A GAMER TURNED MALWARE DEVELOPER : DIVING INTO SILVER RAT AND IT’S SYRIAN ROOTS

EXECUTIVE SUMMARY

This report provides a glimpse into the evolving landscape of RAT development and malicious activities performed by threat actors working under name of ‘Anonymous Arabic’. Our team investigated the Silver RAT (written in C sharp) which has capabilities to bypass anti-viruses and covertly launch hidden applications, browsers, keyloggers, and other malicious activities. The developers operate on multiple hacker forums and social media platforms, showcasing an active and sophisticated presence, in addition to a Telegram channel offering a range of services including the distribution of cracked RATs, leaked databases, carding activities, and the sale of social media bots, which are employed to promote services by automatically engaging with and commenting on user content.

INTRODUCTION

Silver RAT v1.0 was observed in the wild during November 2023. The authors of Silver RAT have also developed another product called S500 RAT. While Silver RAT is currently Windows-based, recent announcements indicate that the developers are planning to launch a new version with the ability to generate both Windows and Android payloads. Silver RAT v1.0 comes with destructive features such as a keylogger, UAC bypass, data encryption using ransomware, and functions to destroy system restore points.

The developer of Silver RAT is, known as ‘noradlb1,’ and is active on prominent hacking forums like XSS, Darkforum, TurkHackTeam, and others, with an arguably respected reputation. The RAT first appeared on their Telegram channel and later on Turkhackteam and 1877 forums. Silver RAT was cracked and leaked on Telegram around October, 2023, and now users on Telegram and GitHub are sharing cracked versions of Silver RAT v1.0 to users without the means to purchase RATs (however there is evidence from user conversations that this may not be as effective as other well-known RATs like xworm).

While generating a payload using Silver RAT’s builder, threat actors can select various options with a payload size up to a maximum of 50kb. Once connected, the victim appears on the attacker controlled Silver RAT panel, which displays the logs from the victim based on the functionalities chosen. The threat actor can hide processes under false headings, and the final payload can be generated in a Windows executable file, delivered through various social engineering methods.

The announcement about the sale of Silver RAT 1.0 initially appeared on the TurkHackTeam forum and later surfaced on 1877 and other underground hacking forums.

Our team found that the threat actor also posted in a well-known Russian forum, selling Silver RAT v1.0.

Additionally, they created a website under an e-commerce domain to facilitate the sale of Silver RAT v1.0.

ASSESSMENT

The initial announcement regarding the release of Silver RAT V1.0 was made on October 19, 2022 on their Telegram channel. Subsequent to this, (November 19, 2022) the threat actor released the RAT on two hacker forums.

PANEL OVERVIEW

Silver RAT v1.0 written in C Sharp is a Window based RAT builder for windows systems, which has different features like Bypass AV, stealing browser cookies, keylogger, hidden browser, hidden RDP access and much more.

Our team have performed the analysis of the Silver RAT v1.0 builder in order to assess it’s capabilities: after executing, there is an initial prompt to request a port number on which Silver RAT will bind the IP, and port number for reverse shell.

This is the builder section of Silver RAT, where users will find numerous options. Some notable features include the ability to Bypass AV, conceal malicious processes by assigning custom process names, and specify the connection method. The user can choose between default connection settings by providing an IP for reverse connection or opt for a web HTML link.

Below is a list of the arguably most interesting functionalities of Silver RAT v1.0:

  • The attacker can utilize either an IP address with a specified port, or a webpage for command and control of the target system.
  • Windows defender exclusion function prevents detection after the program has been launched for the first time.
  • Attackers can configure this functionality to erase all system restore points. If the target attempts to turn off the system and run system restore, it will be ineffective.
  • This option can be configured to delay the execution of the payload. If the target runs the payload, it will not activate until the specified time has elapsed.
  • Hidden process and hidden installation, i.e. the capability to hide a process within the task manager. The attacker can provide a custom process name to hide the payload in a folder, which cannot be found even if the target tries to view hidden files or folders within Windows settings.
  • Bypassing Antivirus using FUD Crypters.

A point to note is that the payload size increases when users select more options, ranging from 40- 50KB.

In the execution process, the .Net executable payload can be delivered by using various social engineering tactics. Upon execution, an administrated permission prompt will appear, and it will run a CMD window that disappears in less than 2 seconds.

Following this, Silver RAT v1.0 establishes a connection, once connected the target will appear in the targets list.

ADMIN CONTROL PANEL

Upon successful connection, the attacker gains the ability to initiate various malicious activities on the target system, as seen in below snippet.

Beginning with the top option ‘Manager,’ the attacker can manage and control various aspects of the target system. This includes managing installed applications, navigating the file manager, modifying registry keys, checking startup items, and monitoring the performance of the target system.

Additionally, attackers can leverage other interesting malicious activities on target system such as:

Hidden Apps
– Attackers can control multiple applications on the client’s computer covertly, with various apps running concurrently.

Hidden Browsers
– Gives the ability to add client browsers to a hidden list.
– Enables the attacker and the victim to use the browser at the same time.

Hidden VNC
– Gives the attackers control of target system
– Attackers can control the client’s internet browsers.

The image below illustrates specific stealing capabilities of Silver RAT v1.0.

Additionally, an attacker can encrypt data on the victim’s computer using ransomware, delete data and browser cookies from the target computer remotely, propogate like worm through USB , and erase system restore points.

BUILDER CODE REVIEW

After analyzing the program file of the builder, there are some flags that warrant discussion:

The below highlights boolean flags like ‘RuntimeProcessCheckerProtection’, ‘RuntimeAntiDebugProtection’, ‘KillDebuggerProtection’, ‘KillMaliciousProcess’, ‘DetectDllInjection’, and ‘RunSingleThread’.

These flags are used to protect the RAT from various debugging techniques, as well as protecting the program from being analyzed. If such activity is detected, the anti-analysis code will terminate the program’s execution.

In the snippet below this list called ‘BadPList’ containing different strings related to programs used by malware analysts. Each string represents the name of a process or tool that the RAT considers potentially bad or associated with debugging and analysis activities.

EXTERNAL THREAT LANDSCAPE MANAGEMENT (ETLM)

Threat Actor Profile:
The Silver RAT developers have 2 different Telegram channels with 1k+ on one channel and 700+ users on another channel, indicating a high user engagement rate.

CYFIRMA researchers found out that the threat actor has been using a well-known Crypto wallet, employing different addresses for transactions, ranging from Bitcoin to Ethereum and USDT (Tether).

Their Bitcoin wallet appears to be empty, while their Ethereum wallet shows 8 transactions including 1 deposit and 7 transfers.

We note approximately 2,275.67 USD of transactions between December 24,2023 and December 25,2023 period, including potential cashing out activities.

During the analysis, we backtracked to the PayPal purchase option, and upon exiting the page, we obtained the Gmail address used by threat actor for PayPal account.

During our investigation, we discovered a Facebook account of a hacktivist group that supports the “Syrian Revolution”, with post engagement from a developer of Silver RAT based on multiple attribute matches. Reviewing the developer’s previous posts reveals a history of offering various first-person shooter (FPS) game hacks and mods.

Based on these observations, it can be ascertained with high confidence that the Silver RAT developer:

  • Began hacking as a teen
  • Is likely in his mid-twenties
  • Resides in Damascus, Syria

THREAT LANDSCAPE

A threat actor using the moniker ‘Dangerous silver,’ and another using ‘Monstermc’, serve as developers for S500 RAT and Silver RAT. They operate a Telegram channel offering malware-as-a-service, distributing cracked RATs from various developers, leaked databases, carding services, fake pages, and the sale of Twitter/Facebook bots. They have blog website named as ‘Anonymous Arabic’ that is moderated by 2 other individuals, as well as groups named as Monstermc and Syria Pirates.

Following the leak, Silver RAT v1.0 is freely available over Telegram, as well as some underground forums and Github, complete with full instructions on its malicious use.

The threat actor is actively sharing information on various social media platforms, as well as development platforms like GitHub, where the threat actors shared different red teaming methods and cracked malware.

The threat actor’s YouTube channel where they shared details about Silver RAT was banned by the platform, but a new (and still active) channel shares tutorials about their malicious tools.

The threat actor Pastebin profile shows they pasted source code of builders as well as some bypass tricks.

UNDERGROUND ACTIVITY MONITORING

We have discovered that the threat actor appears to have a good reputation on across various underground forums.

RECENT DEVELOPMENT

Silver RAT v1.0 generates a Windows executable, however Telegram chatter purports that the upcoming release of a new version of Silver RAT will be capable of generating payloads for both Android and Windows platforms.

MITRE MAPPING

Tactics Techniques
TA0002: Execution T1059: Command and Scripting Interpreter
T1053: Scheduled Task/Job
TA0003: Persistence T1053: Scheduled Task/Job
TA0004: Privilege Escalation T1055: Process Injection
T1053: Scheduled Task/Job
TA0005: Defense Evasion T1112: Modify Registry
T1497: Virtualization/Sandbox Evasion
T1055: Process Injection
T1027: Obfuscated Files or Information
TA0006: Credential Access T1056: Input Capture
T1539: Steal Web Cookie
T1552: Unsecured Credentials
T1528: Steal Application Access Token
TA0007: Discovery T1057: Process Discovery
T1497: Virtualization/Sandbox Evasion
T1083: File and Directory Discovery
T1082: System Information Discovery
TA0009: Collection T1056: Input Capture
TA0010: Exfiltration T1041: Exfiltration over C2 Channel
T1567: Exfiltration over Web Service

IOCs

No SHA256 Indicators Remarks
1 79a4605d24d32f992d8e144202e980bb6b52bf8c9925b1498a1da59e50ac51f9 Silver RAT v1.0 Builder
2 a9fa8e14080792b67a12f682a336c0ea9ff463bbcb27955644c6fcaf80023641 Silver RAT v1.0 Builder
3 7a9aeea5e65a0966894710c1d9191ba4cbd6415cba5b10b3b75091237a70a5b8 Silver RAT Payload
4 0ace7ae35b7b44a3ec64667983ff9106df688c24b52f8fcb25729c70a00cc319 Silver RAT Payload
5 3b06b4aab7f6f590aeac5afb33bbe2c36191aeee724ec82e2a9661e34679af0a Silver RAT Payload
6 27b781269be3b0d2f16689a17245d82210f39531e3bcb88684b03ae620ac5007 Silver RAT Payload
7 0ace7ae35b7b44a3ec64667983ff9106df688c24b52f8fcb25729c70a00cc319 Silver RAT Payload

CONCLUSION

The developer of Silver RAT intends to release new versions of RAT following the leak of v1.0, which rends it freely accessible for malicious purposes. The developer, operating under the name “Anonymous Arabic,” appears is supportive of Palestine based on their Telegram posts, and members associated with this group are active across various arenas, including social media, development platforms, underground forums, and Clearnet websites, suggesting their involvement in distributing various malware. It is crucial for organizations to enhance their defense mechanisms in response to this potential threat.

RECOMMENDATIONS

Strategic Recommendations:

  • Security Awareness Training: educate users about the risks of downloading and installing apps from untrusted sources. Teach them to recognize phishing attempts, suspicious links, and potentially harmful applications.
  • Regular Updates: enforce a policy of keeping devices and operating systems up to date with the latest security patches. Outdated systems can have vulnerabilities that RATs may exploit.
  • Data Encryption: encourage users to enable device encryption and use strong, unique passcodes or biometric authentication methods to protect their devices.

Management Recommendations

  • Incident Response Plan: develop and communicate an incident response plan that outlines steps to take if a device is compromised. This plan should include isolating the device, notifying relevant parties, and taking action to mitigate the breach.
  • User Support: provide users with a clear channel to report suspicious activity, unusual behavior, or potential security incidents. Ensure they understand the importance of reporting such incidents promptly.
  • Regular Backups: regularly back up your device’s data to a secure location. This helps mitigate the impact of data loss in case of a security incident.

