MyCERT: MH370-themed backdoor and fake-transcript spear-phish
MA-381 · 24 March 2014 · MA-386 · 18 April 2014
Confirmed public advisories, a different campaign from the 9 March official-network intrusion. 24 March: a Facebook-app lure dropping a backdoor with remote-control (C2) capability. 18 April: emails posing as an investigation team / ICAO portal item, password-protected archive, fake MH370 transcript, command-and-control. Aimed at organisations and the public, not shown to be the DCA/NSC/MAS breach.
MyCERT MA-381.032014 (24 March 2014): malware using the missing flight as social engineering, classified as a backdoor (BKDR_OTOPROXY / related names), able to take control of the infected PC. MA-386.042014 (18 April 2014): spear-phish with subject-line ICAO/investigation flavour, attachment launching a fake missing-flight transcript and dropping a Trojan with C2 that then mailed itself onward from the victim’s address book. These are the ‘Attack two’ panels on the working chart. They show that MH370 was being used as bait while the official search was running. They do not, without more, merge into the 9 March theft from investigation machines. FireEye’s mid-March write-up of MH370-lure spear-phish against an Asia-Pacific government and a US think tank (group labelled Admin@338) is the same season, still not a named overlap with the CSM case.
Sources
Related
Two waves of MH370-themed cyberattacks
9 March official-network intrusion · March–April public malware lures
Investigation networks spear-phished the day after MH370 vanished
CyberSecurity Malaysia · ~30 PCs · disclosed 20 August 2014
CyberSecurity Malaysia
National cyber agency · publicly described the 9 March intrusion in August 2014