7.11.19

ESET stichtend lid van Google’s App Defense Alliance; Google Play Store’s mobiele toepassingen proactief beschermd door ESET



ESET, een wereldleider in cybersecurity, kondigt vandaag aan dat het een stichtend lid is geworden van de App Defense Alliance om de Google Play Store te beschermen. ESET zal zijn bekroonde detectiekennis en verbeterde beveiliging voor het Android ecosysteem en zijn onderzoek toespitsen op Google Play Store om het veiliger te maken. Als stichtend lid gaat ESET op 6 november aan de slag.

Deze buitengewone alliantie is een aanvulling op de bestaande partnerships van ESET met Google, met inbegrip van Chronicle, een afdeling  van Google Cloud, en de ingebouwde ESET-motor in Google Chrome Cleanup, een beveiligingstool die gebruikers van Google Chrome verwittigt bij mogelijke bedreigingen.

“Wat voorheen een reactieve inspanning was om beveiligingskwetsbaarheden te ontdekken is nu een volwaardige en proactieve campagne om miljarden consumenten en bedrijven bij de bron te beschermen,” aldus Tony Anscombe, global security evangelist en industrie ambassadeur bij ESET. “ ESET is steeds op de voorgrond inzake bedreigingsonderzoek. Samen met Google zullen ESET en de ander leden van de App Defense Alliance in staat zijn om Google informatie te bezorgen waarmee bedreigingen geĆ«limineerd worden zodat de Android gebruikers steeds een stap voor zijn op de cybercriminelen.”

ESET werd uitgekozen door Google op basis van zijn expertise voor het ontdekken van kwaadaardige apps in de Google Play Store wat door de jaren heen goed gedocumenteerd werd. Met de ontdekking van unieke banking trojans, spyware en ransomware, hielp ESET bij het identificeren van enkele van de meest geavanceerde bedreigingen voor mobiele Android-toestellen. Met deze reusachtige samenwerking zullen de researchteams van ESET druk bezig zijn met het analyseren van alle toepassingen en de proactieve bescherming van gebruikers van de Google Play Store. In het kader van deze samenwerking, zal ESET met Google zijn standpunt delen in verband met apps die het detecteert als schadelijk, potentieel schadelijk of ongewenst vooraleer de app op Google Play Store geplaatst wordt.

Ongeveer 40 % van de medewerkers van ESET zijn actief in onderzoek en ontwikkeling,  zodat ESET gebruikers en de rest van wereld beveiligd zijn  tegen de nieuwste cyberbedreigingen. Met meer dan 30 jaar ervaring in cybersecurity, heeft ESET een meerlaagse benadering tot  cyberbeveiliging, zodat het meer dan 110 miljoen gebruikers in 200 landen wereldwijd beschermt. ESET publiceert regelmatig bedreigingsonderzoek op WeLiveSecurity.

“ Sinds jaren werkt Google intensief samen met leden van de cybersecuritygemeenschap om online zowel bedrijfsgebruikers als consumenten te beschermen en de aankondiging van vandaag is het  nieuwste voorbeeld van deze samenwerking,” zegt Dave Kleidenmacher, hoofd van Android security & privacy bij Google. “ Samenwerken met een gerespecteerd lid uit de cybersecurity sector zoals ESET zal de bescherming van het Google Play ecosysteem verbeteren. We kijken uit naar wat onze teams samen zullen verwezenlijken.”

Meer informatie over de manier waarop ESET  helpt om Google Play Store te beschermen, is te vinden op de site van Google App Defense Alliance hier.

Voor het gratis e-book over gegevensbescherming, bezoek  https://www.eset.com/be-nl/zakelijk/data-protection-ebook/

3.11.19

Deepfakes: When seeing isn’t believing



 Is the world as we know it ready for the real impact of deepfakes?

Deepfakes are rapidly becoming easier and quicker to create and they’re opening a door into a new form of cybercrime. Although the fake videos are still mostly seen as relatively harmful or even humorous, this craze could take a more sinister turn in the future and be at the heart of political scandals, cybercrime, or even unimaginable scenarios involving fake videos – and not just targeting public figures.

deepfake is the technique of human-image synthesis based on artificial intelligence to create fake content either from scratch or using existing video designed to replicate the look and sound of a real human. Such videos can look incredibly real and currently many of these videos involve celebrities or public figures saying something outrageous or untrue.

