Sophisticated evasion techniques adopted in the Op Poisoned Hurricane

Pierluigi Paganini August 11, 2014

Researchers at FireEye have uncovered a new campaign dubbed Poisoned Hurricane characterized by the use of some clever techniques to avoid being detected.

Security experts at FireEye revealed that several Internet infrastructure service providers in the United States and Asia, a financial institution, a government organization located in Asia and a US-based media company suffered targeted cyber attack.

The hacking campaign, dubbed Poisoned Hurricane, was detected for the first time in March 2014, when experts at FireEye detected a PlugX (Kaba) variant that connected to legitimate domains and IP addresses. The instances analyzed by the experts were able to connect to domains such as adobe.com, update.adobe.com and outlook.com.

The attackers used the consolidated