Menu
Arabic cyberespionage group attacking Middle Eastern, other targets

Arabic cyberespionage group attacking Middle Eastern, other targets

The Desert Falcons mercenary group has stolen more than 1 million files since 2013

An Arabic cyberespionage group has attacked thousands of high-profile targets in Egypt, Israel, Jordan and other countries for the past two years, cybersecurity vendor Kaspersky Lab said.

The cybermercenaries, which the vendor dubbed the Desert Falcons, has stolen more than 1 million files from 3,000 victims in more than 50 countries, Kaspersky Lab said Tuesday. The group, likely native Arabic speakers, began in 2011, with the first infections coming in 2013, the company said.

Targeted countries include Algeria, Lebanon, Turkey and the United Arab Emirates in the Middle East, and the U.S., Russia, France and Sweden beyond the region, Kaspersky said.

The group's motivation seems to be political, with targets including industry, politicians and prominent activists, said Dmitry Bestuzhev, a security expert at Kaspersky's Lobal Research and Analysis Team.

Whoever is behind the group is not interested in money but in secret classified information that can offer advantages in negotiations or political maneuvering, he said by email.

The attackers appears to be using the stolen information "exclusively for their own needs," he added. The information has not been offered for sale or exposed publicly.

The group uses phishing attacks through email, social-networking sites and chat messages to gain access to an organization, then plants two backdoors in computer systems, Kaspersky said. The backdoor malware, which appears to be developed from scratch, gives the attackers the ability to take screen shots, log keystrokes, upload and download files and collect Word and Excel files on a victim's hard drive or connected USB device, the company said.

The Desert Falcons have targeted Windows and Android systems, the vendor said.

The group has used several techniques to entice victims to run malicious files, including the so-called right-to-left extension override trick, a way in Unicode to reverse the order of characters in a file name, the cybersecurity vendors said.

This is the third major cyberthreat announcement Kaspersky Lab has made this week. On Sunday, the company reported that a still-active cybercriminal gang has stolen up to US $1 billion from banks in at least 25 countries over the last two years.

And on Monday, Kaspersky reported that a cyberespionage group using tools similar to ones used by U.S. intelligence agencies has infiltrated key institutions in countries such as Iran and Russia.

The Desert Falcons group is made up of at least 30 people, operating in three teams and spread across several countries, according to Kaspersky estimates.

The group's members are "highly determined, active and with good technical, political and cultural insight," Bestuzhev said.

Grant Gross covers technology and telecom policy in the U.S. government for The IDG News Service. Follow Grant on Twitter at GrantGross. Grant's email address is grant_gross@idg.com.

Subscribe here for up-to-date channel news

Follow Us

Join the New Zealand Reseller News newsletter!

Error: Please check your email address.

Tags Dmitry Bestuzhevsecuritydata breachExploits / vulnerabilitieskaspersky lab

Featured

Slideshows

StorageCraft celebrates high achievers at its inaugural A/NZ Partner Awards

StorageCraft celebrates high achievers at its inaugural A/NZ Partner Awards

Revealed at a glitzy bash in Sydney at the Ivy Penthouse, the first StorageCraft Partner Awards locally saw the vendor honour its top-performing partners with ASI Solutions, SMBiT Pro, Webroot, ACA Pacific and Soft Solutions New Zealand taking home the top awards. Photos by Maria Stefina.

StorageCraft celebrates high achievers at its inaugural A/NZ Partner Awards
Kiwi resellers make a splash on Synnex and Lenovo RotoVegas road trip

Kiwi resellers make a splash on Synnex and Lenovo RotoVegas road trip

​Synnex and Lenovo hosted 18 resellers for an action-packed weekend adventure in RotoVegas, taking in white water rafting on the Kaituna River, as well as quad biking and dinner at Stratosfare​, overlooking Lake Rotorua at the top of Mount Ngongotaha​. Photos by Synnex.

Kiwi resellers make a splash on Synnex and Lenovo RotoVegas road trip
Show Comments