sexta-feira, 10 de agosto de 2012

Gauss: novo vírus semelhante ao Flame e Stuxnet é descoberto(Gauss: new virus similar to Flame and Stuxnet is discovered)

Pesquisadores da fabricante de antivírus russa Kaspersky descobriram mais um ataque cibernético patrocinado por um Estado, dessa vez voltado a atacar sistemas financeiros no Líbano. A empresa suspeita que o vírus, chamado de Gauss, tenha sido patrocinado pelo mesmo grupo responsável pelo Stuxnet e pelo Flame, os mais complexos ciberataques já realizados e que tinham como alvo principal o Irã.
Segundo a Kaspersky, o Gauss é uma ferramenta de ciberespionagem criada e mantida por um Estado para tarefas de espionagem e roubo de dados confidenciais, focado principalmente em senhas, credenciais de contas bancárias online, cookies e configurações específicas dos equipamentos infectados. "A funcionalidade do Trojan bancário Gauss tem características únicas que não se encontram em nenhuma outra ciberarma descoberta anteriormente", afirmou a companhia em nota.
"Tal como o Flame e o Duqu, Gauss é um complexo conjunto de ferramentas de ciberespionagem, que opera com sigilo e em segredo. No entanto, o seu propósito é diferente, já que o Gauss dirige-se a múltiplos utilizadores em países selecionados, com a finalidade de roubar grandes quantidades de dados, com um enfoque específico em informação bancária e financeira", afirmou em nota Alexander Gostev, director de segurança da Kaspersky Lab.
O vírus foi descoberto em uma investigação iniciada pela agência das Nações Unidas para a Informação e Comunicação Tecnológica (ITU) logo depois da detecção do Flame. De acordo com a Kaspersky, a infraestrutura de comando e controle (C&C) do Gauss foi encerrada em julho, pouco depois da sua descoberta. Além disso, desde o final de maio foram registadas mais de 2,5 mil infecções no sistema de segurança em nuvem da Kaspersky Lab. O número total estimado de vítimas deve ultrapassar dezenas de milhares ¿ número inferior ao Stuxnet, mas é significativamente maior que o número de ataques do Flame e do Duqu.
Os ataques ocorreram em setembro do ano passado a julho deste ano. Neste período, o malware recolheu informação dos browsers, incluindo o histórico de sites visitados e senhas. O Gauss também tinha capacidade de infectar pen drives, utilizando a mesma vulnerabilidade usada pelo Stuxnet e pelo Flame. Um fator que diferencia os dois vírus é a localização das vítimas: enquanto a maioria dos computadores infectados estava no Irã, as vítimas do Gauss estão majoritariamente no Líbano.

Suspeita
Em junho, uma reportagem do The Washington Post afirmou que Estados Unidos e Israel desenvolveram conjuntamente o supervírus Flame para recolher informações-chave das instalações nucleares iranianas. O jornal americano cita fontes ocidentais conhecedoras da operação, que afirmam que o vírus foi projetado para monitorar secretamente redes e controlar secretamente computadores de funcionários iranianos.
Semanas antes, o jornal The New York Times afirmou que os dois países também foram os responsáveis pelo Stuxnet. O presidente americano, Barack Obama, aumentou os ciberataques contra o programa nuclear iraniano, inclusive depois que o vírus Stuxnet foi difundido acidentalmente em 2010. A operação começou no governo do presidente George W. Bush com o nome de "Olympic Games" (Jogos Olímpicos) e é o primeiro ciberataque de que se tem conhecimento lançado contra outro país pelos Estados Unidos usando códigos falsos desenvolvidos por Israel, dizia a reportagem.


Researchers from the Russian antivirus maker Kaspersky discovered over a cyber attack sponsored by a State, this time aimed to attack financial systems in Lebanon. The company suspects that the virus, called the Gauss, has been sponsored by the same group responsible for Stuxnet and the Flame, the most complex cyber attacks already made and that had as main target Iran
According to Kaspersky, the Gauss cyber espionage is a tool created and maintained by a State to tasks of espionage and theft of confidential data, focused primarily on passwords, online banking account credentials, cookies, and specific configurations of equipment infected. "The functionality of banking Trojan Gauss has unique features not found in any other ciberarma discovered earlier," the company said in a statement.
"Like Flame and Duqu, Gauss is a complex set of tools for cyber espionage, which operates in secret and confidential. However, its purpose is different, since the Gauss addressed to multiple users in selected countries, with the purpose of stealing large amounts of data with a specific focus on banking and financial information, "Alexander said in a statement Gostev, Director of Kaspersky Lab security
The virus was discovered in an investigation initiated by the UN agency for Information and Communication Technology (ITU) immediately after the detection of the Flame. According to Kaspersky, the infrastructure for command and control (C & C) of Gauss was closed in July, shortly after their discovery. Moreover, since the end of May were registered more than 2500 infections in the security system's cloud Kaspersky Lab The estimated number of victims exceed tens of thousands fewer than ¿Stuxnet, but is significantly larger than the number of attacks and Flame Duqu.
The attacks occurred in September last year to July this year. During this time the malware has collected information from browsers, including the history of sites visited and passwords. Gauss also had the ability to infect thumb drives, using the same vulnerability used by Stuxnet and the Flame. One factor that differentiates the two viruses is the location of the victims: while most of the infected computers were in Iran, the victims of Gauss are mostly in Lebanon.

Suspicion
In June, a report in The Washington Post said that the United States and Israel have jointly developed the Flame supervirus to gather information from key Iranian nuclear facilities. The American Journal quotes Western sources knowledgeable of the operation, claiming that the virus was designed to secretly monitor and control network computers secretly Iranian officials.
Weeks before, the New York Times said the two countries also were responsible for Stuxnet. U.S. President Barack Obama, increased cyber attacks against the Iranian nuclear program, even after the virus was spread Stuxnet accidentally in 2010. The operation began under President George W. Bush under the name "Olympic Games" (Olympic Games) and is the first cyber attack that is known launched against another country by the United States using false codes developed by Israel, the report said.

Sem comentários:

Enviar um comentário