• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
Tech

Hackers attack the energy industry with malware designed for snooping

Robert Hackett
By
Robert Hackett
Robert Hackett
Down Arrow Button Icon
Robert Hackett
By
Robert Hackett
Robert Hackett
Down Arrow Button Icon
March 31, 2015, 2:55 PM ET
A pump jack is seen at sunrise near Bakersfield
A pump jack is seen at sunrise near Bakersfield, California October 14, 2014. Brent crude hit a new four-year low on Wednesday before recovering to just under $85 a barrel, as faltering global growth curbed demand for fuel at a time of heavy oversupply. Oil saw its biggest daily fall in more than three years on Tuesday after the West's energy watchdog slashed its forecasts for world oil demand for this year and 2015. Picture taken October 14, 2014. REUTERS/Lucy Nicholson (UNITED STATES - Tags: ENERGY BUSINESS TPX IMAGES OF THE DAY) - RTR4ABEWPhotograph by Lucy Nicholson — Reuters

Hackers have been targeting energy industry workers with malicious emails containing malware that, when opened, leave the recipients vulnerable to snooping, software security giant Symantec reported Monday.

The campaign has primarily targeted Middle Eastern countries such as the United Arab Emirates, Kuwait, and Saudi Arabia. But it has also afflicted other nations as well, including the United States, the United Kingdom, and Uganda.

Because most of the companies singled out are involved in the energy business, Symantec speculated that the hackers are motivated by industrial espionage. “Whoever is behind these attacks may have a strategic interest in the affairs of the companies affected,” Symantec said in a blog post.

Having monitored this targeted email attack since the beginning of the year, Mountain View, Calif.-based Symantec (SYMC) reports that it discovered the malicious software program at its center on Feb. 11. The malware in question is a so-called trojan horse, a type of harmful software program that disguises itself as an innocent file.

In this case, the trojan—dubbed “Trojan.Loziak” by the researchers—masqueraded as a Microsoft Excel spreadsheet file. Once downloaded on a vulnerable machine, the previously unreported strain of malware steals information—like system configuration data—off of it. The malware appears to help the attackers determine whether a computer contains valuable data, and therefore whether it is an interesting target or not.

Here’s how the attack works: First the trojan performs an initial survey—collecting information about the computer’s name, installed software (including antivirus), and additional hardware specifications—and then it sends those details back to hackers responsible. If the hackers decide to proceed with the attack, they further infect the machines with additional malware, delivered via servers based in the U.S., U.K., and Bulgaria, according to Symantec. These include pieces of malware such as “Back.door.Cyberat” and “Trojan.Zbot,” which steal confidential information and open “backdoors,” leaving systems susceptible to further breaching.

To gain entry, the attack preys on the same vulnerability in Microsoft Windows that has been exploited in past espionage campaigns, such as Red October, the blog says. (Here’s Fortune’s story about a dispute between two security firms over the alleged resurrection of that campaign.)

Although the post concludes that the attack is relatively unsophisticated, it stresses that the campaign still poses a threat to those who do not keep up to date with the latest security updates.

The group behind the attack does not seem to be particularly advanced, as they exploited an old vulnerability and used their attack to distribute well-known threats that are available in the underground market. However, many people still fail to apply patches for vulnerabilities that are several years old, leaving themselves open to attacks of this kind. From the attacker’s perspective, they don’t always need to have the latest tools at their disposal to succeed. All they need is a bit of help from the user and a lapse in security operations through the failure to patch.

As long as users leave known vulnerabilities unrepaired, hackers will be able to continue to exploit computer systems with minimal effort.

About the Author
Robert Hackett
By Robert Hackett
Instagram iconLinkedIn iconTwitter icon
See full bioRight Arrow Button Icon

Latest in Tech

AIchief executive officer (CEO)
Microsoft AI boss Suleyman opens up about his peers and calls Elon Musk a ‘bulldozer’ with ‘superhuman capabilities to bend reality to his will’
By Jason MaDecember 13, 2025
10 hours ago
InvestingStock
There have been head fakes before, but this time may be different as the latest stock rotation out of AI is just getting started, analysts say
By Jason MaDecember 13, 2025
15 hours ago
Politicsdavid sacks
Can there be competency without conflict in Washington?
By Alyson ShontellDecember 13, 2025
16 hours ago
InnovationRobots
Even in Silicon Valley, skepticism looms over robots, while ‘China has certainly a lot more momentum on humanoids’
By Matt O'Brien and The Associated PressDecember 13, 2025
18 hours ago
Sarandos
Arts & EntertainmentM&A
It’s a sequel, it’s a remake, it’s a reboot: Lawyers grow wistful for old corporate rumbles as Paramount, Netflix fight for Warner
By Nick LichtenbergDecember 13, 2025
22 hours ago
Oracle chairman of the board and chief technology officer Larry Ellison delivers a keynote address during the 2019 Oracle OpenWorld on September 16, 2019 in San Francisco, California.
AIOracle
Oracle’s collapsing stock shows the AI boom is running into two hard limits: physics and debt markets
By Eva RoytburgDecember 13, 2025
23 hours ago

Most Popular

placeholder alt text
Success
Apple cofounder Ronald Wayne sold his 10% stake for $800 in 1976—today it’d be worth up to $400 billion
By Preston ForeDecember 12, 2025
2 days ago
placeholder alt text
Economy
Tariffs are taxes and they were used to finance the federal government until the 1913 income tax. A top economist breaks it down
By Kent JonesDecember 12, 2025
2 days ago
placeholder alt text
Success
40% of Stanford undergrads receive disability accommodations—but it’s become a college-wide phenomenon as Gen Z try to succeed in the current climate
By Preston ForeDecember 12, 2025
2 days ago
placeholder alt text
Economy
The Fed just ‘Trump-proofed’ itself with a unanimous move to preempt a potential leadership shake-up
By Jason MaDecember 12, 2025
1 day ago
placeholder alt text
Success
Apple CEO Tim Cook out-earns the average American’s salary in just 7 hours—to put that into context, he could buy a new $439,000 home in just 2 days
By Emma BurleighDecember 12, 2025
2 days ago
placeholder alt text
Economy
For the first time since Trump’s tariff rollout, import tax revenue has fallen, threatening his lofty plans to slash the $38 trillion national debt
By Sasha RogelbergDecember 12, 2025
2 days ago
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Leadership
  • Success
  • Tech
  • Asia
  • Europe
  • Environment
  • Fortune Crypto
  • Health
  • Retail
  • Lifestyle
  • Politics
  • Newsletters
  • Magazine
  • Features
  • Commentary
  • Mpw
  • CEO Initiative
  • Conferences
  • Personal Finance
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map

© 2025 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.