spot_img

A ‘Taj Mahal’ warning for you

Date:

Trending

Researchers with cyber security firm Kaspersky Lab have uncovered a sophisticated spying platform, TajMahal, that has been active for more than five years now and appears to be unconnected to any known threat actors.

- Advertisement -

The TajMahal framework features around 80 malicious modules and includes functionality is never before seen in an advanced persistent threat, such as the ability to steal information from printer queues and to grab previously seen files from a USB device the next time it reconnects, the researchers said.

Kaspersky Lab has so far seen only one victim, a foreign-based central Asian embassy, but it is likely that others have been affected.

- Advertisement -

“It seems highly unlikely that such a huge investment would be undertaken for only one victim. This suggests that there are either further victims not yet identified, or additional versions of this malware in the wild, or possibly both,” said Alexey Shulmin, Lead Malware Analyst at Kaspersky Lab.

“The distribution and infection vectors for the threat also remain unknown. Somehow, it has stayed under the radar for over five years. Whether this is due to relative inactivity or something else is another intriguing question. There are no attribution clues nor any links we can find to known threat groups,” Shulmin added.

- Advertisement -

The name “TajMahal” comes from the name of the file used to exfiltrate the stolen data, Kaspersky Lab said.

The TajMahal framework is believed to include two main packages, self-named as “Tokyo” and “Yokohama”.

Tokyo is the smaller of the two, with around three modules. It contains the main backdoor functionality, and periodically connects with the command and control servers. Tokyo leverages PowerShell and remains in the network even after the intrusion has moved to stage two.

Stage two is the Yokohama package: a fully armed spying framework. Yokohama includes a Virtual File System (VFS) with all plug-ins, open source and proprietary third-party libraries, and configuration files. There are nearly 80 modules in all, and they include loaders, orchestrators, command and control communicators, audio recorders, keyloggers, screen and webcam grabbers, documents and cryptography key stealers.

TajMahal is also able to grab browser cookies, gather the backup list for Apple mobile devices, steal data from a CD burnt by a victim as well as documents in a printer queue, the researchers said.

It can also request the theft of a particular file from a previously seen USB stick, and the file will be stolen the next time the USB is connected to the computer.

The targeted systems found by Kaspersky Lab were infected with both Tokyo and Yokohama. This suggests that Tokyo was used as first stage infection, deploying the fully-functional Yokohama package on interesting victims, and then left in for backup purposes.

THE SNAPSHOTS

Sign up to get quick snaps of everyday happening, directly in your inbox.

We don’t spam! Read our privacy policy for more info.

- Advertisement -
Krishna Mali
Krishna Mali
Founder & Group Editor of TechGraph.

More Latest Stories

More Articles

Foreign Secretary Cooper Denies UK’s Role in U.S. Operation Against Venezuela’s Maduro

The British Foreign Secretary, Yvette Cooper, said the UK was not involved in the recent U.S. operation targeting Venezuela, including the reported capture of...

6 Realities Every Independent Professional Eventually Faces

Choosing to work independently is a dream for many. The freedom to set your own schedule, pick your projects, and steer your career exactly where you want it is undeniably appealing. Yet, beneath the surface, there are certain realities that every independent professional eventually...

US President Trump Says PM Modi “Knew I Was Not Happy,” Links India’s Russian Oil Import Cuts to Tariff Threats

US President Donald Trump praised Indian Prime Minister Narendra Modi for what he described...

India Extends Textile PLI Application Deadline to March 31

India has extended the deadline for submission of fresh applications under the Production Linked...

Why Edge Data Centres are India’s Next Growth Frontier

India's digital economy has entered a stage where promoting growth is no longer sufficient,...

Bulgaria Becomes 21st Member of the Eurozone

Bulgaria became the 21st nation to adopt the euro as its official currency on...

India, Pakistan Exchange List of Nuclear Facilities Under Bilateral Agreement

India and Pakistan today exchanged the list of Nuclear Installations and facilities covered under...

Scaling Conversations: Superbot AI’s Sarvagya Mishra on Building Regional Voice AI for India’s Linguistic Markets

Speaking with TechGraph, Sarvagya Mishra, Founder and Director of Superbot, discussed how India’s shift...

NCB Advises Indian Travellers to Seek Clearance for Carrying Medicines to Saudi Arabia

The Narcotics Control Bureau has advised Indian travellers to obtain the required approvals before carrying medicines while travelling to Saudi Arabia. The advisory follows the...

