Stories
Slash Boxes
Comments

SoylentNews is people

posted by takyon on Monday August 22 2016, @01:02PM   Printer-friendly
from the dump-for-the-chumps dept.

WikiLeaks is hosting 324 confirmed instances of malware among its caches of dumped emails, a top Bulgarian anti-malware veteran says. Random checks of reported malware hashes find the trojans are flagged as malware by Virus Total's static analysis checks.

Much of the malware appear to be attachments emailed by black hats in a bid to compromise the various parties affected in the WikiLeaks dumps.

Dr Vesselin Bontchev (@bontchev) says the instances of malware are only those confirmed and found in an initial search effort. [...] "The list is by no means exhaustive; I am just starting with the analysis," Bontchev says.


Original Submission

 
This discussion has been archived. No new comments can be posted.
Display Options Threshold/Breakthrough Mark All as Read Mark All as Unread
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
  • (Score: 4, Interesting) by Anonymous Coward on Monday August 22 2016, @01:39PM

    by Anonymous Coward on Monday August 22 2016, @01:39PM (#391607)

    It is not unexpected. But forensic research may reveal useful information here.

    Different espionage groups use different exploit tools. These are high-value targets, their email may contain zero-day exploits. There may even be exploits that can be tracked back to private espionage groups that are legally forbidden from selling their products to certain countries.

    Starting Score:    0  points
    Moderation   +4  
       Insightful=1, Interesting=3, Total=4
    Extra 'Interesting' Modifier   0  

    Total Score:   4  
  • (Score: 0) by Anonymous Coward on Monday August 22 2016, @01:51PM

    by Anonymous Coward on Monday August 22 2016, @01:51PM (#391618)

    It would be interesting to see which of the attachments do not trigger detections but still contain malware.