New research shows a huge increase in the creation of deepfake videos, with the number online almost doubling in the last nine months alone. Deepfakes are increasing in quality at a swift rate, too. This video showing Bill Hader morphing effortlessly between Tom Cruise and Seth Rogan is just one example of how authentic these videos are looking, as well as sounding. Searching YouTube for the term ‘deepfake’ it will make you realize we are viewing the tip of the iceberg of what is to come.

In fact, we have already seen deepfake technology used for fraud, where a deepfaked voice was reportedly used to scam a CEO out of a large sum of cash. It is believed the CEO of an unnamed UK firm thought he was on the phone to the CEO of the German parent company and followed the orders to immediately transfer €220,000 (roughly US$244,000) to a Hungarian supplier’s bank account. If it was this easy to influence someone by just asking them to do it over the phone, then surely we will need better security in place to mitigate this threat.

Fooling the naked eye
We have also seen apps making deepnudes turning photos of any clothed person into a topless photo in seconds. Although, luckily, one particular app, DeepNude, has now been taken offline, what if this comes back in another form with a vengeance and is able to create convincingly authentic-looking video?

There is also evidence that the production of these videos is becoming a lucrative business especially in the pornography industry. The BBC says “96% of these videos are of female celebrities having their likenesses swapped into sexually explicit videos – without their knowledge or consent”.

recent Californian bill has taken a leap of faith and made it illegal to create a pornographic deepfake of someone without their consent with a penalty of up to $150,000. But chances are that no legislation will be enough to deter some people from fabricating the videos.

To be sure, an article from the Economist discusses that in order to make a convincing enough deepfake you would need a serious amount of video footage and/or voice recordings in order to make even a short deepfake clip. I desperately wanted to create a deepfake of myself but sadly, without many hours of footage of myself, I wasn’t able to make a deepfake of my face.
Having said that, in the not-too-distant future, it may be entirely possible to take just a few short Instagram stories to create a deepfake that is believed by the majority of one’s followers online or by anyone else who knows them. We may see some unimaginable videos appearing of people closer to home – the boss, our colleagues, our peers, our family. Additionally, deepfakes may also be used for bullying in schools, the office or even further afield.

Furthermore, cybercriminals will definitely use this technology more to spearphish victims. Deepfakes keep getting cheaper to create and become near-impossible to detect with the human eye alone. As a result, all that fakery could very easily muddy the water between fact and fiction, which in turn could lead us to not trust anything – even when presented with what our senses are telling us to believe.
Heading off the very real threat
So, what can be done to prepare us for this threat? First, we need to better educate people that deepfakes exist, how they work and the potential damage they can cause. We will all need to learn to treat even the most realistic videos we see that they could be total fabrications.

Secondly, technology desperately needs to develop better detection of deepfakes. There is already research going into it, but it’s nowhere near where it should be yet. Although machine learning is at the heart of creating them in the first place, there needs to be something in place that acts as the antidote being able to detect them without relying on human eyes alone.

Finally, social media platforms need to realize there is a huge potential threat with the impact of deepfakes because when you mix a shocking video with social media, the outcome tends to spread very rapidly and potentially could have a detrimental impact on society.

Don’t get me wrong; I hugely enjoy the development in technology and watching it unfold in front of my eyes, however, we must remain aware of how technology can sometimes detrimentally affect us, especially when machine learning is maturing at a rate quicker than ever before. Otherwise, we will soon see deepfakes become deepnorms with far-reaching effects.


Safe downloading habits: What to teach your kids



Even if you are careful about what you download, chances are your children will be less cautious. Here is how you can help them – and your entire family – stay safe.

Life without the internet is rather difficult to fathom, and particularly for children the online world holds a magical allure. While many parents are becoming increasingly aware of the potentially negative effects of too much screen time, the undeniable truth is that there’s a host of opportunities to explore on the internet.

However, it’s also important to consider that not all that’s free on the internet is necessarily safe. Aside from potential copyright issues, the free movie, game or music album that your child downloads may be bundled with malware, adware or another software nasty. This could occur, for example, when kids visit a dodgy website and are bombarded with giant download buttons and flashing ads, finding it hard to not make the click.

Many grown-ups are wising up to the risks of clicking and downloading anything from shady sites or shared by strangers, but children may be less cautious. The consequences can come in the form of frustrating ads and popups, but can also be much more sinister and involve having personal details stolen or losing access to your important data.

And aside from downloading ‘stuff’ from dodgy websites, kids can be tempted to buy from legitimate sites and rack up nasty credit card bills for their parents. Indeed, one mother recently announced she was ‘cancelling Christmas’ after her son racked up a hefty bill buying Xbox add-ons.
So, what can parents do to protect their children, their personal data, and their bank balances?

