Back to news

June 18, 2024 | International, Security

Cybercriminals Exploit Free Software Lures to Deploy Hijack Loader and Vidar Stealer

Cybercriminals exploit free software lures and social engineering tactics to deploy Hijack Loader, Vidar Stealer, and other malware, targeting unsuspe

https://thehackernews.com/2024/06/cybercriminals-exploit-free-software.html

On the same subject

  • This training tool could be the answer to stop mass cyberattacks

    July 9, 2020 | International, C4ISR, Security

    This training tool could be the answer to stop mass cyberattacks

    Mark Pomerleau At air bases across Europe, networks are under attack. Malicious hackers have gained access to sensitive systems, information, controls and critical infrastructure. But cyber operators from U.S. Cyber Command, in concert with Five Eyes partners, have been called in to thwart these attempts in real time. This was the main scenario for this year's capstone cyber training exercise put on by Cyber Command, Cyber Flag 20-2. The exercise, which took place June 15-26 and was exclusively defensive in nature, saw more than 500 participants and 17 teams participating from five countries across nine time zones, and it included America's National Guard, the U.S. Energy Department and the Five Eyes alliance — Australia, Britain, Canada, New Zealand and the U.S. Australia, however, did not participate during this iteration. Officials told reporters this week that the purpose of Cyber Flag 20-2 was to continue building the community of defensive cyber operations and to improve the overall capability of the Five Eyes countries to defend against cyber aggressors. The drill involved teams defending IT and operational security networks against a live, opposing force trying to disrupt, deny and degrade the air bases' operations. The networks under attack were industrial control systems simulated to generate network traffic for an aviation fuel farm, power grid, air traffic control radars and electronic access control systems. The attacks came in the form of malware that targeted devices responsible for fuel and power. But the unique aspect of this year's exercise, as C4ISRNET previously reported, was the use of a new remote cyber training tool called the Persistent Cyber Training Environment. PCTE is an online client that allows Cyber Command's cyber warriors, as well as partner nations, to log on from anywhere in the world to conduct individual or collective cyber training as well as mission rehearsal, which to date had not existed for the cyber force as it does for physical troops. The program is run by the Army on behalf of the joint cyber force. The platform not only allowed the exercise to continue as planned amid the coronavirus pandemic, but it enabled collaboration and simultaneous training across the world. A new way to train Officials say PCTE is providing Cyber Command with an entirely new way to train cyber forces, which previously was difficult given a lack of infrastructure and the time needed to set up ranges and scenarios. It also allows Cyber Command and military units to conduct more frequent training. Cyber Flag typically was Cyber Command's largest and only holistic tactical training event, held annually during June. For units, aside from Cyber Flag, there were no other ways to stay sharp on their skills unless they built their own environments. Now, Cyber Command plans to hold more exercises, with Cyber Flag 20-3 occurring in the fall. “The delivery of the Persistent Cyber Training Environment absolutely allows us to increase the frequency and the complexity of exercises that are conducted by the command itself,” Coast Guard Rear Adm. John Mauger, director of exercises and training at Cyber Command, told reporters. “Going forward, I would expect you to see a series of exercises throughout the year where we are reaching out to the different teams to test their capabilities or to focus on specific issues that are of concern or interest to us. “Going forward, we're going to get the benefits of both those distributed exercises along with increasingly complex exercises as PCTE is instantiated across both the secret network and the top-secret network.” Scenarios and environments can be stored, saved, reused and modified if needed in the system for later exercises. Smaller units will also be able to leverage these scenarios to practice whenever needed. The PCTE virtual environment for this year's exercise included 25 interconnected ranges of more than 3,000 virtual machines — a high-fidelity network that simulated and emulated open internet traffic with more than 4,000 static websites that store and share data. The simulated air base networks created in PCTE had fully configured Windows active directory domains with over 100 nodes running more than 10 types of major operating systems, along with 35 simulated user control workstations actively surfing the internet and using Microsoft Office products to access, create and transfer files. Moreover, officials also explained PCTE can be integrated into larger, multi-combatant command-type exercises to simulate the cyber effects, such as Global Lightning and its companion Cyber Lightning. Global Lightning is an annual global exercise run by Strategic Command to test integration across several geographic and functional combatant commands. Cyber Lightning is Cyber Command's portion to the exercise. “We think that is the next evolution of the Persistent Cyber Training Environment and how we take to the tier 1 exercises, incorporate cyber effects. They're no longer white-carded,” Col. Tanya Trout, Cyber Command's PCTE director and acting director of the Joint Cyber Training Enterprise, told reporters. White carding involves telling exercise participants that a certain action has occurred. This was typical of cyber effects, given it was difficult to realistically simulate them, which diminished the training value in exercises because participants didn't experience the full breadth of these actions. Now, these activities can play a real role in exercises increasing the overall fidelity of training across the joint force and continuity of all operations of warfare. The system will also be able to be used for mission rehearsals. A Cyber Command official said the force can input prior operations, such as those used against the Islamic State group, to train against. Additionally, they'll be able to upload to the platform malware discovered in operations. The PCTE program office, which is in the prototyping phase despite delivering the first portion to Cyber Command in February 2020, also learned valuable lessons in Cyber Flag. Officials said the two-week exercise provided the program office with six months' worth of data it can use to make significant improvements. Prior to the February delivery, the program office leveraged several smaller-scale training events at the unit level to incrementally increase capabilities and scalability as well as help geographically dispersed teams prepare for tier 1 exercises like Cyber Flag. Overall, officials are happy with how the system performed in its first tier 1 exercise, pointing to little to no latency issues, though there were periodic improvement tickets. “What we found through the rapid development and use of the Persistent Cyber Training Environment is that we really have a unique capability to move forward with,” Mauger said. https://www.c4isrnet.com/dod/cybercom/2020/06/25/this-training-tool-could-be-the-answer-to-stop-mass-cyberattacks

