Command servers, which are used to issue instructions to computers – such as “send me all of your documents” – connected to victims through a variety of seemingly innocent networks such as Google groups, Yahoo e-mail and Twitter accounts. Those intermediaries were used to relay links or files to a recipient in a target organization. Once the user clicks on the link or opens an attachment in an infected e-mail, the computer relays a beacon to the command server, which instructs it to start sending files to a dump zone.I'd be very interested to know what the target platforms and applications are. At the risk of setting off the usual, um, civil and informed discussion, presumably Windows/I, for reasons of market share at least, but it'd be nice to know if they routinely exploit vulnerabilities in any other client systems and what they are.
« Older Atta Kim... | Boys Will Be Girls, Girls Will... Newer »
This thread has been archived and is closed to new comments
posted by XMLicious at 9:08 PM on April 5, 2010 [2 favorites]