·         Everything should start with an open dialogue on the dangers lurking on the internet. Put simply, children should be taught to approach everything on the internet with critical thinking. This includes risks that have to do with downloading materials for entertainment or homework from suspicious websites, including those hosting pirated content. Kids should be equally wary of links and attachments sent via email or social platforms and promising, for example, a free game feature.
·         Also, when children want to download new software, they should know that they need to visit the websites of the original software developer, or the official store, where the chances of accidentally downloading any unwanted ‘extras’ are much, much lower.
·         Parents should also ensure that kids use a reliable internet security solution that includes multiple layers of protection and downloads the latest updates automatically, as crooks constantly come up with new threats. Indeed, make sure to keep the operating systems and applications on all of your family’s devices updated with the latest security patches.
·         At the end of the day, it’s important to have an understanding of what kids are up to online. Using a parental control solution helps to keep an eye on children’s activities, including the sites they’re visiting and what they’re downloading. In addition, such a tool can also allow parents to block potentially risky and age-inappropriate websites, as well as prevent children from making accidental online purchases from legitimate websites.

Just like we encourage kids to stop at a road crossing to gauge their circumstances and the cars passing by, we need to teach our children to stop and think before clicking on download buttons. With careful guidance and ensuring that the message of ‘stop and think’ is consistently reiterated, children will soon learn that – while it is exciting to play on the internet – it comes with risks just like many things in life. No child wants an extra game feature at the expense of Christmas being cancelled, so chances are good they’ll take the message on board.

To learn more about more dangers faced by children online as well as about how not only technology can help, head over to https://saferkidsonline.eset.com.

To read how you can instill safe selfie habits in your kids, please refer to our recent Selfies for kids – A guide for parents article.


29.10.19

ConƧu pour les gamers: le tout nouveau logiciel de sĆ©curitĆ© ESET est optimalisĆ© pour un maximum de performances et un minimum d’interfĆ©rences



ESET, un des leaders mondiaux en cybersĆ©curitĆ©, vient de lancer la toute nouvelle version de ses produits Windows pour consommateurs. Celle-ci offre une protection avancĆ©e sans compromettre les performances, la vitesse ni la convivialitĆ©. ESET NOD32 Antivirus, ESET Internet Security et ESET Smart Security Premium sont conƧus pour fournir ce qu’il y a de mieux en matiĆØre de protection tout en permettant aux utilisateurs de profiter de la puissance complĆØte de leur ordinateur.

Tout comme les tĆ©lĆ©phones mobiles, les ordinateurs et laptops sont maintenant conƧus avec des capacitĆ©s hautes performances pour la vidĆ©o, la photo et l’affichage jeu. Il est donc vital que le logiciel de cybersĆ©curitĆ© ne limite pas les capacitĆ©s des appareils des utilisateurs lorsqu’il assure une protection optimale. On estime que sur les 2,2 milliards de gamers, 1,2 milliard jouent sur un PC (1.2 billion of those are playing games on a PC). ESET est donc fiĆØre de fournir une solution qui rĆ©pond  aux besoins de tous les consommateurs, que ce soit aux les entreprises ou pour les loisirs.
Les logiciels ESET permettent de jouer, de travailler et de naviguer sur internet sans ralentissements. Une caractĆ©ristique clef du logiciel est l’empreinte systĆØme trĆØs faible qui offre aux utilisateurs de hautes performances systĆØme tout en prolongeant la vie de leur matĆ©riel. De plus, le logiciel propose un mode gamer, grĆ¢ce auquel il passe automatiquement en mode silencieux si un autre programme est exĆ©cutĆ© en plein Ć©cran. Les mises Ć  jour systĆØme et les notifications sont postposĆ©es pour Ć©conomiser les ressources pour le jeu, la vidĆ©o, les photos ou les prĆ©sentations.
Les solutions d’ESET pour consommateurs ont Ć©galement dĆ©montrĆ© des rĆ©sultats au niveau du faible impact systĆØme et des hautes performances.  Depuis mai 2017, AV-Comparatives a rĆ©compensĆ© ESET Internet Security avec cinq prix Advanced + consĆ©cutifs pour la haute performance de son produit.
Matej KriÅ”tofĆ­k, responsable produits consommateurs chez ESET, dĆ©clare: “Dans sa derniĆØre version, ESET est fier d’offrir des solutions de pointes aux consommateurs. C’est notre passion de fournir ce qu’il y a de mieux en sĆ©curitĆ© TIC tout en veillant Ć  ce que les utilisateurs puissent profiter pleinement de leurs appareils tout en sachant qu’ils sont entiĆØrement protĆ©gĆ©s et dans de bonnes mains. Le gaming est extrĆŖmement populaire et ne cesse de prendre de l’importance. Il est donc capital que les fournisseurs de cybersĆ©curitĆ© en tiennent compte lorsqu’ils rĆ©pondent aux exigences  des consommateurs.”
 La toute nouvelle Ć©dition du produit ESET pour consommateur inclut une foule de nouvelles fonctionnalitĆ©s qui amĆ©liorent leur protection ainsi que leurs performances.
Pour plus d’information sur l’offre de sĆ©curitĆ© d’ESET et l’e-book gratuit, rendez-vous sur https://www.eset.com/be-fr/professionnels/data-protection-ebook/


