Search KuwaitPR.com

Home >> Technology

Cyberattacks on Kuwait Shipping and Transportation Organizations

Tuesday, September 24, 2019/ Editor -  

Share

Home >> Technology

September 24, 2019 - Kuwait

Between May and June 2019, Unit 42, the global threat intelligence team at Palo Alto Networks, observed previously unknown tools used in the targeting of transportation and shipping organizations based in Kuwait.

The first known attack in this campaign targeted a Kuwait transportation and shipping company in which the actors installed a backdoor tool named Hisoka. Several custom tools were later downloaded to the system in order to carry out post-exploitation activities. All of these tools appear to have been created by the same developer. We were able to collect several variations of these tools including one dating back to July 2018. 

The developer of the collected tools used character names from the anime series Hunter x Hunter, which is the basis for the campaign name “xHunt.” The names of the tools collected include backdoor tools Sakabota, Hisoka, Netero and Killua. These tools not only use HTTP for their command and control (C2) channels, but certain variants of these tools use DNS tunneling or emails to communicate with their C2 as well. While DNS tunneling as a C2 channel is fairly common, the specific method in which this group used email to facilitate C2 communications has not been observed by Unit 42 in quite some time. This method uses Exchange Web Services (EWS) and stolen credentials to create email “drafts” to communicate between the actor and the tool. In addition to the aforementioned backdoor tools, we also observed tools referred to as Gon and EYE, which provide the backdoor access and the ability to carry out post-exploitation activities.

Through comparative analysis, we identified related activity also targeting Kuwait between July and December 2018, which was recently reported by IBM X-Force IRIS. While there are no direct infrastructure overlaps between the two campaigns, historical analysis shows that the 2018 and 2019 activities are likely related.


Previous in Technology

Next in Technology


Home >> Technology Section

Latest Press Release

Khabib's Official Training Gloves Will Be Sold at Tooba Charity Auction in Dubai

Burgan Bank Sponsors the Bristol Rovers Football Academy

Porsche Centre Shuwaikh unveils the 2024 Panamera

Burgan Bank Adds Birthday Leaves to Employee Benefits

Burgan Concludes Sponsorship of Kuwait Equestrian Federation's 2023/2024 Tour

KIB shares Iftar meal with security guards as part of its Ramadan campaign

A Deep Dive into the New HUAWEI FreeClip: What Makes the C-bridge Design a Truly ...

KIB announces winners of Al Dirwaza account's monthly and weekly draw

Watches & Wonders 2024 Unico: Hublot's Manufacture Calibre

Bremont introduces a new generation of its Supermarine diving watch series

Ooredoo Kuwait Wraps Up Ramadan 2024 with a Range of Community-Driven Initiative ...

Burgan Bank continues to serve Its customers during Eid Al-Fitr holiday

KIB concludes its annual Ramadan campaign with numerous humanitarian initiatives

Ooredoo Kuwait Strengthens Commitment to Autism Awareness with Visit to Kuwait C ...

How the C-bridge Design Makes HUAWEI FreeClip the Stylish and Comfortable Earbud ...

Ro'ya Talent Program Concludes, Marking Milestone for Burgan Bank's Leadership D ...

Ooredoo Kuwait Unveils Exclusive Roaming Packages for Umrah Pilgrims

CEQUENS Announces Exclusive Partnership with stc Kuwait to Revolutionize Communi ...

Ooredoo Kuwait Sponsors “Longest Ramadan Iftar Table” in Mubarakiyah

The HUAWEI FreeClip: The Open Ear Earbuds that Combine Style and Comfort