Sykipot Malware Used in Attacks Targetting Aerospace Industry

Security researchers from AlienVault have detected new Sykipot attack campaigns.
By Lucian Constantin
News Jul 4th 2012

New email-based attacks, some of which target the aerospace industry, are distributing new variants of the Sykipot information stealing malware, according to researchers from security firm AlienVault.

"We have detected a new wave of Sykipot campaigns that has been running during the past weeks," AlienVault Labs manager Jaime Blasco, said Monday in a blog post. "There are several changes between the new Sykipot campaigns and the older ones."

There are clues suggesting that these attacks originated in China, although this cannot be confirmed with one hundred percent certainty, Blasco said Wednesday.

The rogue emails sent in the new attacks no longer distribute malicious attachments that exploit vulnerabilities in Adobe Reader, Microsoft Excel or Internet Explorer to install Sykipot.