Syria has been the center of much international attention lately. There's unrest in the country and the authoritarian government is using brutal tactics against dissidents. These tactics include using technology surveillance, trojans and backdoors. Some time ago we received a hard drive via a contact. The drive had an image of the system of a Syrian activist who had been targeted by the local authorities. The activist's system had become infected as a result of a Skype chat. The chat request came from a fellow activist. **The problem was that the fellow activist had already been arrested and could not have started the chat**. Initial infection occurred when the activist accepted a file called _MACAddressChanger.exe_ over the chat. This utility was supposed to change the hardware MAC address of the system in order to bypass some monitoring tools. Instead, it dropped a file called _silvia.exe_ which was a backdoor -- a backdoor called "**Xtreme RAT**". Xtreme Rat is a full-blown malicious Remote Access Tool. Sold for 100 euro (Paypal) via a page hosted at Google Sites: https://sites.google.com/site/nxtremerat We have reasons to believe this infection wasn't just bad luck. We believe the activist's computer was specifically targeted. In any case, ...
f-secure