‘Marty McFly’ malware attacks Italian Navy
Posted: Thursday, November 1, 2018
A Russian hacking collective is being named as the instigator of a recent ‘timed’ attack on the Italian naval industry. The goal was to get the company to download malware called MartyMcFly via a phishing email, after which a Remote Access Tool (RAT) would control the company’s system and steal their data. It is believed that the attack was planned in 2010 and was programmed to be activated in late 2017/2018 – hence the name of the virus making reference to the main character in the film ‘Back to the Future’.
The attack originated from a well-crafted email sent to the relevant department asking for the price of spare parts for naval engines. The mail was quite clear, written using the correct jargon and asking for relevant pricing. The email included two attachments, a company profile and a Microsoft.SLSX listing the spare parts required. The quotation request meant that the victim had to open the spreadsheet in order to ascertain what to price, and so release the virus.
Italian cyber security company YOROI have conducted an investigation into the attack. Full technology details may be found here: https://blog.yoroi.company/?p=1829