  • Why Nothing (Even The Air Force) Can Kill The A-10 Warthog

    October 7, 2021 | International, Aerospace

    Why Nothing (Even The Air Force) Can Kill The A-10 Warthog

    Will no one rid us of this troublesome A-10 ‘Warthog’? The United States Air Force (USAF) has spent almost two-thirds of its existence as an independent service trying to get rid of the A-10, one of its most well-known aircraft. But has the Air Force finally given up? It is odd to think that a […]

  • Indra provides the Spanish Army with the most advanced helicopter simulator in Europe

    October 30, 2019 | International, Aerospace

    Indra provides the Spanish Army with the most advanced helicopter simulator in Europe

    October 25, 2019, Spain - Indra, one of the leading multinational technology and consulting companies, has delivered the most advanced helicopter flight simulator in Europe to the Spanish Army. It is the NH90 training system, which contributes to the training of pilots of the three army corps and has been installed at the Héroes del Revellín base in Agoncillo (La Rioja, Spain) as part of the Helicopter Simulation Center (CESIHEL) of the Aviation Academy of the Spanish Army (ACAVIET). The official reception of the system took place this morning in an act chaired by the General Director of Armament and Material (DIGAM), Admiral Santiago Ramón González, in the presence of the Logistic Support Command Chief of the Spanish Army (JEMALE), Lieutenant General Ramón Pardo de Santayana, various Army commanders, and the General Director of Indra, Ignacio Mataix. The NH90 simulator is Indra's new "crown jewel" in simulation. With its launch, the company strengthens its position in the global military simulation market that has grown steadily in recent years and in 2017 generated around 10.8 billion dollars. Indra is positioned ahead of its competitors as a candidate to meet the training needs of the 13 countries and 18 users who have the NH90, both in Europe and the rest of the world. The use of synthetic training systems is essential in preparing pilots of an aircraft equipped with the most complex systems, greatly reducing training times and increasing safety while lowering costs. Indra's simulator recreates with maximum fidelity and realism all the missions in which a military pilot can participate. It has been specially designed for tactical training. On board, pilots can prepare for real operations before carrying them out in their deployments. Remote virtual network training This new system will be integrated into the Army's simulator network, allowing its pilots to carry out joint training missions with other helicopter simulators found in other army bases such as the CH-47D Chinook, the AS532 Cougar, the EC135 or the EC665 Tiger attack helicopter. This means all the pilots will share the same scenario and can train together, regardless of being separated by hundreds of kilometers. The new system represents a decisive commitment to innovation and development of proprietary technologies by the Spanish Ministry of Defense. It ensures top-quality training for pilots of this multipurpose helicopter, the most advanced of its kind in the world, as it is an aircraft designed to carry out missions ranging from tactical transportation and medical evacuation, to special operations, and naval, antisubmarine and electronic combat. About Indra Indra (www.indracompany.com) is one of the leading global technology and consulting companies and is a technology partner for the key business operations of its clients worldwide. It is a leading global supplier of proprietary solutions in specific segments of the Transportation and Defense markets, and a leading company in digital transformation and Information Technology consulting in Spain and Latin America through its subsidiary, Minsait. Its business model is based on a comprehensive offer of its own products, with an end-to-end approach, high-value and a high innovation aspect. In 2018 financial year, Indra achieved revenue of 3.104 billion, with 43,000 employees, a local presence in 46 countries and business operations in more than 140 countries. View source version on Indra: https://www.indracompany.com/en/noticia/indra-provides-spanish-army-advanced-helicopter-simulator-europe

All news