Article 43BC6 Ukraine detects new Pterodo backdoor malware, warns of Russian cyberattack

Ukraine detects new Pterodo backdoor malware, warns of Russian cyberattack

by
Sean Gallagher
from Ars Technica - All content on (#43BC6)
4291363661_0ce34de759_b-800x534.jpg

Enlarge (credit: Mira Mechtley )

The Computer Emergency Response Team of Ukraine (CERT-UA) and the Foreign Intelligence Service of Ukraine have detected a new strain of the Pterodo Windows backdoor targeting computers at Ukrainian government agencies, leading officials in Kiev to warn of a pending large-scale cyber attack.

In an alert posted to the organization's website, a CERT-UA official wrote:

CERT-UA together with the Foreign Intelligence Service of Ukraine found new modifications of Pterodo-type malware on computers of state authorities of Ukraine, which is likely to be the preparatory stage for a cyber attack. This virus collects system data, regularly sends it to command-control servers and expects further commands.

Pterodo, also known as Pteradon, is associated with the Gamaredon threat group, a group of attacks based largely on off-the-shelf software that have focused on Ukrainian military and government targets. Pterodo is a custom backdoor used to insert other malware and collect information. The latest version activates only on Windows systems with language localization for Ukrainian, Belarusian, Russian, Armenian, Azerbaijani, Uzbek, Tatar, and other languages associated with former Soviet states; this makes it more difficult to perform automated analysis of the malware with certain tools.

Read 4 remaining paragraphs | Comments

index?i=j75QIrpJpQc:811tLIVqgqk:V_sGLiPB index?i=j75QIrpJpQc:811tLIVqgqk:F7zBnMyn index?d=qj6IDK7rITs index?d=yIl2AUoC8zA
External Content
Source RSS or Atom Feed
Feed Location http://feeds.arstechnica.com/arstechnica/index
Feed Title Ars Technica - All content
Feed Link https://arstechnica.com/
Reply 0 comments