Iranian nuclear program used as lure in Flash-based targeted attacks

Targeted emails contain malicious Iran-themed Word documents that exploit a known Flash Player vulnerability to install malware

A new targeted email attack is exploiting interest in the Iranian nuclear program to trick people into opening booby-trapped Word documents that exploit a known Flash Player vulnerability to install malware.

"There seems to be a new campaign underway using this new CVE-2012-0754 exploit," said independent security researcher Mila Parkour in a blog post on Monday. The exploit is triggered when Flash Player tries to read a maliciously crafted MP4 file.

The rogue emails contain an attachment called "Iran's Oil and Nuclear Situation.doc," that has malicious Flash content embedded inside. When the Word document is opened, Flash Player tries to download and play a malformed MP4 file, which triggers a memory corruption and gives the exploit arbitrary code-execution ability on the machine.

The exploit is designed to drop and install a computer Trojan detected by some antivirus products as Graftor or Yayih.A, Parkour said. "If you are tracking APT [advanced persistent threats], you are likely to recognize this trojan."

At the time of Parkour's report, the malware had a low detection rate on VirusTotal, with only seven out of the 43 antivirus engines used by the service flagging it as malicious. The detection rate has increased to 21 out of 43 since then.

Advanced persistent threats were a hot topic at the recent RSA security conference in San Francisco, with many industry experts discussing the dangers of targeted attacks that often result in the loss of intellectual property and trade secrets.

Unfortunately, these attacks still work because most organizations are slow when it comes to deploying software security updates. Adobe Systems has patched CVE-2012-0754 in Flash Player, which was released on Feb. 15, but attacks leveraging this vulnerability are still going on.

Adobe is currently working on adding sandbox support to Flash Player, a type of technology that will make it significantly harder to execute arbitrary code on systems even if a vulnerability like CVE-2012-0754 is exploited.

However, cybercriminals will probably start targeting other popular programs when that happens. A few years ago the most common exploits used in zero-day attacks were PDF-based, but now Flash Player is the primary target, said Secunia Chief Security Specialist Carsten Eiram at the RSA conference last Thursday.

The release of Adobe Reader 10, which is sandboxed by default, might have influenced this, but there are many other popular products out there. "Maybe Java will be next," Eiram said.

The tense situation surrounding Iran's nuclear program is a particularly important topic for people working in the defense industry. The fact that it was used as a lure in this attack could suggest that defense industry employees were among the potential targets.

Join the CSO newsletter!

Error: Please check your email address.

More about Adobe SystemsAdobe SystemsAPTRSASecunia

Show Comments

Featured Whitepapers

Editor's Recommendations

Solution Centres

Stories by Lucian Constantin

Latest Videos

  • 150x50

    CSO Webinar: Will your data protection strategy be enough when disaster strikes?

    Speakers: - Paul O’Connor, Engagement leader - Performance Audit Group, Victorian Auditor-General’s Office (VAGO) - Nigel Phair, Managing Director, Centre for Internet Safety - Joshua Stenhouse, Technical Evangelist, Zerto - Anthony Caruana, CSO MC & Moderator

    Play Video

  • 150x50

    CSO Webinar: The Human Factor - Your people are your biggest security weakness

    ​Speakers: David Lacey, Researcher and former CISO Royal Mail David Turner - Global Risk Management Expert Mark Guntrip - Group Manager, Email Protection, Proofpoint

    Play Video

  • 150x50

    CSO Webinar: Current ransomware defences are failing – but machine learning can drive a more proactive solution

    Speakers • Ty Miller, Director, Threat Intelligence • Mark Gregory, Leader, Network Engineering Research Group, RMIT • Jeff Lanza, Retired FBI Agent (USA) • Andy Solterbeck, VP Asia Pacific, Cylance • David Braue, CSO MC/Moderator What to expect: ​Hear from industry experts on the local and global ransomware threat landscape. Explore a new approach to dealing with ransomware using machine-learning techniques and by thinking about the problem in a fundamentally different way. Apply techniques for gathering insight into ransomware behaviour and find out what elements must go into a truly effective ransomware defence. Get a first-hand look at how ransomware actually works in practice, and how machine-learning techniques can pick up on its activities long before your employees do.

    Play Video

  • 150x50

    CSO Webinar: Get real about metadata to avoid a false sense of security

    Speakers: • Anthony Caruana – CSO MC and moderator • Ian Farquhar, Worldwide Virtual Security Team Lead, Gigamon • John Lindsay, Former CTO, iiNet • Skeeve Stevens, Futurist, Future Sumo • David Vaile - Vice chair of APF, Co-Convenor of the Cyberspace Law And Policy Community, UNSW Law Faculty This webinar covers: - A 101 on metadata - what it is and how to use it - Insight into a typical attack, what happens and what we would find when looking into the metadata - How to collect metadata, use this to detect attacks and get greater insight into how you can use this to protect your organisation - Learn how much raw data and metadata to retain and how long for - Get a reality check on how you're using your metadata and if this is enough to secure your organisation

    Play Video

  • 150x50

    CSO Webinar: How banking trojans work and how you can stop them

    CSO Webinar: How banking trojans work and how you can stop them Featuring: • John Baird, Director of Global Technology Production, Deutsche Bank • Samantha Macleod, GM Cyber Security, ME Bank • Sherrod DeGrippo, Director of Emerging Threats, Proofpoint (USA)

    Play Video

More videos

Blog Posts

Market Place