Tactical Recommendations

  • App Review: regularly review the list of installed apps and remove any that are unused or suspicious. RATs often disguise themselves as legitimate apps.
  • Network Security: avoid using unsecured Wi-Fi networks, especially for sensitive transactions. Use a VPN when connected to public Wi-Fi to encrypt your internet traffic.
  • Behavioral Analysis: implement solutions that use behavioral analysis to detect unusual patterns or activities on endpoints. Analyze network traffic for anomalies that may indicate RAT activities.
  • Endpoint Detection and Response (EDR): deploy EDR solutions to enhance visibility into endpoint activities and enable faster detection and response to potential RAT infections.
  • Firewall Configuration: configure firewalls to restrict unnecessary outbound traffic, especially for non-standard ports associated with RATs.

A GAMER TURNED MALWARE DEVELOPER : DIVING INTO SILVER RAT AND IT’S SYRIAN ROOTS

EXECUTIVE SUMMARY

This report provides a glimpse into the evolving landscape of RAT development and malicious activities performed by threat actors working under name of ‘Anonymous Arabic’. Our team investigated the Silver RAT (written in C sharp) which has capabilities to bypass anti-viruses and covertly launch hidden applications, browsers, keyloggers, and other malicious activities. The developers operate on multiple hacker forums and social media platforms, showcasing an active and sophisticated presence, in addition to a Telegram channel offering a range of services including the distribution of cracked RATs, leaked databases, carding activities, and the sale of social media bots, which are employed to promote services by automatically engaging with and commenting on user content.

INTRODUCTION

Silver RAT v1.0 was observed in the wild during November 2023. The authors of Silver RAT have also developed another product called S500 RAT. While Silver RAT is currently Windows-based, recent announcements indicate that the developers are planning to launch a new version with the ability to generate both Windows and Android payloads. Silver RAT v1.0 comes with destructive features such as a keylogger, UAC bypass, data encryption using ransomware, and functions to destroy system restore points.

The developer of Silver RAT is, known as ‘noradlb1,’ and is active on prominent hacking forums like XSS, Darkforum, TurkHackTeam, and others, with an arguably respected reputation. The RAT first appeared on their Telegram channel and later on Turkhackteam and 1877 forums. Silver RAT was cracked and leaked on Telegram around October, 2023, and now users on Telegram and GitHub are sharing cracked versions of Silver RAT v1.0 to users without the means to purchase RATs (however there is evidence from user conversations that this may not be as effective as other well-known RATs like xworm).

While generating a payload using Silver RAT’s builder, threat actors can select various options with a payload size up to a maximum of 50kb. Once connected, the victim appears on the attacker controlled Silver RAT panel, which displays the logs from the victim based on the functionalities chosen. The threat actor can hide processes under false headings, and the final payload can be generated in a Windows executable file, delivered through various social engineering methods.

The announcement about the sale of Silver RAT 1.0 initially appeared on the TurkHackTeam forum and later surfaced on 1877 and other underground hacking forums.

Our team found that the threat actor also posted in a well-known Russian forum, selling Silver RAT v1.0.

Additionally, they created a website under an e-commerce domain to facilitate the sale of Silver RAT v1.0.

ASSESSMENT

The initial announcement regarding the release of Silver RAT V1.0 was made on October 19, 2022 on their Telegram channel. Subsequent to this, (November 19, 2022) the threat actor released the RAT on two hacker forums.

PANEL OVERVIEW

Silver RAT v1.0 written in C Sharp is a Window based RAT builder for windows systems, which has different features like Bypass AV, stealing browser cookies, keylogger, hidden browser, hidden RDP access and much more.

Our team have performed the analysis of the Silver RAT v1.0 builder in order to assess it’s capabilities: after executing, there is an initial prompt to request a port number on which Silver RAT will bind the IP, and port number for reverse shell.

This is the builder section of Silver RAT, where users will find numerous options. Some notable features include the ability to Bypass AV, conceal malicious processes by assigning custom process names, and specify the connection method. The user can choose between default connection settings by providing an IP for reverse connection or opt for a web HTML link.

Below is a list of the arguably most interesting functionalities of Silver RAT v1.0:

  • The attacker can utilize either an IP address with a specified port, or a webpage for command and control of the target system.
  • Windows defender exclusion function prevents detection after the program has been launched for the first time.
  • Attackers can configure this functionality to erase all system restore points. If the target attempts to turn off the system and run system restore, it will be ineffective.
  • This option can be configured to delay the execution of the payload. If the target runs the payload, it will not activate until the specified time has elapsed.
  • Hidden process and hidden installation, i.e. the capability to hide a process within the task manager. The attacker can provide a custom process name to hide the payload in a folder, which cannot be found even if the target tries to view hidden files or folders within Windows settings.
  • Bypassing Antivirus using FUD Crypters.

A point to note is that the payload size increases when users select more options, ranging from 40- 50KB.

In the execution process, the .Net executable payload can be delivered by using various social engineering tactics. Upon execution, an administrated permission prompt will appear, and it will run a CMD window that disappears in less than 2 seconds.

Following this, Silver RAT v1.0 establishes a connection, once connected the target will appear in the targets list.

ADMIN CONTROL PANEL

Upon successful connection, the attacker gains the ability to initiate various malicious activities on the target system, as seen in below snippet.

Beginning with the top option ‘Manager,’ the attacker can manage and control various aspects of the target system. This includes managing installed applications, navigating the file manager, modifying registry keys, checking startup items, and monitoring the performance of the target system.

Additionally, attackers can leverage other interesting malicious activities on target system such as:

Hidden Apps
– Attackers can control multiple applications on the client’s computer covertly, with various apps running concurrently.

Hidden Browsers
– Gives the ability to add client browsers to a hidden list.
– Enables the attacker and the victim to use the browser at the same time.

Hidden VNC
– Gives the attackers control of target system
– Attackers can control the client’s internet browsers.

The image below illustrates specific stealing capabilities of Silver RAT v1.0.

Additionally, an attacker can encrypt data on the victim’s computer using ransomware, delete data and browser cookies from the target computer remotely, propogate like worm through USB , and erase system restore points.

BUILDER CODE REVIEW

After analyzing the program file of the builder, there are some flags that warrant discussion:

The below highlights boolean flags like ‘RuntimeProcessCheckerProtection’, ‘RuntimeAntiDebugProtection’, ‘KillDebuggerProtection’, ‘KillMaliciousProcess’, ‘DetectDllInjection’, and ‘RunSingleThread’.

These flags are used to protect the RAT from various debugging techniques, as well as protecting the program from being analyzed. If such activity is detected, the anti-analysis code will terminate the program’s execution.

In the snippet below this list called ‘BadPList’ containing different strings related to programs used by malware analysts. Each string represents the name of a process or tool that the RAT considers potentially bad or associated with debugging and analysis activities.

EXTERNAL THREAT LANDSCAPE MANAGEMENT (ETLM)

Threat Actor Profile:
The Silver RAT developers have 2 different Telegram channels with 1k+ on one channel and 700+ users on another channel, indicating a high user engagement rate.

CYFIRMA researchers found out that the threat actor has been using a well-known Crypto wallet, employing different addresses for transactions, ranging from Bitcoin to Ethereum and USDT (Tether).

Their Bitcoin wallet appears to be empty, while their Ethereum wallet shows 8 transactions including 1 deposit and 7 transfers.

We note approximately 2,275.67 USD of transactions between December 24,2023 and December 25,2023 period, including potential cashing out activities.

During the analysis, we backtracked to the PayPal purchase option, and upon exiting the page, we obtained the Gmail address used by threat actor for PayPal account.

During our investigation, we discovered a Facebook account of a hacktivist group that supports the “Syrian Revolution”, with post engagement from a developer of Silver RAT based on multiple attribute matches. Reviewing the developer’s previous posts reveals a history of offering various first-person shooter (FPS) game hacks and mods.

Based on these observations, it can be ascertained with high confidence that the Silver RAT developer:

  • Began hacking as a teen
  • Is likely in his mid-twenties
  • Resides in Damascus, Syria

THREAT LANDSCAPE

A threat actor using the moniker ‘Dangerous silver,’ and another using ‘Monstermc’, serve as developers for S500 RAT and Silver RAT. They operate a Telegram channel offering malware-as-a-service, distributing cracked RATs from various developers, leaked databases, carding services, fake pages, and the sale of Twitter/Facebook bots. They have blog website named as ‘Anonymous Arabic’ that is moderated by 2 other individuals, as well as groups named as Monstermc and Syria Pirates.

Following the leak, Silver RAT v1.0 is freely available over Telegram, as well as some underground forums and Github, complete with full instructions on its malicious use.

The threat actor is actively sharing information on various social media platforms, as well as development platforms like GitHub, where the threat actors shared different red teaming methods and cracked malware.

The threat actor’s YouTube channel where they shared details about Silver RAT was banned by the platform, but a new (and still active) channel shares tutorials about their malicious tools.

The threat actor Pastebin profile shows they pasted source code of builders as well as some bypass tricks.

UNDERGROUND ACTIVITY MONITORING

We have discovered that the threat actor appears to have a good reputation on across various underground forums.

RECENT DEVELOPMENT

Silver RAT v1.0 generates a Windows executable, however Telegram chatter purports that the upcoming release of a new version of Silver RAT will be capable of generating payloads for both Android and Windows platforms.

MITRE MAPPING

Tactics Techniques
TA0002: Execution T1059: Command and Scripting Interpreter
T1053: Scheduled Task/Job
TA0003: Persistence T1053: Scheduled Task/Job
TA0004: Privilege Escalation T1055: Process Injection
T1053: Scheduled Task/Job
TA0005: Defense Evasion T1112: Modify Registry
T1497: Virtualization/Sandbox Evasion
T1055: Process Injection
T1027: Obfuscated Files or Information
TA0006: Credential Access T1056: Input Capture
T1539: Steal Web Cookie
T1552: Unsecured Credentials
T1528: Steal Application Access Token
TA0007: Discovery T1057: Process Discovery
T1497: Virtualization/Sandbox Evasion
T1083: File and Directory Discovery
T1082: System Information Discovery
TA0009: Collection T1056: Input Capture
TA0010: Exfiltration T1041: Exfiltration over C2 Channel
T1567: Exfiltration over Web Service

IOCs

No SHA256 Indicators Remarks
1 79a4605d24d32f992d8e144202e980bb6b52bf8c9925b1498a1da59e50ac51f9 Silver RAT v1.0 Builder
2 a9fa8e14080792b67a12f682a336c0ea9ff463bbcb27955644c6fcaf80023641 Silver RAT v1.0 Builder
3 7a9aeea5e65a0966894710c1d9191ba4cbd6415cba5b10b3b75091237a70a5b8 Silver RAT Payload
4 0ace7ae35b7b44a3ec64667983ff9106df688c24b52f8fcb25729c70a00cc319 Silver RAT Payload
5 3b06b4aab7f6f590aeac5afb33bbe2c36191aeee724ec82e2a9661e34679af0a Silver RAT Payload
6 27b781269be3b0d2f16689a17245d82210f39531e3bcb88684b03ae620ac5007 Silver RAT Payload
7 0ace7ae35b7b44a3ec64667983ff9106df688c24b52f8fcb25729c70a00cc319 Silver RAT Payload

CONCLUSION

The developer of Silver RAT intends to release new versions of RAT following the leak of v1.0, which rends it freely accessible for malicious purposes. The developer, operating under the name “Anonymous Arabic,” appears is supportive of Palestine based on their Telegram posts, and members associated with this group are active across various arenas, including social media, development platforms, underground forums, and Clearnet websites, suggesting their involvement in distributing various malware. It is crucial for organizations to enhance their defense mechanisms in response to this potential threat.

RECOMMENDATIONS

Strategic Recommendations:

  • Security Awareness Training: educate users about the risks of downloading and installing apps from untrusted sources. Teach them to recognize phishing attempts, suspicious links, and potentially harmful applications.
  • Regular Updates: enforce a policy of keeping devices and operating systems up to date with the latest security patches. Outdated systems can have vulnerabilities that RATs may exploit.
  • Data Encryption: encourage users to enable device encryption and use strong, unique passcodes or biometric authentication methods to protect their devices.

