New York Times Hackers Back With Smarter Malware

The alleged hackers behind the much-publicised hit on the New York Times have been spotted using more sophisticated malware to ensnare more targets.

FireEye said the attackers, whom some say the Chinese government sponsored, had hit an unnamed economic policy organisation. This is the first major move from the hacking group since the attacks on the New York Times in January.

New York Times attackers return

Since May, they have been using updated versions of the Aumlib and Ixeshe malware, using more encoding of command and control communications and running over new network traffic patterns to cover their tracks.

Such subtle changes may be enough to avoid intrusion detection systems looking out for older versions of the malware

“The updates are significant for both of the longstanding malware families; before this year, Aumlib had not changed since at least May 2011, and Ixeshe had not evolved since at least December 2011,” FireEye researchers Ned Moran and Nart Villeneuve said in a blog post.

“We cannot say for sure whether the attackers were responding to the scrutiny they received in the wake of the episode.

“But we do know the change was sudden. Akin to turning a battleship, retooling TTPs [techniques, tactics, or procedures] of large threat actors is formidable. Such a move requires recoding malware, updating infrastructure, and possibly retraining workers on new processes.”

It is not rare for hacking groups to retool after public exposure. In May, it was claimed the Unit 61398 group, based out of Shanghai and allegedly sponsored by the Chinese government, had returned to attack fresh US targets. It is not believed that same group, also known as the Comment Crew, was responsible for the attack on the New York Times.

What do you know about Internet security? Find out with our quiz!

Thomas Brewster

Tom Brewster is TechWeek Europe's Security Correspondent. He has also been named BT Information Security Journalist of the Year in 2012 and 2013.

Recent Posts

Apple Sales Rise 6 Percent After Early iPhone 16 Demand

Fourth quarter results beat Wall Street expectations, as overall sales rise 6 percent, but EU…

21 hours ago

X’s Community Notes Fails To Stem US Election Misinformation – Report

Hate speech non-profit that defeated Elon Musk's lawsuit, warns X's Community Notes is failing to…

22 hours ago

Google Fined More Than World’s GDP By Russia

Good luck. Russia demands Google pay a fine worth more than the world's total GDP,…

23 hours ago

Spotify, Paramount Sign Up To Use Google Cloud ARM Chips

Google Cloud signs up Spotify, Paramount Global as early customers of its first ARM-based cloud…

2 days ago

Meta Warns Of Accelerating AI Infrastructure Costs

Facebook parent Meta warns of 'significant acceleration' in expenditures on AI infrastructure as revenue, profits…

2 days ago

AI Helps Boost Microsoft Cloud Revenues By 33 Percent

Microsoft says Azure cloud revenues up 33 percent for September quarter as capital expenditures surge…

2 days ago