Sea Turtle hacking group goes after government domains

Researchers at Cisco's Talos cybersecurity unit have discovered a new hacker group that has targeted 40 government and intelligence age...

Researchers at Cisco's Talos cybersecurity unit have discovered a new hacker group that has targeted 40 government and intelligence agencies, telecoms and internet giants in 13 countries for more than two years.

While the new campaign bears some similarities to DNSpionage, which rerouted users from legitimate websites to a malicious server to steal their passwords, the researchers have assessed with high confidence that the campaign they've dubbed “Sea Turtle” is a new, separate operation.

Sea Turtle targets companies by hijacking their DNS by pointing a target's domain name to malicious server instead of to its intended target.

The site-spoofing technique used by the hackers behind the campaign exploits long-known flaws in DNS that can be used to trick unsuspecting victims into imputing their credentials on fake login pages.

Sea Turtle

The attacks launched by Sea Turtle work by first compromising a target using spear phishing to establish a foothold on their network. Known exploits are then used to target servers and routers to move laterally inside a company's network to obtain network-specific passwords. These credentials are then used to target an organization's DNS registrar by updating its records so that its domain name points away from its IP address and instead to a server controlled by the hackers.

The hackers then employ a man-in-the-middle operation to impersonate login pages and obtain additional credentials to move even further into a company's network. By using their own HTTPS certificate for the target's domain, the attackers can make a malicious server appear genuine.

According to Talos, the hackers used this technique to compromise the Swedish DNS provider Netnod as well as one of the 13 root servers that powers the global DNS infrastructure.

The hackers also were able to gain access to the registrar that manages Armenia's top-level domains using similar tactics.

While Talos has not revealed which state is behind the group, its researchers say that Sea Turtle is “highly capable” and have provided mitigation instructions in a blog post, saying:

“Talos suggests using a registry lock service, which will require an out-of-band message before any changes can occur to an organization's DNS record. If your registrar does not offer a registry lock service, we recommend implementing multi-factor authentication, such as DUO, to access your organization's DNS records. If you suspect you were targeted by this type of activity intrusion, we recommend instituting a network-wide password reset, preferably from a computer on a trusted network. Lastly, we recommend applying patches, especially on internet-facing machines. Network administrators can monitor passive DNS record on their domains, to check for abnormalities.”

Via TechCrunch

  • Protect your online privacy with the best VPN


from TechRadar - All the latest technology news http://bit.ly/2ItEBy1
via IFTTT

COMMENTS

BLOGGER
Name

Latest from TechRadar,63, 9to5Mac,7, AI News & Artificial Intelligence | TechCrunch,2, Apple,10, Cointelegraph.com News,9, Electrek,5, Space Explored,2, Technology,108, The Verge,45, TrendlyNews,27, YouTube - 9to5Google,13,9to5Mac,10,AI,2,Apps,4063,Business,151,Camera,1162,Crypto,9,Earn $$$,3,Gadgets,1741,Games,927,GTA,1,IFTTT,7,Innovations,3,Mobile,1700,Paid Promotions,5,Promotions,5,Space,2,Sports,1,Technology,8808,Trailers,796,Travel,37,Trending,4,Trendly News,25458,TrendlyNews,342,Vehicles,5,Video,5,XIAOMI,13,YouTube - 9to5Google,219,
ltr
item
TrendlyNews | #ListenNow #Everyday #100ShortNews #TopTrendings #PopularNews #Crypto #Ai #TrendlyNews: Sea Turtle hacking group goes after government domains
Sea Turtle hacking group goes after government domains
TrendlyNews | #ListenNow #Everyday #100ShortNews #TopTrendings #PopularNews #Crypto #Ai #TrendlyNews
http://www.trendlynews.in/2019/04/sea-turtle-hacking-group-goes-after.html
http://www.trendlynews.in/
http://www.trendlynews.in/
http://www.trendlynews.in/2019/04/sea-turtle-hacking-group-goes-after.html
true
3372890392287038985
UTF-8
Loaded All Posts Not found any posts VIEW ALL Readmore Reply Cancel reply Delete By Home PAGES POSTS View All RECOMMENDED FOR YOU LABEL ARCHIVE SEARCH ALL POSTS Not found any post match with your request Back Home Sunday Monday Tuesday Wednesday Thursday Friday Saturday Sun Mon Tue Wed Thu Fri Sat January February March April May June July August September October November December Jan Feb Mar Apr May Jun Jul Aug Sep Oct Nov Dec just now 1 minute ago $$1$$ minutes ago 1 hour ago $$1$$ hours ago Yesterday $$1$$ days ago $$1$$ weeks ago more than 5 weeks ago Followers Follow THIS PREMIUM CONTENT IS LOCKED STEP 1: Share. STEP 2: Click the link you shared to unlock Copy All Code Select All Code All codes were copied to your clipboard Can not copy the codes / texts, please press [CTRL]+[C] (or CMD+C with Mac) to copy