Chinese virus targets DoD Common Access Card
Posted : Wednesday Jan 18, 2012 17:45:08 EST
A Chinese-based cyber attack is targeting the Defense Department’s Common Access Cards with technology that could steal information from military networks while troops and civilians work at their desks, researchers say.
The new cyber weapon apparently can get inside individual computers after users unwittingly open a standard PDF email file. Once embedded, it logs the users’ keystrokes to obtain personal identification numbers or codes associated with that card and user, according to AlienVault, a Silicon Valley-based cyber security firm.
“Basically, they are able to steal the PIN and then they can get access to whatever they want,” said Jaime Blasco, the lab manager for AlienVault who published detailed technical information about the attack.
The attacks are a variant of a virus, or malware, known as “Sykipot” and date back as far as March 2011, Blasco said.
The new Sykipot strain specifically targets the technology used to support the Pentagon’s CAC system and the emails seeking to spread it often are disguised as official military or government communications, Blasco said.
To lure defense workers to open the infected attachment, some of the emails have used information about new drone technology and pictures of unmanned aerial vehicles, he said.
The hackers behind the virus can access military systems only as long as an infected user’s card remains logged into a system.
Pentagon spokeswoman Air Force Lt. Col. April Cunningham declined to comment on the details published by AlienVault.
“We are aware of reports regarding this matter and take these type of reports seriously. However, due to operational security, we are not able to provide further details,” she told Military Times.
Blasco said the virus is linked to a “command and control server” that appears to be based in China; some flaws buried deep in the code revealed Chinese language characters, suggesting that only a Chinese speaker would be able to launch it.
Defending against attacks using this technology is extremely difficult. The best way to keep military networks secure is to train troops and civilian employees not to open any unfamiliar files or email attachments, Blasco said.
Many military officials are eager to begin widespread use of smart phones, tablets and other wireless devices, but cyber security experts caution that such technology can be more vulnerable to cyber attacks.
Leave a Comment
Most Viewed Stories
- Army more selective on recruits, re-enlistments
- Sill capt., 2nd lt. killed in Afghanistan
- Lawyer blasts military justice, leaves practice
- Report: Bragg 1-star removed from position
- Soldier washed out of BUD/S but wore Trident
- Deadline approaches for officer transfers
- Combat warrants limit raids, cause worry over leaks
- As vets process memories, uniforms get new life
- June officer promotion list released
- Doctor who helped CIA find OBL convicted
- Ind. guardsman dies in Afghanistan attack
- Reservist’s death in Afghanistan ruled suicide
Contests and Promotions
Free Stickers
Click here and we'll send you a FREE AFGHANISTAN, IRAQ, VIETNAM, or DESERT STORM sticker.
Marketplaces
Industry
MIl-MALL
Browse and buy some of the awesome products we have at Mil-mall.com
-
Gummi Army Guys
Price: $1.25
Add to Cart | See More Products! -
Sniper Brew Classic Roast Coffee
Price: $9.95
Add to Cart | See More Products! -
The Hooah! button
Price: $9.95
Add to Cart | See More Products! -
SNIPER: American Single-Shot Warriors in Iraq and Afghanistan
Price: $16.95
Add to Cart | See More Products! -
Army Scrapbook Album
Price: $9.95
Add to Cart | See More Products! -
VALOR and VISION: Heroes * Leaders * Innovation
Price: $6.95
Add to Cart | See More Products!
Military Discounts
Save on your purchases!
In honor of your military service, you can find regular and name brand products at a special discount.










