New York Tech Media
  • News
  • FinTech
  • AI & Robotics
  • Cybersecurity
  • Startups & Leaders
  • Venture Capital
No Result
View All Result
  • News
  • FinTech
  • AI & Robotics
  • Cybersecurity
  • Startups & Leaders
  • Venture Capital
No Result
View All Result
New York Tech Media
No Result
View All Result
Home Cybersecurity

ModifiedElephant APT hackers plant incriminating evidence on victims devices

New York Tech Editorial Team by New York Tech Editorial Team
February 11, 2022
in Cybersecurity
0
ModifiedElephant APT hackers plant incriminating evidence on victims devices
Share on FacebookShare on Twitter

ModifiedElephant APT group has been carrying out its malicious activities since 2012 and successfully evading detection for over a decade.

The IT security researchers at SentinelLabs have revealed details of an advanced persistent threat (APT) group that’s been hijacking the devices of lawyers, educationists, defenders, journalists, and civil rights activists since 2012.

According to SentinelLabs’ report, the group, dubbed ModifiedElephant, plants ‘incriminating evidence’ on its targets’ devices.

About ModifiedElephant’s Cybercrimes

According to researchers, the APT group that evaded detection for a decade has been involved in widespread cyberattacks in India, and the group has persistently targeted high-profile personalities.

Interestingly, the group doesn’t focus on data theft but surveillance. After invading its victim’s device, ModifiedElephant implants files that could be used to prosecute the individual, apart from spying on their activities.

Researchers at SentinelLabs believe that the group’s primary objective is to carry out “long-term surveillance” that usually concludes with the “delivery of evidence.’ This evidence incriminates the victim in specific crimes.

Researchers wrote that there’s an “observable correlation between ModifiedElephant attacks and the arrests of individuals in controversial, politically-charged cases.”

“After careful review of the attackers’ campaigns over the last decade, we have identified hundreds of groups and individuals targeted by ModifiedElephant phishing campaigns. Activists, human rights defenders, journalists, academics, and law professionals in India are those most highly targeted. Notable targets include individuals associated with the Bhima Koregaon case,” SentinelLabs wrote in its report.

Attack Tactics

SentinelLabs claims that ModifiedElephant APT has targeted hundreds of individuals and groups. Their attack tactics involve spearphishing emails using popular email services providers like Yahoo and Gmail to start the infection chain.

“The spearphishing emails and lure attachments are titled and generally themed around topics relevant to the target, such as activism news and groups, global and local events on climate change, politics, and public service,” researchers noted.

The emails contain documents embedded with DarkComet or NetWire RATs, keyloggers, and an unidentified Android Trojan.

ModifiedElephant APT Group plants incriminating evidence on victims' devices
One of the spearphishing emails attributed to ModifiedElephant containing a malicious attachment (Image: SentinelLabs)

Two Entities Identified

Researchers claim that the malware ModifiedElephant uses is mundane and not as sophisticated as expected, but some of its victims have been targeted with NSO Group’s controversial Pegasus spyware.

One such victim was Rona Wilson, whose phone was infected with the Pegasus spyware, which the government of India purchased in its 2 billion-dollar defense deal with Israel back in 2017. The report also revealed that the activities of the APT group are sharply in line with “Indian state interests.”

According to SentinelLabs, a second entity is rigging the phones of those involved in the Koregaon case. This entity was identified to be SideWinder. Between Feb 2013 and Jan 2014, both SideWinder and ModifiedElephant targeted Rona Wilson.

The victim receives phishing emails from SideWinder, and around the same timeframe, ModifiedElephant also invaded Wilson’s device. Researchers suspect that a single entity hired both the hacker groups or these groups could be connected.

“The relationship between ModifiedElephant and SideWinder is unclear as only the timing and targets of their phishing emails overlap within our dataset. This could suggest that the attackers are being provided with similar tasking by a controlling entity, or that they work in concert somehow.”

More malware news on Hackread.com

Gionee subsidiary implanted malware in over 20 million phones

Hezbollah linked hackers hit companies in global malware attack

$120 charging cable O.MG remotely steals data from Apple devices

“Operation Poisoned News” infecting iPhones with LightSpy spyware

NSO zero-click iMessage exploit hacks iPhone without need to click links

Credit: Source link

Previous Post

Uber and Lyft are finally starting to look like different companies

Next Post

US nuclear power plants contain dangerous counterfeit parts, report finds

New York Tech Editorial Team

New York Tech Editorial Team

New York Tech Media is a leading news publication that aims to provide the latest tech news, fintech, AI & robotics, cybersecurity, startups & leaders, venture capital, and much more!

