RSS Feed
Download our iPhone app
Browse DevX
Sign up for e-mail newsletters from DevX


Hammertoss Malware Hides in GitHub, Twitter, Cloud Traffic

A Russian advanced persistent threat is believed to be behind the attacks.


Security vendor FireEye has identified a new malware backdoor called Hammertoss which is able to hide in network traffic streams related to GitHub, Twitter and cloud computing services. This ability to blend in to network traffic makes the malicious communications very difficult to spot.

The researchers at FireEye believe a Russian advanced persistent threat (APT) group known as APT29 is behind Hammertoss. The group uses the malware to steal files and upload them to its own cloud storage accounts.

"While other APT groups try cover their tracks, very few groups show the same discipline to thwart investigators and the ability to adapt to network defenders' countermeasures," FireEye said. "For example, APT29 solely uses compromised servers for CnC, counters remediation attempts, and maintains a rapid development cycle for its malware by quickly modifying tools to undermine detection. These aspects make APT29 one of the most capable APT groups that we track."

View article

Email AuthorEmail Author
Close Icon
Thanks for your registration, follow us on our social networks to keep up-to-date