Management Recommendations

  • Incident Response Plan: develop and communicate an incident response plan that outlines steps to take if a device is compromised. This plan should include isolating the device, notifying relevant parties, and taking action to mitigate the breach.
  • User Support: provide users with a clear channel to report suspicious activity, unusual behavior, or potential security incidents. Ensure they understand the importance of reporting such incidents promptly.
  • Regular Backups: regularly back up your device’s data to a secure location. This helps mitigate the impact of data loss in case of a security incident.

Tactical Recommendations

  • App Review: regularly review the list of installed apps and remove any that are unused or suspicious. RATs often disguise themselves as legitimate apps.
  • Network Security: avoid using unsecured Wi-Fi networks, especially for sensitive transactions. Use a VPN when connected to public Wi-Fi to encrypt your internet traffic.
  • Behavioral Analysis: implement solutions that use behavioral analysis to detect unusual patterns or activities on endpoints. Analyze network traffic for anomalies that may indicate RAT activities.
  • Endpoint Detection and Response (EDR): deploy EDR solutions to enhance visibility into endpoint activities and enable faster detection and response to potential RAT infections.
  • Firewall Configuration: configure firewalls to restrict unnecessary outbound traffic, especially for non-standard ports associated with RATs.

Unknown Nation-Based Threat Actor Using Android RAT to Target Indian Defence Personnel

Unknown Nation-Based Threat Actor Using Android RAT to Target Indian Defence Personnel

Executive Summary

The CYFIRMA research team recently detected a malicious android APK targeting Indian Defence Personnel. Our research revealed that the attack has been active since July 2021.

The APK file in this case is a decoy copy of a promotion letter to the “Subs Naik” rank. Once the victim falls prey to this malicious APK, and upon installation, this app appears as an Adobe reader application icon (look-alike) on the device. Further research revealed that the threat actors were using a variant of publicly available Spymax RAT since its source code is already available on underground forums. Spymax offers different android package builds – and one of the builds has a web view feature that allows the threat actors to inject any web link into the web view module. After the successful installation of the generated APK, it takes the shape of an actual android app. In this occurrence, the threat actors injected a google drive link where-in the threat actor deployed a pdf file containing a list of Indian defense personnel who were awarded promotions to a higher rank.

The threat actors behind the attack are using strategic social engineering techniques, to deliver this and other malicious APK files through WhatsApp as a delivery mechanism. For more details on social engineering tactics, we recommend reading one of our research reports: (Advanced Social Engineering Attacks).

ETLM Attribution

Threat actors are luring Indian Defence Personnel with decoy promotion letters to install malicious android-based Spyware with the aim to exfiltrate confidential information from their devices. The malicious applications obtain several permissions to device resources like – access camera, audio, internet, Wi-Fi, and storage – access to any one of these can be dangerous and catastrophic for national security.

As the target is specifically the defense personnel and since the campaign has been running for quite some time, it is suspected that nation-state threat actor groups are behind the attack to exfiltrate sensitive information. At this moment and with the data analyzed, the CYFIRMA research team cannot attribute the current attack to a specific nation-state threat actor group. What we can infer is that the threat actors involved are less equipped and use easily available RAT. The social engineering techniques used to deliver the malicious APK seem not well-planned.

Analysis of the Sample

Below is a screenshot related to a WhatsApp chat that reveals how the threat actors have used social engineering techniques to deliver the malicious APK via WhatsApp as a delivery medium.

Upon installation of this malicious APK, it disguises itself as a PDF application and appears as a PDF icon on the device.

On clicking the App, it opens a google drive link using the web view module which leads to a letter related to the promotion of defense personnel in pdf format as shown below.

Code Review

CYFIRMA Research team performed a code review of the malicious APK file. Details as below.

Sample Details:
MD5: 8A5C06AE6FD206CEF418BE4B21180F41
SHA1: 54d4f70a9a1d2163d69159f796bb04ced2e68e77,

SHA256: f1fed8fe6c00d3924f65f76e246d1024e51acf096c4388ffdc618086474a2edc

We analyzed the malicious APK file and observed the following code in the “AndroidManifest.xml file.

The code above indicates that the malicious APK used to acquire many dangerous permissions and the permissions mentioned indicate that the malicious APK has the following capabilities:

The source code is highly obfuscated to evade detection and thwart the analysis process as shown in the code snippet.

The package is using com.acrobat.flyunwsaqdzzenrtssfurrxpmnfspvawaqgeppkyqpnlnrfzpo301 name to uniquely identify the app in the device. As part of making the app fully undetectable, the package name was also wrapped with a layer of encryption.

The threat actor has obfuscated class names to avoid detection from virus protection algorithms as observed in the screenshot above.

Below is the code snippet for controlling the camera application. The app allows threat actors to use front and back cameras to access the video feeds which can be used to carry out a breach of confidential visuals and video content at will.

This module allows the app to open a landing page that works as a web view.

The malicious app allows the threat actors to access the victim’s precise location. The logic defined below is used to access the location of the victim and allows threat actors to keep live track of the victim’s location.

Upon launching, this malicious file, opens a Google Drive URL “https[:]//drive[.]google[.]com/drive/folders/1a9kw9u_YGjBpgjoNd1FEWmEiwA-Gyyi0?usp=sharing” which is hardcoded in the app’s “strings.xml” file as shown above. Also, the string.xml mentioned above contains one IP address “5[.]189[.]136[.]230” which belongs to C2 Server using port number 7860.

Further as shown below, the IP is associated with other malicious APKs, HTML, and URLs.

The associated URLs have been used for malicious/phishing purposes in past and the associated communicating APK files are also malicious and detected as spyware by different security solutions.

Following are the hashes corresponding to the communicating files mentioned above:

  • 3abb8ccfe3333af5ea76017ffd75ebe542abdb954a58f110c9c7e833c2dfa8c4
  • 4b63fb26f5ef0792d0232cdcd2b1ac6bc8fed9c8247d124754dfa7930edf2f24
  • 5a8fab25ab66f06d8f78fd7abc72a564bf23a55848f0b276f411df22ee4cb6cc
  • 262fd1463ec69e228c9d1a46ef1a4fd41cf0ed529e394a042dac539b529df918
  • 1bef8c987402f52545624fff21009ff702e59d05c629ba52d53a7c1e96e57298
  • ebdc1cd4be98866b7735568094b287a0122bc6b276f77bc6dea8b476435c0cd1
  • a01635cb3bf070b036fd24833c3628b8f289d4175f1c7dddca56de4e412da63a

C&C Server:
5.189.136.230
Following are the names, types, detections, and dates corresponding to the associated communicating files with the IP address “5[.]189[.]136[.]230”. It seems the files are part of the same campaign active since Jan-2022.

Below is the network traffic captured during the opening of the google drive link.

From captured traffic, we observed the C2 server being active and exfiltrating the data from mobile. Below is captured raw data in HEX value:

Mitre ATT&CK Tactics and Techniques

Sr.no Tactics Technique ID Technique Name
1 Initial Delivery T1476 Deliver Malicious Apps via Other Means
2 Initial Access T1268 Conduct social engineering
3 Initial Access T1444 Masquerade as a Legitimate Application
4 Execution T1436 Commonly Used Port
5 Collections T1433, T1412, T1432, T1429, T1512, T1533, T1430 Access Call Log, Capture SMS, Messages Access, Contact List, Capture Audio, Capture Camera, Data from Local System & Location Tracking

List of IOCs

Sr.no Tactics Technique ID Technique Name
1 67dcf9607cdc1966d64aadb3c25d6a08
4dfa877800d0ce233e75b8fc2e41e89a
dea441cfaae7a9f86080f3cf34c7f47b
bee5884c10f50f094a810cb592fe83db
93d3b042e9121a871e8a023f05d3477b
de8b063d405ee5bf715fc1053e0a2a03
bf2187a03fdc0e7c8999d2e1cdeae6d4
MD5 Samples
2 5.189.136.230 IP C&C Server

Phishing Attacks Leverage Deceptive Website Builders to Target AT&T Users

Phishing Attacks Leverage Deceptive Website Builders to Target AT&T Users

Executive Summary

The CYFIRMA research team observed threat actors using free website builders to clone and deceive popular brand websites for phishing attacks. This research paper will detail how phishing attacks targeting AT&T users leverage free website builders like Google Sites and Weebly Sites.

Attack Type: Impersonating legitimate websites, credential harvesting, and account takeover

Introduction

Recently, a data breach at Australia’s second-largest wireless carrier led to 9.8 million customers’ personal information being exposed. Similarly, the breach at a Malaysian Mobile Virtual Network Operator (MVNO), accounting for the exposure of 1.2 million subscribers’ data, and allegedly perpetrated by the financially motivated Desorden group, indicated the focus of threat actors towards the telecom industry. Research on ongoing attacks on the telecom industry led us to phishing attacks targeting AT&T customers where the threat actors were observed to be using free and popular website builders like Google Sites and Weebly Sites.

In contrast to the large number of cyberattacks that use dark web infrastructure to carry out malicious activities, threat actors are increasingly utilizing web- based application platforms to ensure that phishing emails reach the potential victim’s inbox. In this regard, websites impersonating trusted brands are created for both fraud and credential theft attacks. Google Sites and Weebly Sites are among the two free website builders that make it easy to create authentic- looking websites. As is the norm among threat actors, these free website builders significantly contribute to phishing attacks by facilitating the impersonation of popular brand pages, to exploit free services for malicious purposes. During our investigation, we discovered numerous AT&T phishing websites built with Google Sites and Weebly Sites.

AT&T Phishing Sites – Weebly & Google Sites

Free online services being used for malicious activities is old news, but it is important to keep an eye on these services to understand the evolving threat landscape. We noticed several phishing URLs that utilized iPhone 14 Pro as lures using sites. google.com. This URL and the examination of recent data breaches in the telecom industry led us to an ongoing phishing attack targeting AT&T users using Weebly and Google Sites website builders. Based on the available data, usage of Weebly in phishing attacks has increased significantly compared to Google Sites.

Creating websites on Weebly and Google Sites is a no-brainer activity, and the drafted site will be up and running as soon as it’s published while using reliable infrastructure provided by well-known brands. Additionally, these free services also provide the option to customize the URLs that threat actors can use to mislead legitimate users to malicious sites.

AT&T Phishing Attacks Powered by sites. google.com
In our research, we observed numerous phishing sites created using free services that were targeting AT&T users. Investigation of AT&T phishing sites that leveraged Google Sites led us to another free service provider, Weebly.

AT&T Phishing Attacks Powered by Weebly
We noticed Weebly’s free service has been used to attack AT&T users for the last five months starting from the last week of May 2022. The highest activity in this regard was seen last month as part of one of the observed campaigns.

We observed a total of 850 suspicious (malicious or phishing) URLs associated with Weebly out of which 304 active (Response code 200) URLs are linked to AT&T and 200+ link to inactive sites.

Why Telecom?

Cyberattacks targeted at the telecom industry have a variety of objectives. While some attacks primarily pose a threat to the targeted businesses and their finances, others may also have repercussions for the clients or users of the targeted businesses. Cyberattacks that target telecom services pose a particularly serious risk because the unavailability of these fundamental services could affect business production and other crucial sectors, such as emergency services, energy supply, and the health sector, in addition to being inconvenient for individual users.

Hackers find self-service options and telecom customer accounts to be appealing targets. As with access to a customer’s webmail, self-service portal credentials can be sold to other hackers and used as a starting point for additional criminal activity. Hackers, for example, can order a new sim card using a compromised self-service system while posing as the customer, allowing them to hijack the customer’s mobile number and use it for other criminal activities. The volume of customer data stored in telecom companies turns them into the go-to targets for cyber-attacks.

