Connect with us

Hi, what are you looking for?

BUSINESS

Trend Micro warns businesses, organizations on targeted attack called ‘Safe’

Trend Micro Incorporated, a global leader in consumer digital information security, has revealed a new targeted attack campaign called “Safe”.

Figure 2. Sample of Safe campaign spear-phishing email

Trend Micro Incorporated, a global leader in consumer digital information security, has revealed a new targeted attack campaign called “Safe” which compromised government ministries, technology firms, media outlets, academic institutions and non-governmental organizations from over 100 countries. 

This campaign was first seen on October 2012.

“Those obvious threat campaigns are becoming increasingly well known within the security community,” Macky Cruz, security focus lead of Trend Labs, Trend Micro Incorporated, said. “However, there are some new and smaller campaigns emerging as well, which could create successful and long-term compromises of high-value organizations and enterprises worldwide, and these campaigns cannot be ignored.”

These campaigns, such as “Safe”, use small clusters of C&C servers, new malware as well as attack fewer targets.

Advertisement. Scroll to continue reading.

The campaign involved nearly 12,000 unique IP addresses that were connected to two sets of command-and-control (C&C) servers with the countries involved being widely dispersed.

Figure 1: Breakdown of the top 15 Unique IP Address Locations

Figure 1: Breakdown of the top 15 Unique IP Address Locations

Trend Micro released a research paper which documented the operations of this “Safe” campaign along with their threat protection recommendations. Safe targeted its victims using spear-phishing emails containing a malicious attachment exploiting a Microsoft Office vulnerability (CVE-2012-0158) and leveraging social engineering techniques for initial intrusion. Furthermore, their research discovered in its finding that the average number of actual victims connected to the C&C server remained at 71 per day, with few if any day to day changes. The research also noted that the Safe campaign targeted specific industries and communities in specific regions as early as October 2012.

Figure 2. Sample of Safe campaign spear-phishing email

Figure 2. Sample of Safe campaign spear-phishing email

While determining the intent and identity of the attackers remains difficult, Trend Micro assessed that the Safe campaign is targeted and uses malware developed by a professional software engineer who may be connected to the cybercriminal underground in China. However, the relationship between the malware developers and the campaign operators themselves remains unclear.

Implementation of Trend Micro solutions will help prevent and detect attacks related to the Safe campaign. Trend Micro recommends a comprehensive security risk management strategy that goes further than advanced protection to meet the real-time threat management requirements of dealing with targeted attacks.

Trend Micro Incorporated is a pioneer in server security with over 20 years’ experience.

Advertisement. Scroll to continue reading.
Advertisement
Advertisement
Advertisement

Like Us On Facebook

You May Also Like

HEADLINES

Likening the Converge network to a digital fortress, CISO Andrew T.  Malijan said that its battlements were strengthened in 2024 as it blocked a...

HEADLINES

ThinkShield Firmware Assurance is one of the only computer OEM solutions to enable deep visibility and protection below the operating system (OS) by embracing Zero...

HEADLINES

Kaspersky experts have uncovered a series of scams related to the growing demand, ranging from impersonating trusted brands to creating entirely fraudulent storefronts.

HEADLINES

This achievement highlights the increasing demand for Sophos’ proactive, expert-led security solutions, which help organizations of all sizes stay protected 24/7 against increasingly sophisticated...

HEADLINES

Trend's 2025 predictions report warns of the potential for malicious "digital twins," where breached/leaked personal information (PII) is used to train an LLM to...

HEADLINES

The findings show that platform security – securing the hardware and firmware of PCs, laptops and printers – is often overlooked, weakening cybersecurity posture...

HEADLINES

In rigorous evaluations conducted by prestigious cybersecurity testing organizations, Kaspersky Plus (starting in Q4 2024, Kaspersky Premium), Kaspersky Endpoint Security for Business (KESB), and...

HEADLINES

"Given the Philippines' high exposure to cyber threats, it's important for both individuals and businesses to stay vigilant," said Adrian Hia, Managing Director for...

Advertisement