-

Kaspersky Uncovers Malicious Campaign Targeting the Middle East

WOBURN, Mass.--(BUSINESS WIRE)--Kaspersky’s Global Research and Analysis Team (GReAT) have uncovered a targeted campaign to distribute Milum, a malicious Trojan that gains remote control of devices in various organizations including those representing the industrial sector. This operation is currently active and has been named WildPressure.

Advanced persistent threats (APTs) are commonly associated with the most sophisticated types of cyberattacks. Quite often, the attacker secretly gains extended access into a system to steal information or disrupt its normal operation. These attacks are typically created and deployed by actors that have access to large financial and professional resources. Given the nature of this threat, WildPressure quickly gained the attention of Kaspersky researchers.

So far, the GReAT team was able to uncover several almost identical samples of the “Milum” Trojan that share no code similarities with any known malicious campaigns. The samples possess solid capabilities for remote device management meaning once a system is affected, an attacker can take control from anywhere. In particular, the Trojan can:

  • Download and execute commands from its operator
  • Collect various information from the attacked machine and send it over to the command and control server
  • Upgrade itself to a newer version

Kaspersky’s GReAT team first witnessed the spread of the “Milum” Trojan in August 2019. Analysis of the malware’s code showed that the first three samples were created in March 2019. Based on available telemetry data, Kaspersky researchers believe most of the targets of this campaign are located in the Middle East, and the campaign itself is currently ongoing.

At this time, there are still uncertainties about this campaign including the exact mechanism of how Milum is spread.

“Any time the industrial sector is being targeted, it’s concerning,” says Kaspersky senior security researcher Denis Legezo. “Analysts must pay attention because the consequences of an attack against an industrial target can be devastating. So far, we haven’t seen any clues that would support the idea that the attackers behind WildPressure have intentions beyond gathering information from the targeted networks. However, this campaign is still actively developing, and we’ve already discovered new malicious samples apart from the three originally discovered. At this point, we don’t know what will happen as WildPressure develops, but we will be continuing to monitor its progression.”

Read more about the WildPressure operation on Securelist.

About Kaspersky

Kaspersky is a global cybersecurity company founded in 1997. Kaspersky’s deep threat intelligence and security expertise is constantly transforming into innovative security solutions and services to protect businesses, critical infrastructure, governments and consumers around the globe. The company’s comprehensive security portfolio includes leading endpoint protection and a number of specialized security solutions and services to fight sophisticated and evolving digital threats. Over 400 million users are protected by Kaspersky technologies and we help 270,000 corporate clients protect what matters most to them. Learn more at usa.kaspersky.com.

Contacts

Cassandra Faro
Cassandra.Faro@Kaspersky.com
781-503-1812

Kaspersky


Release Summary
Kaspersky uncovers targeted malicious campaign in the Middle East
Release Versions

Contacts

Cassandra Faro
Cassandra.Faro@Kaspersky.com
781-503-1812

More News From Kaspersky

Kaspersky North America Wins Silver for “Support Department of the Year” in the 10th Annual Best in Biz Awards

WOBURN, Mass.--(BUSINESS WIRE)--Kaspersky North America has been named a silver winner in the “Support Department of the Year” category of the Best in Biz Awards, the tenth annual business awards program judged by prominent editors and reporters from top-tier North American publications. The award was achieved by the Kaspersky North American support and services department, which delivers a wide range of premium support, professional services and training offerings. Throughout the year the team...

Kaspersky Report: Criminals Targeted Remote Work In 2020

WOBURN, Mass.--(BUSINESS WIRE)--Kaspersky researchers have analyzed the redistribution of threat activity that took place in 2020, as the COVID-19 pandemic caused a worldwide, involuntary shift to digital platforms and tools used to work and carry out other aspects of our lives from home. The new way of life resulted in organizations adjusting their corporate networks and led to the emergence of new threats to target those networks, as well as the strengthening of existing threats. Details on t...

Safe_expression: Kaspersky and KRAKATAU Present Unique Clothing Collection Customized by Your Digital Imprint

WOBURN, Mass.--(BUSINESS WIRE)--Today, self-expression is not only about showing our individuality through the clothes we wear and how we look but also by what we do online - with many of us using new media to share our views and beliefs. How can people create their digital identities and express themselves while keeping their unique personality safe online? To raise awareness about the importance of privacy and freedom of self-expression, Kaspersky and international techwear brand KRAKATAU hav...
Back to Newsroom