New Targeted Attack Group Buys BIFROSE Code, Works in Teams
released on 2015-12-14 @ 11:37:11 PM
Recently, TrendMicro uncovered a new cyber-espionage attack by a well-funded and organized group targeting companies close to governments and in key industries mostly in Asia. These targets include privatized government agencies and government contractors, as well as companies in the consumer electronics, computer, healthcare, and financial industries.
This group has been active since 2010. We dub this operation Shrouded Crossbow, after a mutex in a backdoor the group developed. Our research indicates that the group has sufficient financial resources to purchase the source code of a widely available malware tool, and the human resources to design improved versions of its own backdoors based on this.