Symantec reports chemical firms now the target for cyber attacks
At least 48 chemical and defense companies were victims of a coordinated cyber attack that has been traced to a man in China, according to a new report ...

At least 48 chemical and defense companies were victims of a coordinated cyber attack that has been traced to a man in China, according to a new report from security firm Symantec Corp. Computers belonging to these companies were infected with malicious software known as "PoisonIvy," which was used to steal information such as design documents, formulas and details on manufacturing processes, Symantec said on Monday.

Chemical firms being attacked now
They found evidence that the "command and control" servers used to control and mine data in this campaign were also used in attacks on human-rights groups from late April to early May, and in attacks on the motor industry in late May, Symantec said. "We are unable to determine if Covert Grove is the sole attacker or if he has a direct or only indirect role," said Symantec's white paper. "Nor are we able to definitively determine if he is hacking these targets on behalf of another party or multiple parties." The Nitro campaign is the latest in a series of highly targeted cyber attacks that security experts say are likely the work of government-backed hackers. Intel Corp's security unit McAfee in August identified "Operation Shady RAT," a five-year coordinated campaign on the networks of 72 organizations, including the United Nations, governments and corporations. In February, McAfee warned that hackers working in China broke into the computer systems of five multinational oil and natural gas companies to steal bidding plans and other critical proprietary information.
Symantec said on Monday that the Nitro attackers sent emails with tainted attachments to between 100 and 500 employees at a company, claiming to be from established business partners or to contain bogus security updates. When an unsuspecting recipient opens the attachment, it installs "PoisonIvy," a Remote Access Trojan (RAT) that can take control of a machine and that is easily available over the Internet. While the hackers' behavior differed slightly in each case, they typically identified desired intellectual property, copied it and uploaded it to a remote server, Symantec said in its report. Symantec did not identify the companies that were targeted in its white paper and researchers could not immediately be reached. Dow Chemical Co was not immediately available to comment. A spokesman for DuPont declined comment, saying: "We don't comment on cyber security issues."
Reuters

Why AI notetakers are raising serious privacy and security concerns
China's low-cost AI models are changing the global AI race. Here's why Silicon Valley is worried
China's Kimi K3 challenges US AI leaders with frontier-level performance at lower cost
How did Instagram run ads promoting child abuse in India?
Why has India halted WhatsApp’s username feature before launch?