24.10.19

InterSystems lance QuickML




InterSystems, un des leaders mondiaux en logiciel pour les secteurs de la santĆ©, des entreprises et services publiques, vient de lancer QuickML. Il est disponible pour les utilisateurs des plates-formes InterSystems IRIS Data Platform et InterSystems IRIS for Health Data Platform. L’annonce a Ć©tĆ© faite lors du Global Summit 2019, la confĆ©rence organisĆ©e chaque annĆ©e par l’entreprise. En mettant l’apprentissage machine dans les mains des dĆ©veloppeurs orientĆ©s SQL, QuickML permet aux organisations d’introduire des prĆ©visions dans leurs applications existantes.
Les Ć©quipes de dĆ©veloppeurs sont de plus en plus souvent confrontĆ©es aux demandes d’inclusion des capacitĆ©s ML dans des solutions avec une grande quantitĆ© de donnĆ©es. Cependant, trĆØs peu d’entre eux disposent de moyens internes ou de l’expertise nĆ©cessaire pour utiliser effecacement une telle fonctionnalitĆ©. Avec QuickML, InterSystems veut rĆ©soudre ce problĆØme par le biais d’une fonction ML automatisĆ©e qui est disponible dans une syntaxe all-SQL bien connue. QuickML doit simplifier le processus de dĆ©veloppement, de testes et d’implĆ©mentation de modĆØles ML et accĆ©lĆ©rer le processus d’intĆ©gration dans les applications de production.
Selon Scott Gnau, vice-prĆ©sident Data Platforms d’InterSystems, avec QuickM tous les dĆ©veloppeurs utilisant IRIS peuvent introduire dans leurs applications les capacitĆ©s d’apprentissage machine en format simple et Ć©volutif. «Nous voyons ainsi que QuickML, permet Ć  nos partenaires d’applications de faire des prĆ©visions prĆ©cises. IRIS-Dataplatform supporte certaines applications parmi les plus importantes au monde et QuickML vient complĆ©ter la fonctionnalitĆ© de ‘science des donnĆ©es’. CombinĆ© Ć  notre Spark Connector et au moteur d’exĆ©cution Predictive Model Markup Language, les scientifiques et les dĆ©veloppeurs disposent donc d’une sĆ©rie d’outils qui sont faciles Ć  utiliser pour la mise en œuvre d’applications de centre de donnĆ©es puissantes et Ć  grande Ć©chelle. »
QuickML sera disponible en tant que fonction native dans une prochaine version d’IRIS d’InterSystems.
Vous trouverez plus de dƩtails dans le texte ci-dessous et sur www.intersystemsbenelux.com

Les villes intelligentes doivent ĆŖtre cyber-intelligentes



Alors que les villes se tournent vers l’IoT pour rĆ©soudre des problĆØmes existants, quels sont les risques si la cybersĆ©curitĆ© est laissĆ©e Ć  la phase de planification ?

Le terme “Smart cities”, les villes intelligentes, c’est l’idĆ©e qu’une utilisation intensive des technologies de l’information et de la communication (TIC) pour surveiller l’Ć©nergie, les services publics et l’infrastructure de transport peut rĆ©duire les coĆ»ts, l’impact sur l’environnement et rĆ©soudre plus rapidement des pannes.