The Hidden Business Layer Behind IoT Connectivity

When people talk about the Internet of Things, the focus is usually on devices....

When Cybersecurity Tools Break the System: The Hidden Risk Behind Digital Defenses

Cybersecurity solutions are designed to protect businesses from threats, but increasingly, these very tools...

The Cost of Blind Trust: How Inadequate Verification Is Fueling India’s Data Scam Epidemic

India’s digital economy is expanding faster than ever. From gig platforms and financial services...

Building a Future-Ready Portfolio in a Digitally Driven Economy

The rapidly changing investment landscape in India has the nation's fast-growing digital economy at...

Why BFSI Needs Generative AI, Not Rule Engines

The Banking, Financial Services, and Insurance (BFSI) sector has been using rule engines for decision automation, workflow management, and regulatory compliance for decades. These...

How Unified Intelligence Is Transforming the Future of Device Security

Device security has always been a balancing act; protecting sensitive data without slowing the business. With remote work, more IoT devices, and smarter attacks, the old siloed approaches don't work anymore. Unified intelligence is an integrated framework that uses AI and machine learning to...

Enterprise Blind Spots: 3 Cubed’s Shammik Gupta on Building a Digital Twin for Real Operational Clarity

Speaking with TechGraph, Shammik Gupta, Founder of 3 Cubed, discussed how enterprises invested in...

Why Solar Panels Are a Worthwhile Investment

With the increasing urgency to transition to sustainable energy sources, investing in solar panels...

How can mid-career professionals transition into AI-assisted roles without going back to college?

Artificial intelligence is reshaping industries worldwide, from healthcare to finance, marketing, logistics, and education....

Adda247’s Bimaljeet Singh Bhasin on Career247 and the Push for Job-Ready Education

In an interview with TechGraph, Bimaljeet Singh Bhasin, CEO of Skilling and Higher Education...

The Future of Preventive Healthcare in India and the Role of Digital Platforms

India is set to decide on the ongoing healthcare evolution, where the main point...

How Cloud Infrastructure Is Powering India’s SaaS and App Economy

India's Software as a Service (SaaS) and app economy has become one of the...

Home Improvements That Benefit You Today and Boost Value Tomorrow

When it comes to home improvements, the best upgrades are those that provide immediate...

India’s AIF Shift: Steptrade Capital’s Kresha Gupta on the Evolution of Alternative Investments in India

Speaking with TechGraph, Kresha Gupta, Director and Fund Manager at Steptrade Capital, discussed how...

The Shift to Intelligent Hiring: HunarAI’s Krishna Khandelwal on How AI Is Reshaping Recruitment in India

In an interaction with TechGraph, Krishna Khandelwal, Founder and CEO of Hunar.AI, outlined how...

The Cost of Blind Trust: How Inadequate Verification Is Fueling India’s Data Scam Epidemic

India’s digital economy is expanding faster than ever. From gig platforms and financial services...

Tech Driven Urban Growth: How Digital Innovation is Shaping Sustainable Real Estate in India’s Emerging Cities

India stands at an important moment in its urban journey. The country’s largest cities...

Democratising Tech: The AI Revolution Across India’s Healthcare and Finance Sectors

A historic shift is sweeping through India: technology is no longer confined to metro...

Serhiy Tokarev on the Four Hidden Advantages of the CEE Startup Ecosystem

Central and Eastern Europe (CEE) has changed a lot in the last ten years....

How Self-Service Analytics Is Reshaping Everyday Business Decisions

For years, analytics ran on a predictable cycle. Business teams raised requests and waited...

Building a Future-Ready Portfolio in a Digitally Driven Economy

The rapidly changing investment landscape in India has the nation's fast-growing digital economy at...

India’s AIF Shift: Steptrade Capital’s Kresha Gupta on the Evolution of Alternative Investments in India

Speaking with TechGraph, Kresha Gupta, Director and Fund Manager at Steptrade Capital, discussed how...

Vimal Singh on ReadyAssist’s Role in Modernising Roadside Assistance in India

Speaking with TechGraph, Vimal Singh, Founder of ReadyAssist, discussed how traditional roadside assistance models...

The Shift to Intelligent Hiring: HunarAI’s Krishna Khandelwal on How AI Is Reshaping Recruitment in India

In an interaction with TechGraph, Krishna Khandelwal, Founder and CEO of Hunar.AI, outlined how...