{"id":41721,"date":"2019-09-25T15:47:58","date_gmt":"2019-09-25T14:47:58","guid":{"rendered":"https:\/\/www.intelligentcio.com\/me\/?p=41721"},"modified":"2023-10-02T11:35:56","modified_gmt":"2023-10-02T10:35:56","slug":"cybercriminals-attack-kuwait-shipping-and-transportation-organisations","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/me\/2019\/09\/25\/cybercriminals-attack-kuwait-shipping-and-transportation-organisations\/","title":{"rendered":"Cybercriminals attack Kuwait shipping and transportation organisations"},"content":{"rendered":"\n<p>Palo Alto Networks has revealed how cybercriminals attacked organisations\nin Kuwait.<\/p>\n\n\n\n<p>Unit 42, the global threat intelligence team at Palo Alto\nNetworks, observed previously unknown tools used in the targeting of\ntransportation and shipping organisations based in the country.<\/p>\n\n\n\n<p>The first known attack in this campaign targeted a Kuwait\ntransportation and shipping company in which the actors installed a backdoor\ntool named Hisoka. Several custom tools were later downloaded to the system in\norder to carry out post-exploitation activities. <\/p>\n\n\n\n<p>All of these tools appear to have been created by the same\ndeveloper. The team were able to collect several variations of these tools\nincluding one dating back to July 2018.&nbsp; <\/p>\n\n\n\n<p>The developer of the collected tools used character names\nfrom the anime series Hunter x Hunter, which is the basis for the campaign name\n\u2018xHunt\u2019. <\/p>\n\n\n\n<p>The names of the tools collected include backdoor tools\nSakabota, Hisoka, Netero and Killua. These tools not only use HTTP for their\ncommand and control (C2) channels, but certain variants of these tools use DNS\ntunneling or emails to communicate with their C2 as well. <\/p>\n\n\n\n<p>While DNS tunneling as a C2 channel is fairly common, the\nspecific method in which this group used email to facilitate C2 communications\nhas not been observed by Unit 42 in quite some time. <\/p>\n\n\n\n<p>This method uses Exchange Web Services (EWS) and stolen\ncredentials to create email \u2018drafts\u2019 to communicate between the actor and the\ntool. In addition to the aforementioned backdoor tools, the team also observed\ntools referred to as Gon and EYE, which provide the backdoor access and the\nability to carry out post-exploitation activities. <\/p>\n\n\n\n<p>Through comparative analysis, the team identified related\nactivity also targeting Kuwait between July and December 2018, which was\nrecently reported by IBM X-Force IRIS. While there are no direct infrastructure\noverlaps between the two campaigns, historical analysis shows that the 2018 and\n2019 activities are likely related.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Palo Alto Networks has revealed how cybercriminals attacked organisations in Kuwait. Unit 42, the global threat intelligence team at Palo Alto Networks, observed previously unknown tools used in the targeting of transportation and shipping organisations based in the country. The first known attack in this campaign targeted a Kuwait transportation and shipping company in which [&hellip;]<\/p>\n","protected":false},"author":18,"featured_media":41831,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[5,3032,36,15963,809,3343],"tags":[3106,10324,233,127,3594,2659,10325],"class_list":["post-41721","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-enterprise-security","category-industry-verticals","category-intelligent-technology","category-kuwait","category-more-news","category-transport","tag-cybercriminals","tag-hisoka","tag-kuwait","tag-palo-alto-networks","tag-shipping","tag-transportation","tag-xhunt"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/41721","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/users\/18"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/comments?post=41721"}],"version-history":[{"count":4,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/41721\/revisions"}],"predecessor-version":[{"id":41827,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/41721\/revisions\/41827"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media\/41831"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media?parent=41721"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/categories?post=41721"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/tags?post=41721"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}