External Threat Landscape Management

To increase their chances of successfully tricking security solutions, threat actors are utilizing every free tool and service they can find, with compromised websites and phony login pages for well-known brands leading the way. In the observable campaign, free website builders Weebly and Google Sites are used as ammunition to target the telecom giant AT&T. The majority of websites hosted on free website builders are themed around pornography, phishing, dating, and marketplaces that are becoming alternatives to underground sites. According to a recent report on phishing statistics, four out of five phishing attacks make use of web services, tools, and hosting that is not immediately interpreted as malicious. This has significant ramifications for security software that checks the validity of email links by following them to determine whether they are malicious or not.

After banking and finance, telecommunications was the sector that phishing campaigns targeted the most. Herein, 23% of detected phishing attacks were caused by telecom incidents. According to the data that is currently available, 4 out of every 5 phishing sites were set up on infrastructure that did not require any financial investment on the part of threat actors, such as free services and tools or compromised websites.

Impact of Phishing Attack

The following are the possible impact of a phishing attack:

Exfiltration of data : Stolen credentials make it possible to sign into victims’ accounts directly, which enables the exfiltration of data from the victims’ inboxes and accounts, including emails, attachments, and data.

Access to people of interest : Threat actors use compromised accounts to pose as individuals of interest to facilitate communication to gather the necessary intelligence.

Persistent data collection : Threat actors can setup forwarding rules from victim inboxes to actor-controlled dead drop accounts, giving them long- term access to the data they have collected.

Data leak: To increase their credibility with victims, hackers post compromised information on their own or other websites. Such information may be related to employees, organizations, email addresses, customers, or suppliers leading to financial and reputational damage to the compromised organization.

Expanded cyber-attack: Stolen account-based information may be sold on dark web marketplaces, enabling more extensive cyberattacks on compromised accounts.

Fortinet Authentication Bypass Vulnerability Exploited by Threat Actors

Fortinet Authentication Bypass Vulnerability Exploited by Threat Actors

EXECUTIVE SUMMARY

A critical Authentication Bypass Vulnerability in Fortinet Appliances tracked as CVE-2022-40684 has been discovered to be actively exploited in the wild. An authentication bypass using an alternate path or channel vulnerability [CWE-288] in FortiOS, FortiProxy, and FortiSwitchManager could allow an unauthenticated attacker to perform administrative interface operations using specially crafted HTTP or HTTPS requests. Fortinet recently issued a PSIRT Advisory regarding CVE-2022-40684, which includes urgent mitigation guidance, upgrades, workarounds for customers, and recommended next steps.
The CYFIRMA research team conducted a detailed analysis of the vulnerability from the point of view of the exploit, as well as observed the underground forum discussion on vulnerability, and threat actor association.

KEY TAKEAWAYS

  • Successful exploitation of the vulnerability could allow the remote attacker to bypass security and gain privileged access to execute unauthorized code or commands.
  • Darkweb forum discussions indicated ransomware groups’ attention on the CVE. Also, casting light on threat actors’ interest in understanding what has changed in the patch at the time of the fix so that they can exploit older versions.
  • Our intelligence research community observed Iranian and Chinese threat actors abusing the vulnerabilities of Fortinet products. The suspected threat actors are US17IRGCorp aka APT34, HAFNIUM, and its affiliates in the ongoing campaign “درب عقب ” translating to “Tailgate”.
  • Method Discussed by Hackers and their Interest: Exploiting weakness in the systems, Man-in-the-Middle (MitM) attacks, potential ransomware attacks, and lateral movement into the organization network.

VULNERABILITY AT A GLANCE

Authentication Bypass Vulnerability in Fortigate

  • CVE-2022-40684
  • CVSS Score: 9.8
  • CYFIRMA Risk Rating: Critical
  • Exploit Detail: Link

Description:
An authentication bypass via an alternate path or channel [CWE-288] in Fortinet FortiOS versions 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy versions 7.2.0 and 7.0.0 through 7.0.6, and FortiSwitchManager versions 7.2.0 and 7.0.0 enables an unauthenticated attacker to perform administrative interface operations via specially crafted HTTP or HTTPS requests.

Impact:
Successful exploitation of the vulnerability could allow the remote attacker to bypass security and gain privileged access to execute unauthorized code or commands

Affected Version:

Security Indicators

  • Is there already an exploit tool to attack this vulnerability? Yes
  • Has this vulnerability already been used in an attack? Yes
  • Are hackers discussing this vulnerability in the Deep/Dark Web? Yes
  • What is the attack complexity level? Low
  • According to CISA’s Known Exploited Vulnerabilities Catalog, threat actors have historically exploited Fortinet vulnerabilities to obtain initial access and move laterally within a victim’s environment. We assess that threat actors will continue to exploit this vulnerability in the near future to obtain initial access resulting in access to sensitive information, such as the appliance’s configuration file, due to the ease of exploitation, the potential for payload delivery, and the presence of affected Fortinet units within enterprise environments.

Mitigation
Fortinet recently issued a PSIRT Advisory regarding CVE-2022-40684, which includes urgent mitigation guidance, upgrades, workarounds for customers, and recommended next steps. Please refer to the following link for the mitigation here.

EXPLOITING CVE-2022-40684
The CYFIRMA research team analyzed different methods of exploiting CVE-2022-40684.

Manually adding SSH keys to check if the target is vulnerable to exploit

Step 1: Add the SSH key to the vulnerable target using the add_key method.

Step 2: Log in to the vulnerable target using credentials saved from step 1 to access the Fortinet Administrative Interface

Step 3: After credentials are validated, the user will have access to Fortinet Administrative Interface. On the Logs page, we can validate that a new user has been added to the Interface with admin privilege access.

Automate with FFUF Scanner: Open-source exploit using FFUF Scanner
ffuf -w “host_list.txt:URL” -u “https://URL/api/v2/cmdb/system/admin/admin” -X PUT -H ‘User-Agent: Report Runner’ -H ‘Content-Type: application/json’ -H ‘Forwarded: for=”[127.0.0.1]:8000″;by=”[127.0.0.1]:9000″;’ -d ‘{“ssh-public-key1”: “cyfirma”}’ -mr “SSH” -r

Nuclei – Open-source exploit using Nuclei Template

Darkweb Observations
Our research team observed conversations around CVE-2022-40684 exploits in a famous underground forum. Bassterlord is a well-known name in the underground who had associations with LockBit, REvil, Avaddon, and RansomExx groups as a partner. The presence of Bassterlord in the Fortinet CVE conversation is an indication of ransomware groups’ attention on the CVE. The conversation also puts light on threat actors’ interest in understanding what has changed in the patch at the time of the fix so that they can exploit older versions.

Vulnerable Targets

OSNIT tools assist in identifying possible vulnerable targets.
OSINT Serach 1 – Google Dorks – intext:”Please Login” inurl:”/remote/login” – This dorks give more than 100+ vulnerable fortinet pages.


OSINT Serach 2 – raw_data.web.paths:”/api/v2/cmdb/system/admin”
In our OSINT research, we have found 200+ vulnerable IPs associated with CVE-2022-40684.


OSINT Search 3 – Shodan search returned 171k Fortinet FortiGate systems spread across the globe connected to the internet.


In another OSINT search, we found that around 16k Fortinet FortiGate units were vulnerable to 10 different vulnerabilities across the globe other than CVE-2022-40684.

MOST AFFECTED COUNTRIES

SUSPECTED THREAT ACTORS

Upon performing an analysis of the available internet-exposed Fortinet units through OSINT search passing through DeCYFIR attribution to threat actors, we have observed that Iranian and Chinese threat actors have already exploited Fortinet IPs for malicious activities.

Campaign Attribution

Our intelligence community research observed campaign “ درب عقب” translating to “Tailgate” suspected to be launched on 15 September 2022 targeting weak/vulnerable Fortinet products, which could be exploited using existing exploits by US17IRGCorp aka APT34 and its affiliates.

As part of the campaign, we also noticed Persian cybercriminals potentially colluding with Chinese groups and Russian cybercriminals. From a strategic viewpoint on the changing geopolitical scenarios from external threat landscape management, Iran and China are forming strategic relationships with Russia at all levels and have supported Russia in the ongoing Ukraine conflict.

Target Industries

Target Geographies

Motivation
Exfiltration of sensitive information for financial gains, and credential stealing for gaining elevated access to cause operational disruption and reputational damage.

INDICATORS OF COMPROMISE

CYFIRMA would like to highlight the potential risk and indicators observed which may be leveraged by nation-state threat actors to exploit the vulnerability and gain a foothold to exfiltrate sensitive information from the target organizations.

RECOMMENDED ACTIONS

  • Build and undertake safeguarding measures by monitoring/blocking the IOCs and strengthening defences based on the intelligence provided.
  • Integrate CTI feeds with existing SIEM solutions to allow faster detection and alerting of malicious activities. Enrich threat intelligence by combining local monitoring, and internal & external feeds.
  • Deploy an advanced Endpoint Detection and Response (EDR) engine as part of the organization’s layered security strategy.
  • Patch/upgrade all applications/software regularly with the latest versions when available on priority.
  • Configure network defence systems such as intrusion detection system (IDS), and intrusion prevention systems (IPS) for real-time alerts.
  • The use of CAPTCHA (Completely Automated Public Turing test to tell Computers and Humans Apart) is effective against automated bots.
  • Restrict the logins to a specific range of IP Addresses.
  • Implement Multi-Factor Authentication (MFA) to reduce the risk of potential data breaches.
  • Make the root user inaccessible via SSH by editing the sshd_config file and implementing the ‘DenyUsers root’ and ‘PermitRootLogin no’ options.
  • Move to a non-standard port for SSH instead of using the default port 22 and edit the new port line in the sshd_config file.
  • Move to a non-standard port for RDP instead of using the default port 3389.

Infostealer Prynt Malware a Deep Dive into Its Process Injection Technique

Infostealer Prynt Malware a Deep Dive into Its Process Injection Technique

EXECUTIVE SUMMARY

CYFIRMA Research team has seen an uptick in threat actor orchestrated cyber campaigns aimed at stealing confidential and sensitive information. Infostealers like “Prynt” are used to exfiltrate information as the first step leading into orchestration of sophisticated attacks which may include deployment of ransomwares.

In this report, we analyse infostealer “Prynt” which is often configured by the threat actors via a “builder” so that they can subsequently configure the malware easily. It may be noted that “Prynt” Stealer builder is used to create infostealer “Prynt” with a hidden backdoor functionality.

CYFIRMA Research team analysed an infostealer “Prynt” sample which was gathered from a public repository. The sample was found to be written in C/C++ and is a 32-bit console binary. Infostealer “Prynt” has the capability to steal system information from infected systems, which includes files from the targeted directories and credentials from web browsers.

In our analysis, we focus on the process injection technique leverage by the infostealer “Prynt” utilizing reverse engineering & memory forensics analysis, which involves injecting the infostealer “Prynt’s” malicious code into the legitimate AppLaunch.exe (Microsoft .NET ClickOnce Launch Utility) process; and later exits after injecting the code. Running the malicious code in the context of another process may allow access to the process’s resources like – memory, system, and network.

The infostealer “Prynt” has been observed to have the following capabilities:

  • Gathering System Information.
  • Enumerating through files and processes.
  • Hiding the processes.
  • Injecting the code into PE files.
  • Registry changes.
  • Network communication through backdoor.
  • Capture screenshots.

ETLM Attribution

Infostealer “Prynt” is a commodity malware and leveraged as part of Malware-as-a-Service (MaaS). In this case malware authors went ahead and wrapped up stealer with a backdoor even for their paying customers. The backdoor sends copies of victims’ exfiltrated data gathered by other threat actors to a private Telegram chat monitored by the Prynt Stealer developers.

Supported by our analysis, the infostealer “Prynt” evades detection using the process injection technique by injecting itself into a legitimate “AppLaunch.exe” process – which is a common technique used by malware. The Prynt Stealer builder used to create the infostealer “Prynt” has been derived from open-source code bases like AsyncRAT and StormKitty (an information stealer).

Such infostealer campaigns are used to exfiltrate confidential and sensitive information to resell for financial gains in dedicated forums and Telegram channels. Threat actors are also known to use various ways to distribute stealers, including – social engineering, phishing emails, compromised websites, and embedded images.

