logo

Bit9: 32 Pieces of Malware Whitelisted In Targeted Hack

ID: 56c1dd46-9c63-5297-9208-98e269f71551

STIX ID: report--56c1dd46-9c63-5297-9208-98e269f71551

Feed Name: Security Ledger

Threat Score
78/100

Date Published: 2013-02-26

Date Updated: 2026-05-08

Author: Paul Roberts

...
...

Bit9’s corporate network was compromised via a SQL injection that allowed attackers to access accounts and an inactive code-signing server; the attackers signed 32 malicious files (HiKit, HomeUNIX, Hydraq variants) and used them in watering-hole style attacks against three customer networks, effectively bypassing Bit9’s whitelisting defenses. Analysis points to sophisticated, information-gathering malware and possible attribution to actors in China/APAC, with evidence including C2 beacons and references to sinkholed IPs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.