New ‘Wild Neutron’ Hacker Group Targets Bitcoin Firms

Two security firms have discovered a shadowy new hacker collective known as Wild Neutron that has targeted a number of big name firms in the tech industry.

The hackers also go by the name Jripbot and Morpho, and since 2011 it has attacked targets across the world. The hackers are said to focus on corporate espionage and are financially (not politically) motivated.

Wild Neutron

Hacker, programmer, cyber crime, keyboard, computer © scyther5, Shutterstock 2014The discovery was made by Kapersky Lab and Symantec.

The group has apparently hacked companies such as Apple, Facebook, Twitter and Microsoft, as well as bitcoin firms, law firms, investment companies, healthcare and real-estate companies, as well as individual users.

“The focus of the attacks suggests that this is not a nation-state sponsored actor,” said Kapersky Lab. “However, the use of zero-days, multi-platform malware as well as other techniques makes Kaspersky Lab researchers believe it’s a powerful entity engaged in espionage, possibly for economic reasons.”

Its infection vector is still unknown, but it is thought that the victims are compromised by a kit that leverages an unknown Flash Player exploit through compromised websites. “The exploit delivers a malware dropper package to the victim,” said the security vendor. The dropper was apparently signed with a legitimate code verification certificate (from a popular maker of consumer electronics), which allowed the malware to avoid detection by some protection solutions. That certificate is now being revoked.

After getting in the system, the dropper installs the main backdoor, and it seems that the hackers have taken a great deal of care in hiding the command and control server (C&C) address and its ability to recover from a C&C shutdown.

“Wild Neutron is a skilled and quite versatile group. Active since 2011, it has been using at least one zero-day exploit, custom malware and tools for Windows and OS X,” said Costin Raiu, director of the global research and analysis team at Kaspersky Lab.

“Even though in the past it has attacked some of the most prominent companies in the world, it has managed to keep a relatively low profile via solid operational security which has so far eluded most attribution efforts,” said Raiu. “The group’s targeting of major IT companies, spyware developers (FlexiSPY), jihadist forums (the “Ansar Al-Mujahideen English Forum”) and Bitcoin companies indicate a flexible yet unusual mindset and interests.”

Butterfly Gang

Symantec meanwhile has confirmed the group’s existence, but it calls the hacker gang “Butterfly.”

“Butterfly is technically proficient and well resourced,” said Symantec. “The group has developed a suite of custom malware tools capable of attacking both Windows and Apple computers, and appears to have used at least one zero day vulnerability in its attacks. It keeps a low profile and maintains good operational security. After successfully compromising a target organisation, it will clean up after itself before moving on to its next target.

“This group operates at a much higher level than the average cybercrime gang,” it said. “It is not interested in stealing credit card details or customer databases and is instead focused on high level corporate information. Butterfly may be selling this information to the highest bidder or may be operating as hackers for hire. Stolen information could also be used for insider trading purposes.”

Are you a security pro? Try our quiz!

Tom Jowitt

Tom Jowitt is a leading British tech freelancer and long standing contributor to Silicon UK. He is also a bit of a Lord of the Rings nut...

Recent Posts

TSMC Denies Talks With Intel Over Chipmaking Joint Venture

Denial from TSMC, after multiple reports it was in talks with Intel over a joint…

3 days ago

Apple iPhone Shipments In China Slide, As Cook Talks With Trump Official

CEO Tim Cook talks to Trump official, as IDC notes China's smartphone market growth, and…

3 days ago

AMD Warns Of $800m Charge From US Chip Restrictions On China

Another big name chip maker expects a hefty financial charge, after the US tightened rules…

3 days ago

Google Digital Ad Network Ruled Illegal Monopoly By Judge

More bad news for Google. Second time in less than a year that some part…

3 days ago

US State Dept Closes Office Flagging Russia, China Disinformation

Federal office that tackled misinformation and disinformation from hostile nations is closed down, after criticism…

3 days ago

Nvidia CEO Jensen Huang Makes Surprise Visit To China

After Nvidia admits it will take $5.5 billion charge as Trump export limits of slower…

4 days ago