As part of CYFIRMA tracked campaigns observed in the last 6 month, we can see infostealer “Prynt” has been leveraged by threat actors originating from the following geographical regions (Confidence Level: Low):

Threat Actor Demographics

Geographies Targeted Include (40+ Nations)

Industries Targeted Include

What’s Seen Brewing in Underground Forums

CYFIRMA researchers while monitoring cybercriminal activities in the underground forums, noticed that a new version of the Prynt Advanced Stealer 4.2.2 is available on underground forums.

Static Analysis

File: Prynt.Exe
Subsystem: Console
MD5: Bcd1e2dc3740bf5eb616e8249d1e2d9c
SHA1: 230f401260805638aa683280b86af2231cf73f93
SHA256: 04b528fa40c858bf8d49e1c78f0d9dd7e3bc824d79614244f5f104baae628f8f File Type: PE32 Executable (Console) Intel 80386, For MS Windows

File Type

File type of the Prynt.exe is a PE32 executable.

Packing

As can be observed, Prynt.exe is not packed.

As can be observed, Prynt.exe is written in C/C++.

Reverse Engineering

Infostealer “Prynt” process injects malicious code into the legitimate AppLaunch process to hide its activity. Threat actors deploy the infostealer Prynt.exe in the victim’s environment with an aim to steal confidential and sensitive information.

Here we have analyzed the infostealer Prynt.exe on x64 Windows system.

Process injection is a technique which injects malicious code into another running process and the targeted process executes the malicious code. This technique conceals malicious behaviour of their code and may bypass firewalls and other process-specific security mechanisms. Prynt.exe authors used a combination of VirtualAlloc/VirtualAllocEx, VirtualProtect, and WriteProcessMemory APIs to inject code into a remote process.

The infostealer “Prynt” first creates an AppLaunch process to host the malicious code in suspended mode:

AppLaunch process in suspended mode as seen from Task Manager: –

Prynt process creates multiple threads via CreateRemoteThreadEx for establishing foundations for process injection and code execution. CreateRemoteThreadEx also creates a thread that runs in the virtual address space of another process.

VirtualProtect API used to change the permissions on a page in memory through PAGE_EXECUTE_READWRITE parameter: –

VirtualProtect API changes are noticed as RWX permissions at 0x4AB000 in the Memory tab of the Prynt process: –

Prynt process allocates new memory using VirtualAlloc API: –

Prynt is seen allocating new memory in a remote AppLaunch process using VirtualAllocEx API: –

Handles tab of the Prynt process showing the process handle value 0x33c90 associated with the AppLaunch: –

WriteProcessMemory API is used to write data into the allocated space :-

AppLaunch process was injected at 0x400000 address with PAGE_EXECUTE_READWRITE (RWX) permission:-

Prynt process calling SetThreadContext API to point the entry point to a new code section and run the injected code:-

Prynt resumes the suspended thread by calling NtResumeThread API to take the AppLaunch process out of the suspended state: –

Memory Forensics

Operating System: Windows 7 Service Pack 1 [SP1] (64-Bit)
A memory dump (RAM dump) win7sp1x64.raw was captured for memory analysis using WinPmem on x64 Windows 7 SP1 system.

Process Injection

Injected Process: AppLaunch.exe
Volatility plugin malfind was run against win7sp1x64.raw without specifying the -p option, it automatically identified the suspicious memory regions of all the processes running on the system based on the memory content and the VAD characteristics.

The dlllist plugin, which gets module information from the PEB, shows the full path to AppLaunch.exe (pid 215000).

The malfind plugin identified the suspicious memory protection at the address (0x400000) after running against the process AppLaunch.exe (pid 215000).

The vadinfo plugin confirms the suspicious memory region protection at the address (0x400000).

Regular loaded libraries in the address space of a process are of type _MMVAD (Vad) or _MMVAD_LONG (VadL) which represent memory-mapped files.

VadS (_MMVAD_SHORT) tag looks suspicious as it represents dynamically allocated memory pages created via VirtualAllocEx /WriteProcessMemory. But VirtualAllocEx API cannot allocate memory with PAGE_EXECUTE_WRITECOPY protection since the executable is loaded into memory with PAGE_EXECUTE_WRITECOPY protection by the operating system.

The volshell plugin’s db command dumps the content of the memory address 0x400000.

The AppLaunch process (pid 215000) was injected by allocating memory with the PAGE_EXECUTE_READWRITE permission.

Trends Observed

Infostealer “Prynt” has been quietly used alongside RedLine stealer by the same set of Threat Actors to diversify their payloads. RedLine stealer has received a lot of criticism on the underground forums for being overpriced, so infostealer “Prynt” offers a cheaper alternative, which appears to be tested by Threat Actors. With time, if infostealer “Prynt” proves its utility during campaign deployment, we are likely to see a wider spread footprint, but at the moment it is yet to become a mainstream choice.

As shown in below graph, the infostealer “Prynt” stealer and RedLine stealer have common IP addresses in use – providing credibility to our analysis and hypothesis that slowly threat actors are shifting their focus towards infostealer “Prynt”.

Conclusion

Information stealers are prominent malware in the current threat landscape and provide an opportunity for cyber-criminals to steal confidential and system information which can be leveraged to conduct next stage of cyber- attacks like ransomware. Information stealers include backdoor programs, which open specific ports of the computer so the attacker can take control of the system.

Infostealer “Prynt” is configured through a builder and has a secret backdoor as part of the code which is further available in other variants. Infostealer “Prynt” uses process injection as a defence evasion technique and entails running malicious code within the address space of the legitimate process.

Organizations are advised to ensure that unnecessary ports and services are closed to prevent the risk of discovery and potential exploitation.

List of IOCs

Sr No. Indicator Type Remarks
1 BCD1E2DC3740BF5EB616E8249D1E2D9C MD5 Prynt.exe

MITRE ATT&CKTM Techniques Detection

Sr No. Tactic Technique
1 Execution (TA0002) T1106: Native API
2 Privilege Escalation (TA0004) T1055: Process Injection
3 Defense Evasion (TA0005) T1059: Hijack Execution Flow
T1036: Masquerading
T1112: Modify Registry
4 Discovery (TA0007) T1082: System Information Discovery
T1012: Query Registry
5 Command and Control (TA0011) T1102: Web Service

Advanced Social Engineering Attacks Deconstructed

Advanced Social Engineering Attacks Deconstructed

EXECUTIVE SUMMARY

The team at CYFIRMA has analyzed and researched social engineering attacks in depth. The research paper reports techniques used by various threat actors to initiate the first stage of a deadly cyber-attack. The paper discusses the psychological role, and how it becomes an important part of the social engineering attack. Further, we discuss a few social engineering attacks which led to successful compromises. This paper will expose the mindset that drives threat actors to plan and execute social engineering attacks on various occasions.

ABSTRACT

CYFIRMA will break down each part of social engineering attacks from the attacker’s perspective as part of this research. We will discuss and study the attacker’s approach to social engineering attacks as per long and short-term goals. This should help users to gain clear awareness of social engineering attacks that are planned by the threat actors behind closed doors. All the bigger and smaller cyber-attacks are led by social engineering. Plucking the first step of a cyber-attack from the root level would help cyberspace to be more secure. This paper will have a detection section to help the cyber community identify potential attacks before they could even start.

INTRODUCTION

Social engineering attacks psychologically manipulate the human mind and make them do what they are not supposed to do within its full active sense. Social engineering happens in our day-to-day lives. One can use social engineering within their friend’s circle to make things work out in their favour, during street shopping one can use social engineering to bargain the price of a product or as a student, try to convince a teacher after failing to complete his homework on time. In information security, social engineering has a different meaning. In cyber security, social engineering is considered a cyber-attack.

Social engineering is the most used cyber-attack by threat actors in current times. Ransomware groups, Advance persistence teams, scammers, and other threat actors use social engineering before conducting advanced technical attacks. The bigger the target, the more sophisticated the art of deception can get on the cyber playground. The success of cyber-attacks depends upon the social engineering manoeuvre of threat actors. As the internet and its users grow across the world, cyber security firms have also captured massive coverage to spread awareness among common users, government entities, and private organizations about potential cyber-attacks. Though their target could be anyone depending on their interest, for a successful attack, attackers must indirectly fight with cyber security firms who frequently dismantle the latter’s tactics and techniques by releasing cyber security updates. With the help of these updates on the internet, users have evolved to intercept common social engineering attacks they face or potentially might face. However, threat actors have not given up on their vicious intention to accomplish their aim. They are frequently creating and inventing new social engineering attacks to exploit unintended loose ends of the human brain. They constantly change their social engineering attacks by leveraging geopolitical events, religious issues, war, social issues, data leaks, pandemics, etc. Social engineering attacks are always there in the arsenal of threat actors to make victims fall into their malicious cyber trap. It is extensively used for pushing the victims to interact with malicious files or malicious uniformed resource locator [URL] and to fetch critical information by engaging with the victim via e-mail, chatting, or phone call. Social engineering attack plays a more important role when threat actors are not technically or resourcefully advanced.

SOCIAL ENGINEERING METHODS

Social engineering is an important attack for threat actors to create a base for actual advance technical attacks. The attacks can be planned into three parts. These methods depend upon the threat actor’s long-term and short- term aims, whether their malicious intention could be achieved through one- time information, or they want to keep information flowing throughout the month or a year. Below we discuss various types of social engineering attacks.

STRATEGIC ATTACK

This is a highly sophisticated and complicated attack where the threat actor perfectly maintains a disguised or fake identity to keep engagement active with the victim. The attack is performed with the aim of a long-term goal. They operate as a spy but virtually. If this attack is successful, then it could benefit the threat actor in fetching the required basic information and help the threat actor to drop their malicious content with not many hurdles.

One of the benefits of a Strategic attack is if threat actors fail in the first attempt, then they will come out learning more about the victim such as his/her likes and dislikes which will help the threat actor to craft a second attempt with a more accurate strategy with high chances of a successful attack.

Not all threat actors are advanced, so many attackers rely on social engineering attacks with strategic approaches. It’s not always that threat actors can bypass all the technical challenges they face. Sometimes they must pull their social engineering skills to avoid detection by making the victim disable anti-viruses or maybe sometimes threat actors need to make the victim interact with complicated technical tasks to execute the malicious file successfully. Successful Strategic Attacks always make sure the victim is ready to hear the threat actor’s commands and follow them.

TACTICAL ATTACK

This attack is based on clickbait and is technically advanced enough to make sure the victim must interact very less with malicious links or files. This attack usually takes leverage of geopolitical events, social issues, religious issues, war, politics, and other issues or contexts which instantly trigger the human mind to react to it. The attack is usually conducted on mass targets with the same social engineering attack. However, with time, approaches may change. In many cases, it is found that threat actors used the same social engineering attack on various targets and then suddenly shifted to a new issue after coming to the notice of cyber security firms. The tactical attack is always aimed at a quick compromise of the victim’s device.

LATERAL MOVEMENT ATTACK

This attack follows a “successful breach” into the victim’s device. The security community must have read and heard about “threat actors moving laterally”. These attacks come under the very same lateral movement attack. During the attacks, the art of social engineering becomes easy. However, they avoid instant attacks on victims connected to the compromised user. They wait and monitor the compromised victim’s activity for a few days and in some cases a year or months. After they finish collecting information, they monitor to find out which social media or chatting messenger the compromised victim is NOT using frequently. After the confirmation and burning of the victim’s valuables, they conduct lateral movement attacks using the already cooked-up genuine profile of the victim. This way, threat actors don’t have to put extra effort into perfect deception mode, providing an extra edge for social engineering attacks to drop malicious links or files.

THE PSYCHOLOGY BEHIND SOCIAL ENGINEERING

This is one of the most important aspects of social engineering attacks. After intense reconnaissance and search, the threat actor uses the accumulated data to find the state of mind that the victim is in. The data is used for analyzing the victim’s character, nature, behavior & mental status. Accumulated data helps threat actors to know the psychological status of the human mind, it helps them with low-level or medium-level confirmation of the victim’s interaction with malicious content. During the initial stage of many attacks using accumulated data, threat actors are somewhat sure of compromising the victim even before they execute a social engineering attack.

