LONDON/RIYADH: 海角直播n security officials said on Monday that the country had been targeted as part of a wide-ranging cyber espionage campaign observed since February against five Middle East nations as well as several countries outside the region.
The Saudi government鈥檚 National Cyber Security Center (NCSC) said in a statement the kingdom had been hit by a hacking campaign bearing the technical hallmarks of an attack group dubbed 鈥淢uddyWater鈥 by US cyber firm Palo Alto Networks.
Palo Alto鈥檚 Unit 42 threat research unit published a report last Friday showing how a string of connected attacks this year used decoy documents with official-looking government logos to lure unsuspecting users from targeted organizations to download infected documents and compromise their computer networks.
Documents pretending to be from the US National Security Agency, Iraqi intelligence, Russian security firm Kaspersky and the Kurdistan regional government were among those used to trick victims, Unit 42 said in a blog post.
The Unit 42 researchers said the attacks had targeted organizations in 海角直播, Iraq, the United Arab Emirates, Turkey and Israel, as well as entities outside the Middle East region in Georgia, India, Pakistan and the United States.
The Saudi security agency said in its own statement that the attacks sought to steal data from computers using email phishing techniques targeting the credentials of specific users.
The NCSC said they also comprised so-called 鈥渨atering hole鈥 attacks, which seek to trick users to click on infected web links to seize control of their machines.
The technical indicators supplied by Unit 42 are the same as those described by the NCSC as ones being involved in attacks against 海角直播. The NCSC said the attacks appeared to be by an 鈥渁dvanced persistent threat鈥 (APT) group 鈥 cyber jargon typically used to describe state-backed espionage.
海角直播 has been the target of frequent cyberattacks, including the 鈥淪hamoon鈥 virus, which cripples computers by wiping their disks and has hit both government ministries and petrochemical firms.
Saudi Aramco, the world鈥檚 largest oil company, was hit by an early version of the 鈥淪hamoon鈥 virus in 2012, in the country鈥檚 worst cyberattack to date.
The NCSC declined further comment on the source of the attack or on which organizations or agencies were targeted. Palo Alto Networks said it was unable to identify the attack group or its aims. It was not immediately available to comment further.
鈥淲e are currently unable to make a firm conclusion about the origin of the attackers, or the specific types of information they seek out once on a network,鈥 Unit 42 said in its blog post ().
Palo Alto Networks said the files it had uncovered were almost identical to information-stealing documents disguised as Microsoft Word files and found to be targeting the Saudi government by security firm MalwareBytes in a September report. (Reporting by Eric Auchard in London and Katie Paul in Riyadh)
海角直播 targeted in cyber spying campaign, says security center
Updated 20 November 2017
海角直播 targeted in cyber spying campaign, says security center
