Trojan Hidden in Fake Revolutionary Documents Targets Syrian Activists
The campaign to use social engineering to install surveillance software that spies on Syrian activists is growing ever more complex as violence in Syria has escalated. Since the beginning of the year, Syrian opposition activists have been targeted using several Trojans, including one disguised as a Skype encryption tool, which covertly install spying software onto the infected computer, as well as a multitude of phishing attacks which steal YouTube and Facebook login credentials.
The latest campaign contacts targeted Syrian activists over Skype and delivers a Trojan by getting the targets to download a fake PDF purporting to contain a plan to assist the city of Aleppo, where opposition protest has been growing steadily since a raid on Aleppo University dormitories resulted in the deaths of four students and a temporary shutdown of the state-run school earlier this month. Like many of the attacks we have reported on, this one installs a Trojan called DarkComet RAT, a remote administration tool that allows an attacker to capture webcam activity, disable the notification setting for certain antivirus programs, record key strokes, steal passwords, and more--and sends that sensitive information to the same Syrian IP address used in attacks described by TrendMicro, Symantec, Cyber Arabs, and in several of EFF's blog posts.
The attack is initiated over Skype with the following message in Arabic:
[29/05/2012 18:03:44] Aleppo Team || ...: اخر تعديل لخطة حلب حان وقت الجهاد
[29/05/2012 18:03:46] Aleppo Team || ...: أرسل الملف "خطة النهاية2.rar"
Roughly translated into English as:
[29/05/2012 18:03:44] Aleppo Team | | ...: Last modified plan Aleppo time for Jihad
[29/05/2012 18:03:46] Aleppo Team | | ...: Send the file "plan eventually 2.rar"
Extraction of the rar file creates a directory called:خطة حلب or "Plan Aleppo," shown in the screenshot below.

Inside this is a file called: aleppo_plan_ خطة_تحريك_حلب cercs.pdf. The right-to-left text display makes this appear to be a PDF file, but is it an SCR, shown in the screenshot below.

The SCR file is malware.
The file that we have analyzed is aleppo_plan_ خطة_تحريك_حلب cercs.pdf, md5Sum bc403bef3c2372cb4c76428d42e8d188.
It displays a PDF while dropping the following files, shown in the screenshot below:
C:\Documents and Settings\Administrator\StartMenu\Programs\Startup\(empty).lnk
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\explorer.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Aleppo plan.pdf
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Firefox.dll

It runs explorer.exe, which installs DarkComet RAT and also opens a PDF which describes a plan to assist Aleppo in the revolution. The document includes a detailed discussion of logistics and would potentially be very interesting to Syrian dissidents and activists. Some of the content may be genuine, but there are also some aspects of the PDF that might raise the suspicions of a keen-eyed reader, including the flag across the top of the document, which is the flag of the Assad regime rather than the flag of the revolution.

As of May 29th, this version of DarkComet is not detectable by any anti-virus software. For a detailed discussion of how to find and remove DarkComet from your computer, see this blog post.
Syrian Internet users should be especially careful about downloading documents sent over Skype, even if the message purportedly comes from a friend.
Recent DeepLinks Posts
-
Jan 23, 2017
-
Jan 23, 2017
-
Jan 23, 2017
-
Jan 19, 2017
-
Jan 19, 2017
Deeplinks Topics
- Fair Use and Intellectual Property: Defending the Balance
- Free Speech
- Innovation
- UK Investigatory Powers Bill
- International
- Know Your Rights
- Privacy
- Trade Agreements and Digital Rights
- Security
- State-Sponsored Malware
- Abortion Reporting
- Analog Hole
- Anonymity
- Anti-Counterfeiting Trade Agreement
- Artificial Intelligence & Machine Learning
- Biometrics
- Bloggers' Rights
- Border Searches
- Broadcast Flag
- Broadcasting Treaty
- CALEA
- Cell Tracking
- Coders' Rights Project
- Computer Fraud And Abuse Act Reform
- Content Blocking
- Copyright Trolls
- Council of Europe
- Cyber Security Legislation
- CyberSLAPP
- Defend Your Right to Repair!
- Development Agenda
- Digital Books
- Digital Radio
- Digital Video
- DMCA
- DMCA Rulemaking
- Do Not Track
- DRM
- E-Voting Rights
- EFF Europe
- Electronic Frontier Alliance
- Encrypting the Web
- Export Controls
- FAQs for Lodsys Targets
- File Sharing
- Fixing Copyright? The 2013-2016 Copyright Review Process
- FTAA
- Genetic Information Privacy
- Government Hacking and Subversion of Digital Security
- Hollywood v. DVD
- How Patents Hinder Innovation (Graphic)
- ICANN
- International Privacy Standards
- Internet Governance Forum
- Law Enforcement Access
- Legislative Solutions for Patent Reform
- Locational Privacy
- Mandatory Data Retention
- Mandatory National IDs and Biometric Databases
- Mass Surveillance Technologies
- Medical Privacy
- Mobile devices
- National Security and Medical Information
- National Security Letters
- Net Neutrality
- No Downtime for Free Speech
- NSA Spying
- OECD
- Offline : Imprisoned Bloggers and Technologists
- Online Behavioral Tracking
- Open Access
- Open Wireless
- Patent Busting Project
- Patent Trolls
- Patents
- PATRIOT Act
- Pen Trap
- Policy Analysis
- Printers
- Public Health Reporting and Hospital Discharge Data
- Reading Accessibility
- Real ID
- Reclaim Invention
- RFID
- Search Engines
- Search Incident to Arrest
- Section 230 of the Communications Decency Act
- Shadow Regulation
- Social Networks
- SOPA/PIPA: Internet Blacklist Legislation
- Student Privacy
- Stupid Patent of the Month
- Surveillance and Human Rights
- Surveillance Drones
- Terms Of (Ab)Use
- Test Your ISP
- The "Six Strikes" Copyright Surveillance Machine
- The Global Network Initiative
- The Law and Medical Privacy
- TPP's Copyright Trap
- Trans-Pacific Partnership Agreement
- Travel Screening
- TRIPS
- Trusted Computing
- Video Games
- Wikileaks
- WIPO
- Transparency
- Uncategorized





eff.org/nsa-spying
