Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cyberwarfare

Attackers Using Taidoor Trojan to Target Think Tanks and US-Taiwan Interests

In 2008, the Taidoor Trojan made its first appearance on the Web. It started by attacking government agencies, but the group behind it expanded their reach by targeting a wide range of victims. Now, based on research from Symantec, it appears that the group running Taidoor is interested in think tanks, especially those that are focused on Taiwan.

In 2008, the Taidoor Trojan made its first appearance on the Web. It started by attacking government agencies, but the group behind it expanded their reach by targeting a wide range of victims. Now, based on research from Symantec, it appears that the group running Taidoor is interested in think tanks, especially those that are focused on Taiwan.

While Taidoor started out by targeting governments, between 2009 and 2010, the malware shifted gears. Government victims were counted among those in the media, financial, telecom and manufacturing sectors. The length of the attack, almost four years now, shows that the group responsible for Taidoor is persistent if nothing else.

Based on the collected data, Symantec says that since May 2011, there has been a substantial increase in Taidoor related activity. The malware’s current targets are primarily private industry and influential international think tanks with a direct involvement in US and Taiwanese affairs. Facilities in the services sector that these organizations may use have also been targeted.

“The attackers generally used document based vulnerabilities sent through email as attachments to compromise their intended targets. The most common document type exploited by Taidoor attacks is PDF followed closely by Word documents,” Symantec explained in a blog post.

“In all, at least 9 different vulnerabilities have been observed in use by these attackers in the past. We should bear in mind that the vulnerabilities used are generally ones that are already publically disclosed and patched by vendors at time of use. The attackers are simply exploiting the fact that some organizations may be slow to apply patches.”

Like other Trojan attacks, once the system is compromised, the malware waits for instructions once it calls home. However, Taidoor is a bit interesting in this regard, as the attacker(s) will routinely access the compromised host and run various commands, to check for recently accessed documents, a list of installed software, desktop and network configurations, and more. Moreover, the attacks have a normal workday, as they only check the infected hosts during set times.

Stephen Doherty, Symantec’s Security Response Manager, and Piotr Krysiuk, a Senior Software Engineer in Ireland, published a paper on Taidoor. The 20-page report is available here.

Written By

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Kim Larsen is new Chief Information Security Officer at Keepit

Professional services company Slalom has appointed Christopher Burger as its first CISO.

Allied Universal announced that Deanna Steele has joined the company as CIO for North America.

More People On The Move

Expert Insights

Related Content

Cybercrime

A recently disclosed vBulletin vulnerability, which had a zero-day status for roughly two days last week, was exploited in a hacker attack targeting the...

Cybercrime

The changing nature of what we still generally call ransomware will continue through 2023, driven by three primary conditions.

Identity & Access

Zero trust is not a replacement for identity and access management (IAM), but is the extension of IAM principles from people to everyone and...

Cyberwarfare

WASHINGTON - Cyberattacks are the most serious threat facing the United States, even more so than terrorism, according to American defense experts. Almost half...

Cybercrime

Patch Tuesday: Microsoft calls attention to a series of zero-day remote code execution attacks hitting its Office productivity suite.

Cyberwarfare

Russian espionage group Nomadic Octopus infiltrated a Tajikistani telecoms provider to spy on 18 entities, including government officials and public service infrastructures.

Malware & Threats

The NSA and FBI warn that a Chinese state-sponsored APT called BlackTech is hacking into network edge devices and using firmware implants to silently...

Cyberwarfare

Several hacker groups have joined in on the Israel-Hamas war that started over the weekend after the militant group launched a major attack.