Symantec Connect
  • Login
  • Register
  • Security
    • All of Connect
    • Backup and Archiving
    • Endpoint Management
    • Endpoint Virtualization
    • Storage and Clustering
    • Security
    • Inside Symantec
    • Vision User Conference
    • Partners
    • Developers
    •  
  • Overview
  • Forums
  • Articles
  • Blogs
  • Downloads
  • Events
  • Videos
  • Groups
  • Ideas
Login to participate
Security ResponseRSS

Hydraq - An Attack of Mythical Proportions

Symantec Security Response
January 15th, 2010
Tags: Endpoint Protection (AntiVirus), Emerging Threats, Security, Security Response
Facebook Twitter

Over the past couple of days, media outlets have been abuzz with news of a cyber attack on Google. A number of people have theorized political intent and the implications of these attacks.

First, a little background. The critical infrastructures of large corporations are attacked on a daily basis. Some companies are targeted more than others, but all of them are targeted by either hackers who like to put a large feather in their cap, or by hackers trying to steal information for monetary gain. As in all cases with large companies the attacks are investigated thoroughly to make certain that networks and data are not compromised. 

As with all targeted attacks, this particular attack was tailored to target a small number of corporate users. The attack vector in this instance could be one of many. A hacker only requires an unpatched computer to visit a website of the hacker's choice, or open a document crafted by the hacker. This can be done by sending a malicious document attached to an email or sending a spoofed email message with a link to a malicious website. Once this is done the hacker installs a back door on the computer that allows him to gain complete control. This grants access to all information stored or passing through the compromised computer. It is vital to note that such hackers don't try to take over all computers within a corporation. All they need is one computer in order to enter an intranet and then seek the information of their choosing. The current case is no different. A very small number of people were attacked using a combination of such vectors, resulting in back door Trojans being installed. More details of the Trojan, detected by Symantec as Trojan.Hydraq and Trojan.Hydraq!gen1, can be obtained from our Threat Expert blog.

There is evidence to show that documents attached to an email message were a method of infection. There are also reports of an unpatched vulnerability in Microsoft's Internet Explorer, which allowed even fully patched computers to become infected once they were lured into visiting a website of the hacker's choosing. We've also seen multiple variants of the Trojan, which confirm that the authors of the malware were constantly improving control of compromised computers by updating the Trojan. This can mean only one thing: the hackers didn't employ one technique across the board, but used different files along with different combinations of attack vectors in order to compromise a network.

We've seen changes happening in cyber attacks for several years now. This attack just brings to light the stark difference we see today as compared to Trojans from a decade ago. In the past, malware authors wanted everyone to know their name and so were doing things such as changing the desktop backgrounds of computers to showcase their ability to compromise a computer. Today, the cyber world is a very different place. Today’s malware authors would rather stay under the radar on one computer for as long as possible, than risk their exposure by trying to infect 100 computers.

We will continue to do whatever we can to protect our customers' assets as more information comes to light about the cyber attack on Google. We advise customers to apply patches where they can, and update their security suite solutions on a regular basis. There are a number of Symantec solutions that can help, such as Data Loss Prevention Network Prevent, which is effective at detecting or blocking the exfiltration of user data via a network protocol following a successful hack into a server; Critical System Protection, which can harden servers that contain critical data and stop unauthorized applications and services from accessing information or prevent data from being moved off the server; and Control Compliance Suite (CCS), which can be used to protect against incursions by hackers or targeted malware by ensuring that patches and configurations of externally facing devices such as firewalls are up to date. Additionally, there are service programs such as Security Program Assessment, which  evaluates the maturity of an information security program. We also urge customers to block traffic to known malicious sites where possible.

Next: Protect Yourself Against Exploit Targeting New IE Zero-Day Vulnerability

+5 (5 votes)
  • Symantec Security Response's blog
  • Email this page
  • Comments RSS Feed

About Security Response Blog

Our security research centers around the world provide unparalleled analysis of and protection from malware, security risks, vulnerabilities, and spam.

Filter by:

Filter by:

Recent Blog Posts

  • シマンテック セキュリティ レスポンス ブログ日本語版正式公開のご挨拶
    symantec japan - September 01, 2010
  • Evolution of SEO Poisoning
    Andrea Lelli - September 01, 2010
  • Tidserv后门新变种感染MBR,远程控制用户计算机
    Livian Ge - September 01, 2010
  • ソーシャルネットワークを使用した日本語スパム
    Takako Yoshida - August 30, 2010
  • Catching Flies with Honey
    Gavin O Gorman - August 30, 2010

Blog Tags

10.x 11.x 419 scam 64-bit 9.x and Earlier Adobe Flash Adobe Reader Advanced Persistent Threats AndroidOS.Tapsnake Apple Backdoor.Tidserv Backdoor.Trojan Black Hat 2010 Brazil Brightmail Gateway Clickjacking Cricket World Cup 2011 Earth Day Email Emerging Threats Endpoint Encryption Endpoint Protection (AntiVirus) Endpoint Protection Small Business Enterprise Security Manager Evolution of Security FIFA Father's Day Gary Coleman General Symantec Google ISTR XV IT Risk Management Infostealer.Bancos Infostealer.Gampass Internet Security Threat Report Java Katrina Kaif MPack MS08-067 Malicious Code Master Boot Record Michael Jackson Microsoft Patch Tuesday Misleading Applications Mobile & Wireless Mobile Security Mother's Day Online Fraud Orkut PDF Password Management Restore SCADA SEO Poisoning Security Security Security Risks Security Trends 2010 Soccer Social networking South Africa Spam Spam Survey Sykipot Symantec State of Spam & Phishing Report Trojan.Bredolab Trojan.Clampi Trojan.Dropper Trojan.FakeAV Trojan.Loginck Trojan.Mebratix Trojan.Mebroot Trojan.Mozipowp Trojan.Pidief.J Trojan.Twebot Trojan.Vundo Trojan.Zbot Trojan.Zlob Valentine's Day VirusDoctor Vulnerabilities & Exploits W32.Ackantta W32.Ackantta.B@mm W32.Changeup W32.Downadup W32.Koobface W32.Qakbot W32.Sality W32.Stuxnet W32.Virut W32.Waledac Windows World Cup 2010 World Expo 2010 Zeus conficker endpoint security facebook iPhone 4 iPhone mobile applications jailbreak language spam phishing retrovirus rogue antivirus rootkit scams social engineering social media twitter typosquatting volcano
© 2010
  • Symantec Corporation
  • Contact Us
  • Get RSS
  • Privacy Policy
  • Symantec.com