In many cases, actors have even compromised the victim who was already alerted to being targeted. They pushed victims to interact with malicious content – a specially crafted social engineering attack – to make the victim feel that the malicious channel is safe to use for online communication. However, the application was wrapped up with malware. Threat actors found loose ends in human minds and successfully exploited the state of alertness (or lack thereof) of the victim. This is only possible when threat actors know about the victim’s state of mind.

STATISTICS

CYFIRMA research team reviewed 100 cyber-attacks by various prominent threat actors to detect the type of social engineering attack. Statistics indicate that out of 100 attacks in the last 18 months, 13 attacks were using strategic social engineering attacks and 61 were tactical attacks, the remaining 26 were under other attacks such as web attacks. Listed below are some notable examples.

UBER ATTACK

In one of the recently reported attacks by various media outlets and security firms, a hacker used a tactical social engineering attack to get an MFA approved by Uber’s employees. The hacker had stolen log files purchased from the dark web market that contained the credentials of two employees who were working at Uber. The log file contained credentials of Google, Facebook, Twitter, Uber, Instagram, slack, and many more internet platforms. The hacker logged in to one of Uber’s internal sub-domains, then kept on sending a push notification, hoping to get approval on MFA. However, when it didn’t work, the hacker impersonated the IT guy and convinced the victim to approve. After the fact, the hacker opened doors for random users to communicate with him, and he shared his experience and process that he chose to compromise Uber. However, a bunch of information must have given him the confidence of pulling this menace with a pinch of social engineering attack to take this cyber-attack to a whole new level.

He triggered the victim’s mind with an unexpected request which could only be possible if the Uber IT team would have reached him in real. The victim had no idea of his credentials leaking to a third person and the attacker knew it. So, the threat actor moved tactically and didn’t give enough time for Uber employees to think and consider it could be social engineering, the signature of a cyber-attack.

ATTACK BY KIMSUKY

Kimsuky is an advanced persistent threat group based in North Korea. They are known for launching attacks on the South Korean government and UN officials. In the month of August Kimsuky launched a spear phishing campaign backed by a strategic social engineering attack. The threat actor impersonated a Korean government official and requested consultation on the report related to the “Situation in Korean Peninsula”. When the victim agrees to follow up on the consultation request then the threat actor reverts to email with a malicious file. If the victim denies the request, then the threat actor replies with no attachments, which also, hints at attempting the attack again at a later date.

Translation: We will make it a hassle and we will bless you.” We will get back to you later.

I appreciate it.

Translation: Thank you for your over-acceptance of the Advisory, Advisory Letter Transmission Drip LI

This unique social engineering attack gives a sort of confirmation to the threat actor about whether the potential victim is going to interact with a malicious file or not. Such a social engineering approach will also limit the spread of malware which will reduce the chances of the malicious file being detected or coming under the radar of an anti-virus company.

ATTACK BY TA453

CYFIRMA noticed another unique social engineering play by Iranian APT TA453 who understood the utility of social engineering attacks in the well-planned cyber-attack. In fresh attacks, TA453 implemented a strategic social engineering attack against the target with the profession of medical research. More than one disguised identity as officials from foreign policy research institutions was created and added to be part of a group discussion via email. They sent a well-crafted email discussing the relationship between Iran and Israel. This was a strategic attack, so, dropping off malicious links straight to the victim wasn’t the plan, they intended to keep the victim engaged in conversation and leverage the context to drop credential harvesting links. The threat actor replied within the same group via another disguised identity to make the victim understand the gravity of the topic and how important it is to them.

This attack had lots of resources put on the job. Considering the effort and resources it reflects that the target was a high-profile individual. The threat actor created an environment to control the whole conversation and psychologically tried to make the victim feel that his views are very important and that he should express his thoughts via responding to the emails. Even though the topic chosen against the victim was medical research, the background didn’t have convincing power. Choosing a topic related to medical research could have backfired as one must have an equal level of knowledge to keep conversational engagement active. So, the threat actor tried to leverage the always contentious geopolitical and diplomatic relations to bring victims to the point where they could share links or files.

SOCIAL ENGINEERING DEPENDENCY ON ADVANCED TECHNICAL ATTACK

In some events, threat actors finalize social engineering attacks by first considering advanced technical attacks. They plan social engineering attacks on the basis of advanced technical attack options available to them. Assume a scenario where threat actors have access to “open redirection” vulnerability in a reputed media house’s website. The victim is a high-profile individual from a government entity or a reputed multibillion/million-dollar company. Then threat actors could decide to take a disguised identity of a journalist and through social engineering attack, they can deliver the malicious file or link using open redirection vulnerability. Displayed below is a captured HTTP request as a proof of concept from the Break the security vulnerability-lab reproducing an open redirection bug that points to a malicious link.

In the past, Microsoft has warned its readers about open redirection vulnerabilities being abused for delivering malicious files and redirecting users to phishing pages. Big firms like Facebook, Google, and Microsoft reward well for finding the OR vulnerability in their web applications. In recent attacks, OR vulnerability in American Express was abused by threat actors to deliver the phishing page.

Open redirection is a highly destructive vulnerability when it comes to delivering a malicious file or link.

DETECTION

Detection of social engineering attacks can reduce the number of successful cyber-attacks in its initial stage. Following are a few points that we can keep in mind to dismantle any cyber-attack in the future:

  • Always be alert when any unknown user tries to reach different communications points. Also, verify if the unknown user has taken the name of a person known to you as a reference to start the conversation.
  • Be very sure before trusting any mail or message that arrived related to any ongoing issue like the pandemic.
  • Analyze on your own the number of important files you carry being an internet user and what pieces of information have the potential to attract a cyber thief. Stay alert according to the outcome of this analysis.
  • Conduct regular VAPT sessions to get rid of vulnerabilities like OR that could be leveraged by threat actors to deliver malware or infect users or employees.
  • Always confirm before clicking on the file that was shared by connections on social media or emails received from contacts after a long-time gap.
  • Cross-check be fore engaging further with the user who is prompting, again and again, to click or visit any link.
  • Always be alert when the user asks to open any link or file through a WhatsApp call. Chances are high that the received WhatsApp calls could be from a virtual number, as threat actors always avoid using any real SIM.
  • Always cross-check via call or any other mode of reliable communication before opening any file that is shared by employees such as IT personnel or HR.

EXTERNAL THREAT LANDSCAPE MANAGEMENT ATTRIBUTION

In the past, wars used to be fought with bombs and missiles. However, with the advancement of technology and rapid digitalization, most wars are now being launched in the cyberspace. For instance, the ongoing Russia-Ukraine escalation witnessed a destructive cyber-attack preceding the actual real- world attack by Russian ground forces. The Ukrainian cyber assets too were deployed to geolocate the Russian defense personnel posted on the war field. Ukrainian cyber attackers used social engineering tactics as the first base of their attack, so as to facilitate targeted missile attacks on the Russians. Human error has always been highlighted as the weakest link in the security chain of any organization – it is this link which the evolved TTPs of social engineering uses to launch massive offensives in the war front.

Cyber-attacks have effectively evolved into warfare, war crimes, bank robbery, personal damage to an individual, and are bringing successful ventures to dust. Many real-world crimes are now replaced with equally destructive and far-reaching cyber-attacks, with social engineering serving as the instigator of these attacks.

With increasing complexity and guile, the modern-day social engineering attacks are leaving the cyber security community in shock that attackers can go to any extent to compromise victims. The recent Uber attack is one of the big examples – of attackers going to great lengths to fool potential victims. As the threat of cyber-attack is increasing day by day, even social engineering attacks will take different shapes which depends upon the creative mind of the attacker and their ability to escalate events to ensure maximum damage. Herein, the detection of this attack has the potential to dismantle cyber- attacks in their initial stage if rightly followed up.

CONCLUSION

Social engineering attacks are the base of the most advanced cyber-attacks, which are tough to avoid for anyone who has open communication lines such as email, messenger, social media, and many more. The threat actors are always trying to stay ahead of cyber defenders, cyber security firms and are always dodging defensive walls created by awareness on latest social engineering tactics used. In most cases, it is always the human presence of mind that can prevent the first stage of a cyber-attack. And likewise, in most cases it is due to human negligence that threat actors can perform successful social engineering attacks. Following up on the detections mentioned here-in could stop many cyber-attacks.

Thousands of TP-Link Routers Vulnerable, Can be Exploited by Multiple Hackers

Thousands of TP-Link Routers Vulnerable, Can be Exploited by Multiple Hackers

EXECUTIVE SUMMARY

As per CYFIRMA’s latest research report, thousands of TP-Link routers being used globally, are still vulnerable and could be exploited by multiple threat actor groups and cybercriminals from China, Russia, and Iran. Attackers can collaborate on exploiting TP-Link routers using the Remote Code Execution vulnerability (CVE-2022-30075, CVSS Score: 8.8) and credential leaks that are available for sale in the Russian forums on the dark web.
From an External Threat Landscape Management (ETLM) analogy, the vulnerable TP-Link routers could also be used by threat actor groups and cybercriminals to “launch cyberattacks, expanding the attack surface to the target organization, and geopolitically motivated cyberwarfare for mutual interest.”

INTRODUCTION

TP-Link Technologies Co., Ltd. often shortened to TP-Link, is a global manufacturer of computer networking products based in Hong Kong and Shenzhen, China.

TP-Link routers provide wireless internet access to multiple devices in your home, and organizations. TP-Link has ADSL modem routers and VDSL modem routers.

CYFIRMA researchers have observed, as per the sample analyzed, thousands of TP-Link routers are still being used, which are vulnerable and could be exploited by cybercriminals.

Fig: Global Deployment Landscape (August 2022, OSINT)

Observations in the Underground Forums

In the sample analysed, CYFIRMA researchers have observed multiple instances of hackers looking to collaborate on exploiting TP-Link using the remote code execution vulnerability (CVE-2022-30075) globally.

Fig: Screenshots from Underground Forums

In the Russian forums on the dark web, we have observed leaked credentials of TP-Link products available for sale. These can be leveraged by hackers to gain access to the devices and further exploit the path of attack to target an organization’s environment.

About the Remote Code Execution Vulnerability CVE-2022-30075

About 2 months back, a critical remote code execution vulnerability impacted the TP-Link Router AX50 firmware 210730 and older versions. The import of a malicious backup file via web interface identified as CVE-2022-30075. An attacker could exploit the vulnerability and carry out a remote code execution attack caused by a flaw in the backup and restore functionality.

Details of the vulnerability are as follows:
CVE No: CVE-2022-30075
CVSS Score: 8.8
Exploits: Link (June 2022)
Potential TTPs based on MITRE ATT&CK Framework

Sr. No Tactics Techniques
1 TA0004: Privilege Escalation T1068: Exploitation for Privilege Escalation

Source: NVD, GitHub

Advisory Alerts

Following are the advisories released by various enforcement agencies about the vulnerability and the software:

  • On 13 June 2022, CISA published the vulnerability with no CVSS score assigned. Source: CISA
  • On 22 June 2022, Sing CERT published the vulnerability under the category of Other Vulnerabilities along with their CVSS Score: 8.8 which is critical. Source: SingCERT
  • On 01 September 2022, CERT-IN published an advisory about TP-Link routers vulnerable with severity rating critical and could be exploited by arbitrary code execution on the targeted system. Source: CERT-In

Research & Analysis

CYFIRMA researchers have observed in the sample analysed, multiple open ports which seem to be in use for TP-Link routers. These open ports could act as the initial access vectors for cybercriminals.

Geographical Spread Of Number Of Devices

Fig: Top 10 nations using TP-Link Products (as per the sample of 280,000+ devices analysed)

Attribution & Correlation

Multiple hacker groups could potentially exploit the vulnerability in these devices, although any specific cybercriminal group exploiting these routers cannot be isolated at this stage.