Next Post
US nuclear power plants contain dangerous counterfeit parts, report finds

US nuclear power plants contain dangerous counterfeit parts, report finds

  • Trending
  • Comments
  • Latest
Meet the Top 10 K-Pop Artists Taking Over 2024

Meet the Top 10 K-Pop Artists Taking Over 2024

March 17, 2024
Clubhouse will soon let you pin links to the top of rooms

Clubhouse will soon let you pin links to the top of rooms

October 23, 2021
10 Raunchy Movies on Netflix You Won’t Regret Watching

10 Raunchy Movies on Netflix You Won’t Regret Watching

May 20, 2024
Panther for AWS allows security teams to monitor their AWS infrastructure in real-time

Many businesses lack a formal ransomware plan

March 29, 2022
Zach Mulcahey, 25 | Cover Story | Style Weekly

Zach Mulcahey, 25 | Cover Story | Style Weekly

March 29, 2022
How To Pitch The Investor: Ronen Menipaz, Founder of M51

How To Pitch The Investor: Ronen Menipaz, Founder of M51

March 29, 2022
Startups On Demand: renovai is the Netflix of Online Shopping

Startups On Demand: renovai is the Netflix of Online Shopping

2
Robot Company Offers $200K for Right to Use One Applicant’s Face and Voice ‘Forever’

Robot Company Offers $200K for Right to Use One Applicant’s Face and Voice ‘Forever’

1
Menashe Shani Accessibility High Tech on the low

Revolutionizing Accessibility: The Story of Purple Lens

1

Netgear announces a $1,500 Wi-Fi 6E mesh router

0
These apps let you customize Windows 11 to bring the taskbar back to life

These apps let you customize Windows 11 to bring the taskbar back to life

0
This bipedal robot uses propeller arms to slackline and skateboard

This bipedal robot uses propeller arms to slackline and skateboard

0
corporate practice of medicine

When Business Growth Starts to Influence Clinical Decisions

September 10, 2026
man using a computer

AI Is Easy to Try. Making It Work Is Harder.

September 9, 2026
Kesewi works to a two-word standard: think simple.

One Concept, One Yes: The Studio That Stopped Offering Options

September 8, 2026
FINQ’s Autonomous Ranking Engine Produces 23.51% and 23.83% Since Inception as the S&P 500 Returns 11.61%

FINQ’s Autonomous Ranking Engine Produces 23.51% and 23.83% Since Inception as the S&P 500 Returns 11.61%

September 7, 2026
Blackstone Backs Huskeys With $27M Series A as Security Teams Struggle to Control the Modern Network Edge

Blackstone Backs Huskeys With $27M Series A as Security Teams Struggle to Control the Modern Network Edge

September 2, 2026
Deal Room and Playlist Agent

Walnut Extends AI Agents Across the Full Buyer Journey With Enterprise-Grade Platform Launch

September 2, 2026

Recommended

corporate practice of medicine

When Business Growth Starts to Influence Clinical Decisions

September 10, 2026
man using a computer

AI Is Easy to Try. Making It Work Is Harder.

September 9, 2026
Kesewi works to a two-word standard: think simple.

One Concept, One Yes: The Studio That Stopped Offering Options

September 8, 2026
FINQ’s Autonomous Ranking Engine Produces 23.51% and 23.83% Since Inception as the S&P 500 Returns 11.61%

FINQ’s Autonomous Ranking Engine Produces 23.51% and 23.83% Since Inception as the S&P 500 Returns 11.61%

September 7, 2026

Categories

  • AI & Robotics
  • Benzinga
  • Cybersecurity
  • FinTech
  • New York Tech
  • News
  • Startups & Leaders
  • Venture Capital

Tags

AI AI QSRs AI security Allseated Automat-it AWS B2B marketing Business CISO CISO Whisperer Collaborations Companies To Watch Cybersecurity Enterprise AI Entrepreneur Fetcherr Finance FINQ Fintech Funding Announcement Hi Auto Impala Investing Investors investorsummit israelitech Leaders Mate Security Metaverse Mindset Minnesota omri hurwitz Perion PointFive PR QSR Real Estate start- up startupnation Startups Startups On Demand Tech Tech leaders Unlimited Robotics VC
  • Contact Us
  • Privacy Policy
  • Terms and conditions

© 2024 All Rights Reserved - New York Tech Media

No Result
View All Result
  • News
  • FinTech
  • AI & Robotics
  • Cybersecurity
  • Startups & Leaders
  • Venture Capital

© 2024 All Rights Reserved - New York Tech Media