Welcome, Guest: Register On Nairaland / LOGIN! / Trending / Recent / New
Stats: 3,195,533 members, 7,958,635 topics. Date: Wednesday, 25 September 2024 at 07:15 PM

Samsung Service Centers In Italy Targeted In Malware Campaign - Science/Technology - Nairaland

Nairaland Forum / Science/Technology / Samsung Service Centers In Italy Targeted In Malware Campaign (309 Views)

Po River, The Longest River In Italy,dries Up (Pix) / Bizarre Giant Pig-Faced Shark Pulled Out Of The Water In Italy / 17-year-old Boy Arrested For Coding Malware To Steal Password Of Crypto Wallet (2) (3) (4)

(1) (Reply)

Samsung Service Centers In Italy Targeted In Malware Campaign by danny638: 2:24pm On Jul 17, 2018
Samsung Service Centers in Italy Targeted in Malware Campaign


Security researchers have discovered ongoing malware campaigns targeting Samsung service centers in Italy, campaigns that appear to be the counterparts of attacks that have previously targeted similar electronics service centers in Russia this year.

These malware campaigns are nothing out of the extraordinary, and the only thing that remains a mystery is their purpose and end goal.

Mundane malware distribution effort
The attacks usually start with the delivery of spoofed spear-phishing emails to Samsung Italy service center workers.

These emails carry attached Excel documents that when opened leverage the CVE-2017-11882 Office Equation Editor vulnerability to infect users with malware.

The entire malware delivery system and exploit chain is described in a detailed report published by Italian cyber-security firm TG Soft and is near identical to the attacks targeting electronics service centers in Russia, as described in a previous Fortinet report.

Both attack waves, targeting Italy and Russia, started at the end of March, according to the two reports. But while Russian service centers were targeted with the Imminent Monitor RAT, the attacks on Samsung Italy service centers also leveraged other RATs, such Netwire and njRAT.

Both companies also noted that the spear-phishing emails are very well put together, and appear to have been written by a native in Italian and Russian, respectively.

Nobody knows the purpose of these attacks
But despite all the data gathered by TG Soft and Fortinet, the two companies have not been able to determine why the hackers are trying to infect electronics service centers, to begin with.

Such service centers hold very little customer data that a threat actor could steal, and an attacker having many other more attractive companies he could target and gain more useful data from.

One explanation may be that attackers are trying to taint the tools used in these service centers so that they could infect the repaired devices with malware. But this is only a theory, as no evidence has been unearthed to support this scenario, and this entire malware distribution campaign remains shrouded in a fog of mystery.

(1) (Reply)

Best Open Source API Testing Tools / Matlab Projects In Nigeria / 8 Essencial Plugins You Need For Your Wordpress Blog

(Go Up)

Sections: politics (1) business autos (1) jobs (1) career education (1) romance computers phones travel sports fashion health
religion celebs tv-movies music-radio literature webmasters programming techmarket

Links: (1) (2) (3) (4) (5) (6) (7) (8) (9) (10)

Nairaland - Copyright © 2005 - 2024 Oluwaseun Osewa. All rights reserved. See How To Advertise. 10
Disclaimer: Every Nairaland member is solely responsible for anything that he/she posts or uploads on Nairaland.