http://www.bloomberg.com/news/2014-12-19/sony-hackers-used-a-half-dozen-recycled-cyber-weapons.html



Sony Hackers Used a Half-Dozen Recycled Cyber-Weapons

By Gwen Ackerman Dec 19, 2014 4:37 PM ET

The cyber attack that turned Sony’s movie studio upside down relied heavily
on old software and schemes, according to research from an Israeli
cybersecurity company.

Most hackers reuse at least one component from malware that’s been deployed
in the past, but the *Sony intrusion*
<http://www.bloomberg.com/news/2014-12-19/sony-hackers-seen-having-snooped-for-months-planted-bomb.html>
relied on at least six known pieces of software, says CyActive, a digital
security company based in Beersheba. These components have been used in
attacks on South Korean banks and a Saudi Arabian oil company dating back
to 2012.

Inventing new kinds of cyber-weapons is expensive, which is why hackers
often recycle and take the risk of getting detected. Many corporate and
government systems contain holes and can misidentify components of old
viruses, failing to stop a new attack. Since last year, an estimated 450
financial institutions have been targeted by a breed of attack allowing
hackers to remotely access computers. For those offenses, attackers reused
four previously known software components.

Some hackers have been more shameless about borrowing from past heists.
Last holiday season, Target was the victim of the *biggest retail hack in
U.S. history*
<http://www.businessweek.com/articles/2014-03-13/target-missed-alarms-in-epic-hack-of-credit-card-data>.
Attackers relied on eight reused components for that assault, and a similar
scheme *hit Home Depot*
<http://www.bloomberg.com/news/2014-09-18/home-depot-says-data-breach-affected-56-million-payment-cards.html>
this year, CyActive says. Governments are still getting swindled by
variations of an attack that first hit the U.S. Defense Department six
years ago. It reuses a dozen components from known hacks. One of the
targets this year was the *Ukraine prime minister’s office*
<http://www.ft.com/intl/cms/s/0/2352681e-1e55-11e4-9513-00144feabdc0.html>,
where dozens of computers had been infected, according to the Financial
Times.

The effectiveness of reusing computer code from old attacks spotlights the
need for corporate defenders to change their tactics and stay a step ahead
of the bad guys, says CyActive. Sony didn't immediately respond to a
request for comment.

CyActive released research this week detailing the extent that the Sony
hackers based their attack on old viruses. Research published earlier this
month from Kaspersky Labs in Moscow linked the assault to one that targeted
the oil company Saudi Aramco in 2012. *Sony first learned*
<http://www.bloomberg.com/news/2014-12-16/sony-said-to-learn-last-year-about-large-network-security-breach.html>
about the theft of its data last year after hackers *bypassed defenses*
<http://www.bloomberg.com/news/2014-12-05/why-sony-s-plan-to-foil-playstation-type-attacks-faltered.html>
the Japanese company added in response to its last major breach in 2011,
Bloomberg News reported.

While the Sony hack didn’t expose state secrets or threaten an energy
company, it inflicted significant damage to the company’s bottom line and
its reputation. The hackers, who the U.S. says are *linked to the North
Korean government*
<http://www.bloomberg.com/news/2014-12-19/north-korean-hack-of-sony-not-acceptable-state-conduct-fbi-says.html>,
successfully pressured Sony and theater companies to *halt the planned Dec.
25 release*
<http://www.bloomberg.com/news/2014-12-17/sony-cancels-the-interview-release-as-theaters-back-out.html>
of “The Interview,” which makes fun of the country and its leader, Kim Jong
Un.




__._,_.___
 ------------------------------
Posted by: "beowulf" <[email protected]>
------------------------------


 Visit Your Group
<https://groups.yahoo.com/neo/groups/grendelreport/info;_ylc=X3oDMTJmcGhzZjY4BF9TAzk3MzU5NzE0BGdycElkAzIwMTk0ODA2BGdycHNwSWQDMTcwNTMyMzY2NwRzZWMDdnRsBHNsawN2Z2hwBHN0aW1lAzE0MTkwMzA0MDQ->


 [image: Yahoo! Groups]
<https://groups.yahoo.com/neo;_ylc=X3oDMTJlcWk5dHZsBF9TAzk3NDc2NTkwBGdycElkAzIwMTk0ODA2BGdycHNwSWQDMTcwNTMyMzY2NwRzZWMDZnRyBHNsawNnZnAEc3RpbWUDMTQxOTAzMDQwNA-->
• Privacy <https://info.yahoo.com/privacy/us/yahoo/groups/details.html> •
Unsubscribe <[email protected]?subject=Unsubscribe>
• Terms of Use <https://info.yahoo.com/legal/us/yahoo/utos/terms/>

__,_._,___

-- 
-- 
Thanks for being part of "PoliticalForum" at Google Groups.
For options & help see http://groups.google.com/group/PoliticalForum

* Visit our other community at http://www.PoliticalForum.com/  
* It's active and moderated. Register and vote in our polls. 
* Read the latest breaking news, and more.

--- 
You received this message because you are subscribed to the Google Groups 
"PoliticalForum" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
For more options, visit https://groups.google.com/d/optout.

Reply via email to