1、意大利当局逮捕EyePyramid间谍行动嫌疑人
标题:Operation EyePyramid: Two Siblings Spied on Italy's Elite
作者信息:January 11, 2017 12:40 PM By Catalin Cimpanu
//BEGIN
Italian authorities have arrested and charged two siblings for carrying out a cyber-espionage campaign against Italy's elite, with targets that varied from famous businessmen to high-ranking politicians, including Matteo Renzi, former Italian prime minister.
According to court documents (embedded below), the two used a simple scheme to infect their victims.
The two hired the services of a local programmer to develop their own brand of malware, a backdoor trojan, which authorities have named EyePyramid.
意大利当局逮捕并起诉了2名网络间谍,这2人是兄弟俩,其中一人属于神秘组织“共济会”的高级成员。这个间谍行动被官方确定为:EyePyramid。其部分原因可能是Eye和Pyramid多出现在间谍软件的源代码中。
虽然他们定位的目标人群都是职位很高的精英人士(前政府总理、红衣主教、外交官、欧洲中央银行行长、意大利央行、参议员、内政部、财政部以及成功商人等等非富即贵人士),但是其传播方式还是非常简单和传统:采用钓鱼邮件的方式。
//END
The list of victims includes names such as former prime minister Matteo Renzi, former prime minister Mario Monti, cardinal Gianfranco Ravasi, head of the European Central Bank Mario Draghi, Vatican officials, members of Italy's tax police, Bank of Italy officials, and representatives of the Italian Senate, and members of several Italian ministries (Finance, Economy, Internal Affairs, Foreign Affairs, and others).
In a TV interview, Italian investigators said Giulio Occhionero was a high-ranking member of a Masonic lodge. The words "eye" and "pyramid," used regularly in the malware's source code, are some of the most known symbols of Freemasonry.
被逮捕的嫌疑人一个45岁,一个49岁,是弟兄俩。意大利的调查官员声称这2个嫌疑人很可能与神秘组织“共济会”相关。意大利警方请求美国FBI参与了本次调查活动,最后获取到的信息是该行动从2008年就开始了。到被逮捕前,这2人已经盗取了87GB之多的重要信息:都是写金融账户信息以及登录用户名密码等等,而且这些资料信息被分成了122个类别存放:类别包括商业信息、政府信息等等。
嫌疑人被抓,与该间谍软件采用的一个商业化的邮件发送模块的License信息相关。调查人员顺着这条线索,最终找到了该恶意代码的幕后黑手。
嫌疑人相关背景信息:搜共济会
点评:从目标人群的名单看去,打击很精准:TARGETED |