Targeted malware attacks against pro-Tibet groups - F-Secure Weblog : News from the Lab

チベット情報を悪用した標的型攻撃が出ているそうです。

There's unrest on the streets of Tibet - clashes between Tibetians and the Chinese military.
Copyright Getty Images / CNN.COM Quoting Wikipedia, "Tibet was once an independent kingdom, which later became a part of China. The government of the People's Republic of China and the Government of Tibet in Exile, however, disagree over when Tibet became a part of China, and whether this incorporation into China is legitimate according to international law."

UNPOからメールが来ているようなものらしいです。

Here's an email that was mailed to a pro-Tibet mailing list three days ago.

It looked like it was coming from the Unrepresented Nations and Peoples Organization (UNPO). However, the email headers were forged and the mail was coming from somewhere else altogether.

Just the filenames of some of the recent malicious attachments tell a lot:

  • UNPO Statement of Solidarity.pdf
  • Daul-Tibet intergroup meeting.doc
  • tibet_protests_map_no_icons__mar_20.ppt
  • reports_of_violence_in_tibet.ppt
  • genocide.xls
  • memberlist.xls
  • Tibet_Research.exe
  • tibet-landscape.ppt
  • Updates Route of Tibetan Olympics Torch Relay.doc
  • THE GOVERNMENT OF TIBET.ppt
  • Talk points.chm
  • China's new move on Tibetans.doc
  • Support Team Tibet.doc
  • Photos of Tibet.chm
  • News ReleaseMassArrest.pdf
  • Whole Schedule and Routing for Torch Relay.xls

As you can see there's a variety of "trusted" filetypes used in these targeted attacks, including DOC, XLS, PPT, PDF, CHM.

screenshot