Les avantages sont Ć©vidents. Si une ampoule d’Ć©clairage public tombe en panne et peut le faire savoir, on peut la remplacer plus rapidement. Si on peut contrĆ“ler le trafic plus efficacement, on rĆ©duit la pollution et le bruit ainsi que la durĆ©e des trajets. Si on peut rĆ©gler le chauffage de maniĆØre trĆØs prĆ©cise, on peut rĆ©duire la consommation d’Ć©nergie et le gaspillage. Si on peut suivre le trafic en temps rĆ©el, on peut planifier les meilleures routes pour les vĆ©hicules de secours.

La plupart des gouvernements nationaux ont signĆ© l’Accord de Paris et se sont engagĆ©s Ć  atteindre des objectifs de rĆ©duction d’Ć©missions de carbone.  Ces objectifs ont ensuite Ć©tĆ© transmis aux niveaux rĆ©gionaux et municipaux. La mise en œuvre des technologies intelligentes en milieu urbain joue un rĆ“le important dans la rĆ©alisation de ces objectifs. Mais lĆ  où il y a des rĆ©seaux complexes de milliers de capteurs et d'appareils IoT interconnectĆ©s et contrĆ“lĆ©s par ordinateur, toutes sortes de sonnettes d'alarme ont retenti dans l'esprit des praticiens de la cybersĆ©curitĆ©.

Des chercheurs d’ESET ont analysĆ© des malwares qui ont probablement Ć©tĆ© utilisĆ© dans plusieurs attaques contre l’industrie de l'Ć©nergie et qui a finalement causĆ© des pannes de courant. Ce genre de perturbations a des effets majeurs sur la vie des gens car l’Ć©nergie fournie de maniĆØre intermittente et peu fiable finit rapidement par causer des problĆØmes. Les aliments et les mĆ©dicaments se dĆ©composent rapidement lorsque la rĆ©frigĆ©ration et les congĆ©lateurs ne fonctionnent plus. Les hĆ“pitaux doivent limiter leur consommation d’Ć©nergie a l’essentiel. Ni les pompes Ć  carburant, ni les stations de charge ne peuvent fonctionner, les feux de circulation sont hors service, les bĆ¢timents sont en surchauffe ou trop rafraichis. L’Ć©clairage urbain ne fonctionne pas. Les systĆØmes de paiements Ć©lectroniques ne fonctionnent pas non plus, les salaires ne sont probablement pas payĆ©s, les distributeurs automatiques ne donnent plus de billets. On ne peut recharger ni son tĆ©lĆ©phone ni son laptop. La pompe Ć  insuline ne fonctionne pas et le dispositif de respiration artificiel non plus. Il en va de mĆŖme pour les systĆØmes de surveillance Ć  distance, les camĆ©ras de sĆ©curitĆ© et la machine Ć  cafĆ©. Dans de telles circonstances le chaos s’en suit rapidement.

On peut aussi imaginer des attaques plus subtiles que des pannes totales d’Ć©lectricitĆ©. Il y a eu deux cas majeurs d’utilisation de malware pour extraction illicite de crypto-monnaie sur des systĆØmes de contrĆ“le compromis dans des centrales nuclĆ©aires. L’extraction de crypto-monnaie demande Ć©normĆ©ment d’Ć©nergie et a un lourd impact sur l’environnement en plus des coĆ»ts et de la possibilitĆ© de causer des problĆØmes de distribution d'Ć©nergie comme dĆ©crits ci-dessus. Il n’y a donc pas que les entreprises qui sont affectĆ©es par ces attaques. Dans la plupart des cas, les appareils IoT ne sont pas bien sĆ©curisĆ©s et leurs vulnĆ©rabilitĆ©s peuvent rĆ©sulter en attaques où les utilisateurs ont peu de possibilitĆ©s de prendre des mesures pour les limiter.

L’an dernier, une opĆ©ration Ć  grande Ć©chelle a Ć©tĆ© dĆ©couverte. Elle utilisait des routeurs internet domestiques pour exploiter de la crypto-monnaie. LĆ  où il y a de l’argent facile – en raison de la vulnĆ©rabilitĆ© des systĆØmes – il y aura de l’exploitation criminelle.

Les compteurs intelligents sont une aubaine tant pour les services publics que pour les consommateurs et les entreprises car ils permettent de contrĆ“ler la consommation. Toutefois, leur compromission peut entrainer le vol d’Ć©nergie, de gaz ou d’eau. Mais de tels compteurs peuvent aussi indiquer combien de courant est introduit dans le rĆ©seau (panneaux solaires), le reste du rĆ©seau dĆ©pendant alors de cette prĆ©cision pour Ć©quilibrer la charge et la production. Et comme c’est souvent le cas lors de dĆ©faillances au niveau sĆ©curitĆ©, ce sont les Ć©vĆ©nements imprĆ©vus qui peuvent avoir les consĆ©quences les plus dĆ©vastatrices.             

