People older than 65 are less likely to reuse passwords than younger generations, an AARP survey found. Photo: Getty
People older than 65 are less likely to reuse passwords than younger generations, an AARP survey found. Photo: Getty
People older than 65 are less likely to reuse passwords than younger generations, an AARP survey found. Photo: Getty
People older than 65 are less likely to reuse passwords than younger generations, an AARP survey found. Photo: Getty

Cyber attack group targets UAE and Lebanese government officials


  • English
  • Arabic

Emirati government officials may have been compromised by a cyber-attack that would leave staff vulnerable to blackmail, analysts have said.

Researchers at the respected Cisco Talos Intelligence Group said that UAE police forces and the country’s Telecommunication Regulatory Authority, which has a role in protecting against cyber-attacks, were among the targets.

Also attacked by the mysterious group, which has not been identified, in the infiltration attempt were Lebanon’s finance ministry and Middle East Airlines, the Lebanese carrier, the experts said.

They believe that the attacker spent time studying their targets before launching their attack. The scheme could have allowed them to access confidential information and gain access to emails.

Cisco outlined details of the attempts in a briefing note by analysts this week.

The TRA has previously described attempts by hacking groups to infiltrate government and private sector companies, including 34 hacks on websites in January 2018.

_________________

Read more:

Careem hit by cyber attack with data of up to 14 million users stolen

Cyber security is 'number one priority' for companies in the UAE

Dozens of cyber attacks target UAE Government and companies

Ethical hackers and intelligence experts key to countering rise of cyber threats in UAE 

_________________

One of their attacks worked by trying to trick people into downloading Word documents infected with spying software on a fake jobs website, which was disguised as a page of a legitimate company. Web activity suggests the campaign targeted the UAE.

The other attempted to redirect web users from legitimate government web addresses to fake sites, potentially leaving members of the public to upload sensitive personal information to hackers rather than the authorities.

The identification of the attack comes after DarkMatter, the UAE-based cyber security firm, released a report in which it said it had found several “common, preventable cyber security weaknesses” across the country.

Outdated software, weak passwords and a lack of awareness were making some entities a soft target for cyber criminals, it warned.

The latest attack showed the need for public bodies and businesses to upgrade their security infrastructure, according to Hoda Al Khzaimi, the director of the Centre of Cyber Security at New York University Abu Dhabi.

“The attack relies of having a weak infrastructure when it comes to web security and people to click on postings to download malicious documents,” she said. “This is textbook, which means we have to upgrade our infrastructure and the way we build security.”

Ethical hackers take part in a competition to get access to a car during the Hack in the Box Security Conference in Dubai. Pawan Singh / The National
Ethical hackers take part in a competition to get access to a car during the Hack in the Box Security Conference in Dubai. Pawan Singh / The National

Warren Mercer and Paul Rascagneres, the authors of the blog exposing the attack, said they were unable to link the criminals to any previous activities through analysis of their tactics or IP addresses.

“Cisco Talos recently discovered a new campaign targeting Lebanon and the United Arab Emirates affecting .gov domains, as well as a private Lebanese airline company,” they wrote.

“Based on our research, it’s clear that this adversary spent time understanding the victims’ network infrastructure in order to remain under the radar and act as inconspicuous as possible during their attacks.”

In an attack associated with the scheme, users are directed to fake job websites and invited to download apparently innocent word documents which in fact contained a malicious software that included a ‘remote administration tool’. This could be used to send information from an infected computer back to the attacker. This affected users in October, before spreading in November.

A separate ‘DNS redirection attack’ was launched between September and November, leading to multiple public sector servers in the UAE being compromised with users unwittingly directed to “attacker-controlled IP addresses,” it is claimed. The analysts said several servers belonging to the public sector in Lebanon and the UAE “were apparently compromised”.

“We don’t know if the redirection attack was ultimately successful, or what exact purpose the DNS redirection served,” the authors wrote. “However, the impact could be significant, as the attackers were able to intercept all traffic destined for these host-names during this time.

“Because the attackers targeted email and VPN traffic specifically, they may have been used to harvest additional information, such as email and/or VPN credentials. As incoming email would also be arriving at the attackers’ IP addresses, if there was multi-factor authentication, it would allow the attackers to obtain MFA [security] codes to abuse.

“Since the attackers were able to access email, they could carry out additional attacks or even blackmail the target.”

The UAE has tried to beef up cyber security policies over recent years, while private sector companies have also come under attack.

Careem, the Dubai-based ride-hailing app, revealed earlier this year that the personal information of up to 14 million users, across the Middle East, North Africa, Pakistan and Turkey had been stolen by criminals. There was no evidence that credit card numbers were accessed.

The UAE government, meanwhile, rolled out an upgrade to cyber security across federal bodies last year.

if you go

The flights

Emirates have direct flights from Dubai to Glasgow from Dh3,115. Alternatively, if you want to see a bit of Edinburgh first, then you can fly there direct with Etihad from Abu Dhabi.

The hotel

Located in the heart of Mackintosh's Glasgow, the Dakota Deluxe is perhaps the most refined hotel anywhere in the city. Doubles from Dh850

 Events and tours

There are various Mackintosh specific events throughout 2018 – for more details and to see a map of his surviving designs see glasgowmackintosh.com

For walking tours focussing on the Glasgow Style, see the website of the Glasgow School of Art. 

More information

For ideas on planning a trip to Scotland, visit www.visitscotland.com

Top 10 most polluted cities
  1. Bhiwadi, India
  2. Ghaziabad, India
  3. Hotan, China
  4. Delhi, India
  5. Jaunpur, India
  6. Faisalabad, Pakistan
  7. Noida, India
  8. Bahawalpur, Pakistan
  9. Peshawar, Pakistan
  10. Bagpat, India
Classification of skills

A worker is categorised as skilled by the MOHRE based on nine levels given in the International Standard Classification of Occupations (ISCO) issued by the International Labour Organisation. 

A skilled worker would be someone at a professional level (levels 1 – 5) which includes managers, professionals, technicians and associate professionals, clerical support workers, and service and sales workers.

The worker must also have an attested educational certificate higher than secondary or an equivalent certification, and earn a monthly salary of at least Dh4,000. 

How to report a beggar

Abu Dhabi – Call 999 or 8002626 (Aman Service)

Dubai – Call 800243

Sharjah – Call 065632222

Ras Al Khaimah - Call 072053372

Ajman – Call 067401616

Umm Al Quwain – Call 999

Fujairah - Call 092051100 or 092224411

The biog

Date of birth: 27 May, 1995

Place of birth: Dubai, UAE

Status: Single

School: Al Ittihad private school in Al Mamzar

University: University of Sharjah

Degree: Renewable and Sustainable Energy

Hobby: I enjoy travelling a lot, not just for fun, but I like to cross things off my bucket list and the map and do something there like a 'green project'.

RESULT

Kolkata Knight Riders 169-7 (20 ovs)
Rajasthan Royals 144-4 (20 ovs)

Kolkata win by 25 runs

Next match

Sunrisers Hyderabad v Kolkata Knight Riders, Friday, 5.30pm