As in the past 2 years due to the pandemic, organizations have had to support their workforce working from home to support conducting business globally. This has led to TP-Link routers being in demand for the employees to stay connected and carry out their day-to-day operations. However, the vulnerabilities identified in the TP-Link routers have not been patched in many cases, thus leaving several devices exposed.

We have reasons to believe that – Chinese threat groups such as Hafnium and its affiliates, Iranian Groups such as Charming Kitten as well as multiple Russian threat actor groups – Fancy Bear, Cozy Bear, FIN11, and TA505 could potentially exploit vulnerabilities in these devices to fulfill their motives (which may include specific geo-political considerations).

In drawing a parallel with indicators CYFIRMA research team has been observing since August 2021, multiple Russian threat actor groups –  Fancy Bear, Cozy Bear, FIN11, and TA505 – were observed launching a cyber-attack campaign known as Привет бойцы aka Hello Fighters, exploiting 1512 of a specific and popular brand of routers. Industries targeted by the campaign included – Chemical & Large Manufacturing, Fertilizer, Automobiles & Components, Electronic Product Equipment, Healthcare, Shipping & Transportation, and Polymer & Fibre.  Geographies targeted included – France, Germany, Ukraine, Japan, Indonesia, the UK, India, the USA, Latvia, Taiwan, and many others.

External Threat Landscape Management

From an External Threat Landscape Management (ETLM) perspective, cybercriminals from countries that may not have a cordial relationship with other nations could use the vulnerable TP-Link routers to launch a cyber-attack on organizations that have a footprint on such vulnerable devices, or possibly for conducting geopolitically motivated cyber warfare.

The interest shown by Chinese and Russian-speaking state-sponsored threat actor groups, coupled with the huge landscape of vulnerable router implementations observed in countries like Australia; easily presents an opportunity for cybercriminals and threat actor groups to exploit such vulnerable routers – thereby expanding their attack footprint of targeting organizations from within and beyond their traditional known set of target nations.

Conclusion

It is paramount to patch the vulnerable software of the TP-Link routers to the latest version. Organizations need to adopt an ETLM-powered risk-based approach to cybersecurity decision-making to minimize possible exposures and external threats coming their way. Based on these and other indicators, we suspect an uptick in cyberattacks from various nation-state threat actors on critical infrastructure, state entities, and defence organizations. Open vulnerabilities and ports in such devices will only compound the negative impact on targeted organizations and their nation’s economic prowess.

Erbium Stealer Malware Report

Erbium Stealer Malware Report

Executive Summary

The Erbium malware is an information-stealer/ info stealer, which is distributed as Malware-as- a-Service (MaaS). CYFIRMA research team observed this malware binary in Aug-2022 while carrying out threat hunting activities. The team has also observed the stealer malware being advertised on Russian-speaking hacker forums.

The malware sample we have analyzed is a 32-bit executable binary. It contains obfuscated contents to evade detection by security products and firewalls. The malicious executable decrypts the obfuscated contents by using XORing logic after which it drops the 32-bit Erbium stealer DLL binary in the %temp% location and loads that dropped file in the current process by calling LoadLibraryA API. The dropped DLL files establish a connection to the Erbium stealer C2 server. Erbium malware establishes the connection to Discord’s Content Delivery Network (CDN) servers. Discord is a chat program that enables real-time communication between users through the internet and is being abused by threat actors to deliver malware. Info stealer malware developers sell these types of malware in underground forums and sell the harvest details in underground forums as well as criminal marketplaces. Ransomware affiliates or other threat actors purchase such details and then use these valid credentials, VPN, etc. as initial access to compromise the organization.

The malware [ErbiumStealer] has the following capabilities:

  • Ability to enumerate drives.
  • Ability to enumerate paths, files, and folders.
  • Capability to load other libraries, processes, and DLLs in memory.
  • Ability to Gather System Information.
  • Network communication capability.
  • Collecting user credentials, such as passwords, from a range of popular chat and email programs, as well as web browsers.
  • Ability to obtain information from various installed applications.
  • Ability to obtain cryptocurrency wallet information [log-in credentials and stored funds].
  • Ability to collect data of Authentication (2FA) and password-managing software.

External Threat Landscape Management (ETLM) Attribution

Recently CYFIRMA’s research team detected a new sample of Erbium stealer in wild. We observed one of the recent gaming campaigns where the threat actors lure gamers/players who want to acquire an unfair or prohibited edge over other players with the malicious binary posted on MediaFire [free service for file hosting]. Threat actors are spreading this malware using drive-by-download techniques and pretending as cracked software/game hacks. CYFIRMA’s research team on further monitoring activities associated with this campaign conclude that the identity of the threat actor is currently unknown for this Erbium stealer malware sample.

Erbium stealer malware is an information stealer, designed to gather sensitive data, including passwords for applications, credit card numbers, web browser cookies, auto-complete data, desktop files, machine data, installed software, crypto wallet stealing, etc, and send those details to the attacker command & control (C2) domain and can even download additional payloads from the C2 server.

From our analysis, we were able to find the following functionality available in the sample:

  • Erbium stealer malware is decrypting their malicious code using XOR logic. In that decryption, the malware author uses the keys depending on the obfuscated content length. The key starts at Hexadecimal value 31 and does increments by 1.
  • Erbium stealer malware author dropped DLL file [Erbium stealer] and it contains malicious functionality in the DLLMain function instead of Exported API.
  • Erbium stealer malware using the user-agent string: Erbium-UA-4ce7c27cb4be9d32e333bf032c88235a while establishing connection to Erbium control panel.
  • Erbium stealer malware establishes the connection to Discord’s Content Delivery Network (CDN) servers for download addition malware.
  • The malware targeted the below web browsers for harvesting information [passwords, cookies, and autofill information]
    • Cyberfox, Firefox, K-Meleon, BlackHawk, Pale Moon, Google Chrome, Thunderbird.
  • Erbium stealer malware steals Crypto Wallets’ information.
  • Further, the malware collects data from two-factor (2FA), multifactor authentication (MFA), and then password management software.

Erbium & Other Information Stealers Being Sold on the Underground Forums

In recent years information stealers are one of the most popular malware types being used in the wild. Once the info stealers threat actor obtains the harvested information from victim systems, the threat actors/malware authors will act as an initial access broker[IAB]. These threat actors advertised those obtained details on the dark web such as breached[.]to as well as Russian language underground forum of XSS and special-access forums, along with cybercriminals marketplaces. Threat actors such as ransomware affiliates or other threat actors purchase these details. If a threat actor purchases these details, they have access to a variety of resources, which could lead to data exfiltration, lateral movement, and deploy other malware such as ransomware, etc. Even though there are other approaches, such as exploiting flaws in publicly accessible internet services, the use of stealer malware can cut down on costs and operation time. This is because this malware can access a system with valid credentials without hiring pen-testers for gaining initial access to the organization’s network, which reduces the risk of being discovered by perimeter protection systems.

A wide range of threat actors leverages commodity information stealers which are distributed as MaaS model that will be sold on the underground forum for USD (prices) based on a subscription basis. For example, Red Line stealer’s prices range from USD 100 to USD 300.

Another type of information stealer is private information stealers, which are developed by threat actors themselves by using already available stealer code on open-source platforms or developing [creating brand-new] information stealers, whenever the commodity information stealers do not fulfill threat actors’ requirements. private information stealers will be shared among a small set of cyber-criminals only for reduces the chances of detection. For example, recently, CYFIRMA’s research team observed Whisper Stealer selling on the underground forum for USD100 for a 1-month subscription. This stealer is C# .Net-based malware having the capabilities are collected from browsers, user credentials, cookies, autofill fields, credit cards, wallets, etc.

Just like the information stealer developers who sell malware samples developed by them in the underground forums, the malware developers also post their advertisements in the underground forum for selling the obtained logs [from victims] to cybercriminals.

The Erbium stealer malware is being sold on one of the Russian hacker forums at 500 Rubles per week, 1500 Rubles per month, and 10,000 Rubles per year. The Erbium stealer team is running the technical support as well, indicating the malware team’s add-on functionality in the future.

Below are screenshots of reviews given by Erbium stealer malware subscribers. on the dark web. Based on these reviews/feedback the Erbium stealer malware author makes modifications in the next version of the malware.

ErbiumStealer Analysis

Basic Static Analysis of Erbium Stealer Malware:
Sample Details:
MD5: 1EF9C948E6045D8D8794A89CC9545B0F
SHA1: 7FA3530F3CC242075C04A43593FAEA2A8CE7A194
SHA256: 04642249B0AD41B1C6CC8862EC372C3B9B1E855D104A16A6A3FAE694CC23EC0C File Type: Windows PE
Architecture: 32 Bit
Subsystem: GUI

This malware was written in Microsoft Visual C++ programming language. This malware binary file’s size is 839227 (bytes). As shown in the below figure, this information stealer binary file has an entropy value is 6.71 and the code section was compressed by an unknown packer [custom].

Dynamic Analysis of Erbium Stealer Malware

Upon execution of this file, it decompressed the required dynamic DLL file names and file strings, URL, etc, which on execution are compressed by an unknown compressor[packer]. After that, it is dropping the information stealer [ErbiumStealer] DLL file in the temp location. Once the DLL file is dropped, that file is loaded in memory.

Files Added to Victim Host

C:\Users\manoj\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8LFDVDUP\clearkey[1].dll [md5:E53C97B18D69F5C6B7A854660E640700] ][product: Firefox] C:\Users\manoj\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BOT5RNIL\softokn3[1].dll [md5:3A59B504F6C41324B0D6CB6EDBE3AD61] ][product: Firefox] C:\Users\manoj\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IIXT9CHD\freebl3[1].dll [md5:ED6249F72BA742802B2FA3EF20900D18][product: Firefox] C:\Users\manoj\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IIXT9CHD\nss3[1].dll[md5:05ED4FFBF6B785750D2CDACCA9287F10][product: Firefox] C:\Users\manoj\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TABIZERP\mozglue[1].dll [md5:5D59E053D45049FFB8C6C08D8944E30C][product: Firefox] C:\Users\username\AppData\Local\Temp\hiokcmapbccbelnex.dll[6BC81580D318DC8EBF48B3555DD4C9D7]

Network Communication of Erbium Stealer

Once the Erbium Stealer file dropped the DLL file in the %temp% location, the dropped DLL [Erbium Stealer] file establishes a connection to the Panel: https[://] panel[.]erbium [.]ml, raw[.]githubusercontent[.]com and cdn[.]discordapp[.]com This malware tries to establish a connection to Discord’s Content Delivery Network (CDN) servers. While examining this malware code, this malicious file is not able to reach Discord’s Content Delivery Network (CDN) servers.

Recently CYFIRMA’ s research team published a research report on the malicious use of the discord app. You may visit the link: https://www.cyfirma.com/cyber-research-on-the-malicious-use-of-discord/, to get more in-depth knowledge that how threat actors use the application as a tool for malicious purposes:

Code Analysis of Erbium Stealer Malware

This information stealer malware is decrypting the obfuscated code by the XOR logic, to decode the encrypted code malware authors use the starting key 31[Hexadecimal value]. Depending upon the obfuscated content length the decryption keys are incrementing by 1. Before executing the malicious code this malware initially decrypts the Erbium Stealer panel URL.

Malware authors scatter the obfuscated contents as well as decryption logic code in the binary file to make it difficult for reverse engineering as well as writing the pattern [signature] to detect this malware by the antivirus engine.
It is followed by the malware getting the temp path by calling the GetTempPathA API then it creates a malicious DLL file [along with a legitimate DLL file] in the temp folder by calling the CreateFileA API.

Next, the malicious executable writes the malicious DLL binary file content from the buffer to the created DLL file by calling WriteFile API.

Once the malicious DLL file content has been written from the buffer to this file handle, the malware closes the handle and then decodes the required API function by executing above mentioned XOR logic. After that, this malicious DLL file loads into the address space of the calling process by calling LoadLibraryA API.

