{"id":56434,"date":"2020-12-14T07:04:15","date_gmt":"2020-12-14T07:04:15","guid":{"rendered":"https:\/\/www.intelligentcio.com\/me\/?p=56434"},"modified":"2020-12-14T07:04:17","modified_gmt":"2020-12-14T07:04:17","slug":"deathstalker-a-detailed-look-at-a-mercenary-apt-group-that-targets-businesses-in-me","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/me\/2020\/12\/14\/deathstalker-a-detailed-look-at-a-mercenary-apt-group-that-targets-businesses-in-me\/","title":{"rendered":"DeathStalker: A detailed look at a mercenary APT group that targets businesses in ME"},"content":{"rendered":"\n<p>Kaspersky researchers have published a detailed overview of DeathStalker, a \u2018mercenary\u2019 advanced persistent threat (APT) group that has been leveraging efficient espionage attacks on small and medium-sized firms since 2013.<\/p>\n\n\n\n<p>DeathStalker is presumably a hacker-for-hire group that targets victims from around the world further signifying the size of their operations. Despite their global targeting, this group focused in targeting Middle Eastern countries.<\/p>\n\n\n\n<p>Kaspersky has seen increased activity in the United Arab Emirates (UAE), Lebanon, and Turkey. Experts have also noticed that DeathStalker uses spear-phishing emails to target governments, capital markets, FinTechs, law firms and particularly SMBs.<\/p>\n\n\n\n<p>DeathStalker is a unique threat group which mainly focuses on cyber-espionage against law firms and organisations in the financial sector. The threat actor is highly adaptive and notable for using an iterative toolset, making them able to execute effective campaigns. Based on Kaspersky\u2019s analysis, the group potentially started in 2013 and is still active with evolving techniques.<\/p>\n\n\n\n<p>\u201cDeathStalker is a prime example of a threat actor that organisations in the private sector need to defend themselves against. It will continue to impact organisations in the Middle East and even those organisations that are not traditionally the most security-conscious need to be aware of becoming targets too. Its persona-based tactic is what sets it apart from the rest of the APT groups and at Kaspersky we urge businesses in the Middle East to stay vigilant of this threat,\u201d said Maher Yamout, Senior Security Researcher at Kaspersky.<\/p>\n\n\n\n<p>Recent research enabled Kaspersky to link DeathStalker\u2019s activity to three malware families, Powersing, Evilnum and Janicab, which demonstrates the breadth of the groups\u2019 activity carried out since at least 2013. While Powersing malware family has been traced by Kaspersky since 2018, the other two malware families have been reported on by other cybersecurity vendors. Analysis of code similarities and victimology between the three malware families enabled the researchers to link them to each other with medium confidence.<\/p>\n\n\n\n<p>\u201cOur experts at Kaspersky have noticed that these cyber-mercenaries use interactive social engineering to target users. The attacker doesn\u2019t only send a phishing email with the hopes that the target will open it but keeps sending interactive emails with a pretext or a persona. It is a tactic used to gain victims\u2019 attention and lure them to open malicious files,\u201d Yamout added.<\/p>\n\n\n\n<p>In order to avoid falling victim to a targeted attack by a known or unknown threat actor, Kaspersky researchers recommend implementing the following measures:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li><strong>Educate employees about phishing attacks:<\/strong> APTs start with a fraudulent email that gains access to your system<\/li><li>Deploy a training programme that teaches employees what to look for, what to do and who to notify if they spot something suspicious<\/li><li><strong>Ensure that the latest updates are installed:<\/strong> APT hackers look to exploit any weakness in a system, which is why it is important to run updates on all cybersecurity programs.<\/li><li><strong>Secure sensitive data:<\/strong> Take the additional safety measures to save your most sensitive information<\/li><li>Use application whitelisting tools to prevent unauthorised applications from running<\/li><\/ul>\n\n\n\n<p>Kaspersky further recommends that future awareness training and security product assessments include infection chains based on LNK (shortcut) files.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Kaspersky researchers have published a detailed overview of DeathStalker, a \u2018mercenary\u2019 advanced persistent threat (APT) group that has been leveraging efficient espionage attacks on small and medium-sized firms since 2013. DeathStalker is presumably a hacker-for-hire group that targets victims from around the world further signifying the size of their operations. Despite their global targeting, this [&hellip;]<\/p>\n","protected":false},"author":18,"featured_media":54782,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[5,36,432,232,791,13,185],"tags":[2157,12581,12579,12580,7258,364,12582,3479,926,184],"class_list":["post-56434","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-enterprise-security","category-intelligent-technology","category-oman","category-qatar","category-ksa","category-top-stories","category-uae","tag-apt","tag-capital-markets","tag-deathstalker","tag-fintechs","tag-governments","tag-kaspersky","tag-law-firms","tag-lebanon","tag-turkey","tag-uae"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/56434","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/users\/18"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/comments?post=56434"}],"version-history":[{"count":1,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/56434\/revisions"}],"predecessor-version":[{"id":56435,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/56434\/revisions\/56435"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media\/54782"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media?parent=56434"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/categories?post=56434"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/tags?post=56434"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}