Parmi d’autres projets centrĆ©s IoT, l’Union EuropĆ©enne a Ć©tĆ© trĆØs active dans l’implĆ©mentation des technologies de villes intelligentes, mis en place sous l'Ć©gide de son programme de recherche et d'innovation appelĆ© Horizon 2020. La portĆ©e de ces projets varie, mais beaucoup ont de vastes implications dans les secteurs concernĆ©s – villes et sociĆ©tĆ© intelligentes, agriculture, soins de santĆ©, gestion de l’eau et des ocĆ©ans, alimentation, production et de nombreux autres aspects de la vie.

Parmi ces projets, certains sont rĆ©gis par des missions de conseils qui guident et conseillent sur l’implĆ©mentation des divers projets. (Pour information : un chercheur d’ESET Ć©tait parmi les 550 postulants pour la mission concernant la neutralitĆ© climatique et les villes intelligentes mais n’a pas obtenu de siĆØge – il y en avait 15.) Ces missions de conseil se composent de membres actifs dans diverses disciplines et il faut espĆ©rer que la cybersĆ©curitĆ© sera au centre de leurs prĆ©occupations mĆŖme si elle n’est que mentionnĆ©e sporadiquement lors des sĆ©ances d’information pour les conseillers.
Quand tout sera dit et fait, il y aura des avantages Ć©normes liĆ©s Ć  la mise en œuvre de technologies qui peuvent amĆ©liorer des vies et rĆ©duire l’impact sur l’environnement. D’autre part, il ne faut jamais sous-estimer les risques si la sĆ©curitĆ© de ces technologies n’est pas prise en charge. 

Pour plus d’information sur l’offre de sĆ©curitĆ© d’ESET et l’e-book gratuit, rendez-vous sur https://www.eset.com/be-fr/professionnels/data-protection-ebook/


14.10.19


Connecting the dots: Exposing the arsenal and methods of the Winnti Group

New ESET white paper released describing updates to the malware arsenal and campaigns of this group known for its supply-chain attacks

Today, ESET Research releases a white paper updating our understanding of the Winnti Group. Last March, ESET researchers warned about a new supply-chain attack targeting video game developers in Asia. Following that publication, we continued those investigations in two directions. We were interested in finding any subsequent malware stages delivered by that attack, and we also tried to find how the targeted developers and publishers were compromised to deliver the Winnti Group’s malware in their applications.

While we continued that investigation of the Winnti Group, additional reports on their activities were published. Kaspersky released details about the ShadowHammer malware that was found in the Asus Live Update utility.
That report also mentioned some of the techniques we describe in detail in this new white paper, such as the existence of a VMProtect packer and a brief description of the PortReuse backdoor. FireEye also published a paper about a group it calls APT41. Our research confirms some of their findings regarding the subsequent stages in some of the supply-chain attacks, such as the use of compromised hosts for mining cryptocurrencies.

Our white paper provides a technical analysis of the recent malware used by the Winnti Group. This analysis further refines our understanding of their techniques and allows us to infer relationships between the different supply-chain incidents.

We hope the white paper and indicators of compromise we release today will help targeted organizations find if they are victims or prevent future compromise.
There are lots of reports about this group’s — or perhaps these groups’ — activities. It seems each report gives new names to the group and the malware. Sometimes, this has been because the link with existing research wasn’t strong enough to classify the malware and activities of interest under a previous name, or, because vendors or research groups have their own classifications and naming and used them in their public reporting. For someone who doesn’t actually analyze the malware samples, it can be difficult to confirm aliases and easy to add more confusion.

We have chosen to keep the name “Winnti Group” since it’s the name first used to identify it, in 2013, by Kaspersky. We do understand Winnti is also a malware family: that is why we always write Winnti Group when we refer to the malefactors behind the attacks. Since 2013, it was demonstrated that Winnti is only one of the many malware families used by the Winnti Group.

To be clear, we do not exclude the idea that there might be multiple groups using the Winnti malware. For the scope of our research we refer to them as potential subgroups of the Winnti Group because there is no evidence they are completely isolated. Our definition of the Winnti Group is broad enough to include all these subgroups because it is based mainly on the malware and techniques they use.
Our white paper has a section describing the names we use and their aliases.

Read the complete article on