US Firm Finds Malware Targeting Visitors to Afghan Government Websites

Advertisement
By Reuters | Updated: 22 December 2014 09:40 IST
Malicious software likely linked to China is being used to infect visitors to a wide range of official Afghan government websites, U.S. cyber-security researchers say.

ThreatConnect, a Virginia-based cyber-security firm, said its researchers last week found a corrupted JavaScript file that is being used to host content on "gov.af" websites, and there are no antivirus protections available for the malware.

Rich Barger, chief intelligence officer of ThreatConnect, told Reuters his company was confident the new campaign, "Operation Poisoned Helmand," was linked to the "Poisoned Hurricane" campaign detected this summer by another security firm, FireEye, that linked it to Chinese intelligence.

He said the latest attack was very recent and one timestamp associated with the Java file was from December 16, the same day Chinese Prime Minister Li Keqiang visited Afghanistan to meet with Afghanistan's chief executive officer, Abdullah Abdullah.

Advertisement

China is seeking to take a more active role in Afghanistan as the United States and NATO reduce their military presence.

Advertisement

"We found continued activity from Chinese specific actors that have used the Afghan government infrastructure as an attack platform," Barger said, noting that Chinese intelligence could use the malware to reach a wide array of global targets checking trusted Afghan government sites for information.

Barger said the attack was a variant of what he called a typical "watering-hole" attack in which the attackers infect a large number of victims, and then follow up with the most "promising" hits to extract data.

Advertisement

He said researchers this summer saw a malicious Java file on the website of the Greek embassy in Beijing while a high-level delegation led by Keqiang was visiting Greek Prime Minister Antonis Samaras in Athens.

The two events were not directly related, Barger said, and additional research was needed into the status of ministerial and official government websites on or around the dates of notable Chinese delegations and or bilateral meetings.

Advertisement

The malware was found on a variety of Afghan government websites, including the ministries of justice, foreign affairs, education, commerce and industry, finance and women's affairs, according to ThreatConnect, which was formerly known as CyberSquared.

The report emerged as the United States sought help from China, Japan, South Korea and Russia in combating cyber-attacks such as the one Washington on Friday accused North Korea of carrying out against Sony Pictures.

© Thomson Reuters 2014

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Apple Announces New Annual and Monthly AppleCare+ Plans in India
  2. Jio Brings Free Gemini 3 AI to All 5G Subscribers: See Eligibility, Benefits
  3. Qualcomm to Launch Snapdragon 8 Gen 5 Chip on This Date
  4. Google's Gemini 3 AI Models Are Finally Here With These New Features
  5. Realme 15 Lite 5G Listed on Amazon With These Specifications
  6. From Courtrooms to CBDCs: Nischal Shetty on India's Growing Crypto Sector
  7. Oppo Find X9 Pro Review: A 'Pro' Flagship With 'Ultra' Capability
  8. Gemini App and AI Mode in Search Get New Features With Gemini 3 AI Model
  9. Oppo Enco Buds 3 Pro+ With Up to 43 Hours of Battery Life Launched in India
  10. Vivo V60e Review
  1. Jio Brings Google's Gemini 3 AI Model to All 5G Unlimited Subscribers: Check Eligibility, Benefits
  2. Realme 15 Lite 5G Listed on Amazon With Dimensity 8000 Chipset: Price in India, Specifications
  3. Qualcomm Announces Snapdragon 8 Gen 5 Chipset Launch Date in China: What to Expect
  4. New AppleCare+ Coverage Options in India Announced With Theft and Loss Protection for iPhone
  5. Gemini 3 Release Comes With a Redesigned Gemini App, New Features for AI Mode
  6. Mars Orbiter Tracks Interstellar Comet 3I/ATLAS With Unprecedented Precision
  7. China to Launch Empty Shenzhou-22 Lifeboat After Shenzhou-20 Damage
  8. German Team Uses Autonomous AI to Steer CubeSat in Space
  9. Gemini 3 Released as Google’s Most Intelligent AI Models Yet, Outperforms GPT-5.1 and Claude 4.5 Sonnet
  10. Extreme Star Factory: ALMA Detects Galaxy Y1 Forming Stars 180 Times Faster Than the Milky Way
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.