, they give the order to transfer funds to their own accounts.<\/p>\n<p>Technical details and IOCs can be found in this <a href=\"https:\/\/securelist.com\/the-silence\/83009\/\">Securelist post<\/a>.<\/p>\n<h3>How to protect your business against a Silence attack<\/h3>\n<p>As you can see, reminding employees not to open attachments from external e-mails is not sufficient. To protect financial institutions against modern-day cyberthreats, we recommend:<\/p>\n<ol>\n<li>Holding training sessions and workshops to raise employee awareness. Check out <a href=\"https:\/\/www.kaspersky.com\/advert\/enterprise-security\/security-awareness?redef=1&amp;THRU&amp;reseller=gl_kdailypost_acq_ona_smm__onl_b2b_kasperskydaily_lnk_______\">Kaspersky Security Awareness<\/a>, for example: It&#8217;s not a series of lectures about threats, but more practical exercises with attack simulations that help to develop employees&#8217; practical skills.<\/li>\n<li>Using solutions capable of detecting anomalies in the network at a deep level. For example, <a href=\"https:\/\/www.kaspersky.com\/advert\/enterprise-security\/anti-targeted-attack-platform?redef=1&amp;THRU&amp;reseller=gl_enterprsec_acq_ona_smm__onl_b2b_blog_ban____kata___\">Kaspersky Anti Targeted Attack<\/a>. This security solution is able to detect targeted attacks even if they employ as-yet-unknown methods.<\/li>\n<\/ol>\n<p> <input type=\"hidden\" class=\"category_for_banner\" value=\"finance-promo\" \/> <br \/><a href=\"https:\/\/www.kaspersky.com\/blog\/silence-financial-apt\/19993\/\" target=\"bwo\" >https:\/\/blog.kaspersky.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: Nikolay Pankov| Date: Wed, 01 Nov 2017 15:14:20 +0000<\/strong><\/p>\n<p>Silence: A new APT attack on financial institutions <\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10425,10378],"tags":[11029,16278,1001,9190,16279,16280,16281,3924,16143,12269],"class_list":["post-10215","post","type-post","status-publish","format-standard","hentry","category-kaspersky","category-security","tag-apt","tag-banks","tag-business","tag-finance","tag-funds","tag-kaspersky-anti-targeted-attack","tag-kaspersky-security-awareness","tag-phishing","tag-silence","tag-trojans"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/10215","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=10215"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/10215\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=10215"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=10215"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=10215"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}