Treść książki

Przejdź do opcji czytnikaPrzejdź do nawigacjiPrzejdź do informacjiPrzejdź do stopki
APT—theNewCyberforce?
internationalorganisations,suchastheEUandNATO),andwasobviously
ofgreatinteresttoanynationalintelligenceagency.
TheKimsukyOperationisanotherespionagecampaignclassifiedas
anAPT.Interestingly,thiscampaignusesverysimpleandbasicmalware.
Accordingtotheanalysis,6themalwaretargetedorganisationslinkedto
“ThesupportersoftheUnification,”anorganisationinSouthKoreaand
China.Thisindicatesapoliticalcontextandestablishesaframeworkfor
adiscussionontherelevanceofAPTsinmoderngeopolitics.
Latethisyear,theMiniDuke7campaignwasdetectedagain,operating
aftertwoyearsofinactivity,underthenewnameofCosmicDuke.8Thisnew
versionappearstohaveaverywiderangeofespionageinterests.Ittargets
informationfromorganisationsinvolvedwithgovernment,diplomacy,
energy,telecommunications,andmilitarysectors,operatinginstatessuchas
Georgia,Russia,theUnitedKingdom,Kazakhstan,India,Belarus,Ukraine,
Cyprus,andLithuania.Thecomplexityofthemalwareandthecountriesin
whichtheinfectionshavebeendetectedleadresearcherstoassumethatitis
astate-sponsoredcampaign.Inparticular,documentsexplicitlyreferringto
politicalissues,suchastherecentcrisisinUkraineandNATOoperations,
havebeenfoundduringtheinvestigation.Thesefindings,alongwithlittle
languagecluesleftinthecodesuggestthatCosmicDukeispartofan
internationalcyberespionagecampaigncarriedoutbyRussia.However,this
cannotbeprovedwithabsolutecertainty.
AnAPTismuchmorethanacomplexpieceofcode;itispotentially
damagingpiece.Itdoesnotmatterwhetheritisaprofessionalorelementary,
aslongasitiseffectiveandcritical.The“Advanced”attributegiventoan
APTisrepresentedbytheselectivityofitstargets,whichalsoexpressesits
imminence.TheclassificationofanAPTisfarmorecomplicatedthansimple
malwareanalysis,sinceitrequiresmuchmoresophisticatedstudy,whichdoes
notendwithsimplecodeanalysis.Tounderstandthecriticalnatureofatarget
orthepossiblemotivationsbehindanattack,humaninvolvementtogether
withtechnical,political,andmilitaryskillsarerequired.Unfortunately,the
analysisitselfisnotanexactscience,andduetothephysicaldiversitiesof
6
D.Tarakanov,“The‘Kimsuky’Operation:ANorthKoreanAPT?,”KasperskyLabExpert,
2013.
7
C.Raiuetal.,“TheMiniDukeMystery:PDF0-dayGovernmentSpyAssembler0x29A
MicroBackdoor,”KasperskyLab,February2013.
8
“COSMICDUKE:CosmuwithatwistofMiniDuke,”F-SecureLabSecurityResponse,
July2014,www.f-secure.com.
ThePolishQuarterlyofInternationalAffairs,2015,no.3
9