Wednesday, August 20, 2014

NUKE REGULATOR HACKED BY SUSPECTED FOREIGN POWERS


Not once but, THRICE.

The methods adopted by the hackers is really interesting

  1. Malware in the cloud
  2. Email from legitimate account



From the Article

Nuclear Regulatory Commission computers within the past three years were successfully hacked by foreigners twice and also by an unidentifiable individual,

One incident involved emails sent to about 215 NRC employees in "a logon-credential harvesting attempt,"

A dozen NRC personnel took the bait and clicked the link. 


hackers also attacked commission employees with targeted spearphishing emails that linked to malicious software. A URL embedded in the emails connected to "a cloud-based Microsoft Skydrive storage site," which housed the malware,

In another case, intruders broke into the personal email account of an NRC employee and sent malware to 16 other personnel in the employee's contact list. A PDF attachment in the email contained a JavaScript security vulnerability. One of the employees who received the message became infected by opening the attachment, McIntyre said. 


Follow this link for additional details:

No comments:

Post a Comment