Basic Static analysis of dropped Erbium Stealer [DLL]

1st Stage Payload (Dropped)

Sample Details:
MD5: 6BC81580D318DC8EBF48B3555DD4C9D7
SHA1: DABCED5B9F1EF63EFF6B29152192DFA1F1499481
SHA256: E3DD6D5CA0C9A16D95E4C591B7BBAD40E3D4D78BCF29CE6D8EA80B263C67F1C5
File Type: Windows PE
Architecture: 32 Bit
Subsystem: dynamic-link-library

This malware sample was also compiled in Microsoft Visual programming language. This malware’s binary file size is 2825728 (bytes). As shown in the below figure, this DLL file has an entropy value is 6.85 and the code section was compressed by an unknown [custom] packer.

Code Analysis of Erbium Stealer Malware [DLL file]

Similar to file hash: 1EF9C948E6045D8D8794A89CC9545B0F this malicious file initially decrypts the required DLL files name, File contents, etc by the XOR logic. In this file, the decryption logic code also scatters to make it difficult and delay analysing the malicious code while doing reverse engineering.

This DLL file is stealer malware that targets victim stored browser history and steals browser information, passwords for applications, credit card numbers, web browser cookies, auto-complete data, desktop files, machine data, installed software, crypto wallet stealing, authentication-related software, and password managers, etc. The below figure is one part of the memory strings.

Erbium stealer malware steals passwords, cookies, and autofill information from the following web browsers as shown in the memory dump.

  • Cyberfox, Firefox, K-Meleon, BlackHawk, Pale Moon, Google Chrome, Thunderbird.

This malware also steals the data from the following crypto wallets:

This info stealer malware collects data from two-factor (2FA), multifactor authentication (MFA), and then password management software as well.

Extension ID Extension Name
bhghoamapcdpbohphigoooaddinpkbai Authenticator 2FA
gaedmjdfmmahhbjefcbgaolhhanlaolb Authy 2FA
oeljdldpnmdbchonielidgobddffflal EOS Authenticator
imloifkgjagghnncjkhggdhalmcnfklk Trezor Password Manager

After that this DLL file de-obfuscate the obfuscated content, this malware obtains the user agent string Erbium-UA- 4ce7c27cb4be9d32e333bf032c88235a.

Like file hash: 1EF9C948E6045D8D8794A89CC9545B0F, this DLL file is decrypting the ErbiumStealer panel URL. In this DLL file memory and creating socket connection then establishing a connection to panel[.]erbium[.]ml.

After that this DLL file creates a thread by calling CreateThread API and executing the malicious code on the thread.

These threat actors sent the data to the threat actor-controlled server by calling the send API.

The figure below shows the Erbium stealer panel.

The figure below shows the Erbium stealer Dashboard. This Dashboard shows how many logs so far received from the victim machine. also, this Erbium stealer Dashboard shows when the subscription user registered with this MaaS service, and which date the subscription is going to end.

Recently, CYFIRMA’s research team observed the Erbium stealer malware sample volume increased on the 2nd of September, in the wild.

Conclusion

“Erbium stealer” malware is spread through several tactics, including spear-phishing, malicious advertising, exploit kits, and malware loaders such as Smoke Loader, Private Loader, etc. The malware is associated with an unknown threat actor. This malware gathers sensitive data, including passwords for applications, credit card numbers, web browser cookies, auto-complete data, desktop files, machine data, installed software, etc. This malware also has crypto wallet stealing capabilities. Finally, information stealer malware developers sell the gathered details on the underground forum and cybercriminal marketplaces.

List of IOCs

Sr No. Indicator Type Remarks
1 1EF9C948E6045D8D8794A89CC9545B0F MD5 sample
2 6BC81580D318DC8EBF48B3555DD4C9D7 MD5 Erbium stealer DLL file
3 Erbium-UA-4ce7c27cb4be9d32e333bf032c88235a strings User-agent
4 Panel[.]erbium[.]ml Ip address Erbium stealer control panel
5 LrtmqR1muOHUwcTB strings File strings

MITRE ATT&CK Tactics and Techniques (Based on our analysis)

Sr No. Tactic Technique
1 Execution (TA0002) T1106: Native API
2 Defense Evasion (TA0005) T1027: Obfuscated Files or Information
3 Credential Access (TA0006) T1539: Steal Web Session Cookie
T1552.001: Unsecured Credentials: Credentials In Files
4 Discovery (TA0007) T1057: Process Discovery
T1082: System Information Discovery
5 Collection (TA0008) T1005: Data from Local System
6 Command and Control (TA0011) T1573: Encrypted Channel

FIN11 is Back : Impersonates Popular Video Conference Application

FIN11 is Back : Impersonates Popular Video Conference Application

CYFIRMA research team has observed impersonated web download pages of Zoom Application – which is the most downloaded application in recent years. We believe with moderate confidence that financially motivated FIN11 is behind this campaign. This threat actor is known for conducting a large-scale campaign using the impersonated web applications. In this case, FIN 11 was observed employing Zoom download pages to install Information Stealer (Vidar) targeting a large attack surface. We also observed an IP address that was earlier associated with AsyncRAT.

As per our VT research, the threat actor is using the disguised Zoom application which is used worldwide as a video conference solution indicating its focus to compromise a large number of systems across all operating systems using popular web applications. Russia-based threat actor FIN11 has lately been associated with CLOP ransomware for post-compromise ransomware deployment and data theft extortion. This association with the ransomware group increases the possibility of compromised systems becoming potential ransomware victims.

Several fake Zoom Video Communications download pages were discovered in the wild by the CYFIRMA research team. The Russian Federation is the registrant country for all the hosts. The CYFIRMA research team believes with moderate confidence that financially motivated FIN11 is behind this campaign involving fake download pages of popular web applications used worldwide.

Recently Identified Impersonated Web Application Download Page Links:

Below are the six impersonated web application download page links observed in the wild.

  • https://zoom-download[.]host – 92[.]53[.]96[.]41
  • https://zoom-download[.]space – 2a03:6f00:1::5c35:6029
  • https://zoom-download[.]fun – 92[.]53[.]96[.]41 pDNS 5.101.159[.]26; 87.236.16[.]226
  • https://zoomus[.]host – 92[.]53[.]113[.]155
  • https://zoomus[.]tech – 92[.]53[.]114[.]144
  • https://zoomus[.]website – 92[.]53[.]114[.]172

During our passive DNS research, we observed a vast number of impersonated web applications used in the past. Here are a few sample links:

  • www.user01zoom[.]website – 161[.]35[.]144[.]236
  • www.zo0m[.]info – 23[.]82[.]19[.]170
  • www.app-zoom[.]com – 198[.]54[.]116[.]220
  • zoom-meetings[.]net – 2607:f1c0:100f:f000::2ce
  • zoom-update[.]online – 192[.]254[.]185[.]80
  • zoomcyber[.]nl – 2606:4700:3030::6815:970
  • zoomclient[.]nl – 2606:4700:3037::ac43:a1d6
  • https://veehy[.]com/download-zoom/ – 5[.]39[.]216[.]178
  • http://videoconfer[.]xyz/ – 2606:4700:3035::ac43:87c5
  • zoom-download.huvpn[.]com–5[.]39[.]216[.]179
  • https://zoom[.]cheap/ – 2606:4700:3031::ac43:9b36

The Zoom Video Communication application as a phishing lure has been historically been used in large-scale campaigns. Since, the past two years, due to COVID-19, the world saw a significant increase in remote work, distance education, as well as the growth of online social relations. This led to high downloads of the Zoom application, and the trend has continued even after the pandemic. Zoom emerged as one of the most downloaded applications in the world year after year. For instance, with 300 million downloads, it was the most downloaded business app worldwide in 2021.

This popularity of Zoom has led to a renewed interest in employing it as phishing lures. In the reported incident, the threat actor employed the ‘Vidar’ information stealer embedded in the Zoom application to target broad attack surface across all industries and geographies.

External Threat Landscape Management

Since 2016, the Russian-based threat actor group FIN11 has been conducting widespread phishing campaigns. Initially, the threat group targeted financial, retail, and hospitality organizations. However, FIN11 later broadened its target to include a diverse set of sectors and geographic regions. During their phishing operations, threat actors cast a wide net and then select which victims to further exploit based on characteristics such as sector, geolocation, or perceived security posture. FIN11 has lately been associated with CLOP ransomware for post-compromise ransomware deployment and data theft extortion. Historically, the group has used services that provide anonymous domain registration, bulletproof hosting, code signing certificates, and private or semi-private malware; this strategy has been carried over into the ongoing campaign. In this incident, the threat actor used Vidar information stealer which is one of the prominent malware used by the group.

VT View on Malicious Content in the Host

The observed hosts (six links mentioned above) are pointed to malicious .exe, .rar, .apk, .lnk, and .pdf files indicating that a well-planned campaign by FIN 11, targets all operating systems to compromise a large attack surface.
Details are shared below.

https://zoom-download[.]host – 92[.]53[.]96[.]41

https://zoom-download[.]space – 2a03:6f00:1::5c35:6029

https://zoom-download[.]fun – 92[.]53[.]96[.]41 pDNS – 5[.]101[.]159[.]26; 87[.]236[.]16[.]226

https://zoomus.host – 92[.]53[.]113[.]155; https://zoomus.tech – 92[.]53[.]114[.]144

Impersonated Web Application View

Technical Analysis of Malicious Zoom URLs and Application Installed

Our research team analysed samples obtained from impersonated Zoom application download page. When clicked on the Download button, a malicious zip archive (8B07C2E1D99A6E43FB29C4B1A23BC743) downloaded which contains malicious “Zoom.exe” (19AFF3D6ED110A9037AFF507CAC4077F) file pretends to be a legitimate Zoom App having a Zoom icon. This file “Zoom.exe” is a 64-bit SFX [Microsoft Cabinet] file. Once extracted “Zoom.exe”, it contains two files: “ZOOMIN~1.EXE” (E710423F15A7C40DAC815C2D637CABD0) which is zoom application setup [legitimate], 2nd one is “Decoder.exe” (98C8C28B790BBCE2BC2F20CC8FF2BD8E) which is a malicious downloader.

Upon execution “Zoom.exe”, it drops “Decoder.exe” and “ZOOMIN~1.EXE” at location “C:\Users\Username\AppData\Local\Temp\IXP000.TMP\“. “Decoder.exe” (as mentioned above- 98C8C28B790BBCE2BC2F20CC8FF2BD8E), is a malicious downloader and “ZOOMIN~1.EXE” (as mentioned above-E710423F15A7C40DAC815C2D637CABD0) is a valid zoom installer which installs the legitimate zoom app on the system so that the execution does not create suspicion to the user.

Following is the process tree corresponding to the execution of malicious “Zoom.exe”:

The “Decoder.exe” when executed, establishes a connection with “hxxp[:]//193[.]106[.]191[.]223/CharSequence[.]TextPaint[.]setAlignment.module8_Rkbbnqyt[.]png” and downloads an encoded .PNG (21ABAC012CAA151DA5ED7C760198FAC6) file.

The IP address (193[.]106[.]191[.]223) is attributed to Russia and with AsyncRAT as shown below :

Later, “Decoder.exe” leverage PowerShell and execute Base64 encoded command as shown below:

“C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe” -enc UwB0AGEAcgB0AC0AUwBsAGUAZQBwACAALQBTAGUAYwBvAG4AZABzACAAMQAyAA==

The Base64 encoded command:

“UwB0AGEAcgB0AC0AUwBsAGUAZQBwACAALQBTAGUAYwBvAG4AZABzACAAMQAyAA==” when decoded equivalent to “S t a r t-Sleep-Seconds 12” might be used to become inactive for 12 seconds before next operation.

Further, it creates a child process with the name MSBuild.exe. The Microsoft Build Engine (MSBuild.exe) is a platform for building applications. This engine, which is also known as MSBuild, provides an XML schema for a project file that controls how the build platform processes and builds software. Visual Studio uses MSBuild, but MSBuild does not depend on Visual Studio. By invoking msbuild.exe on a project or solution file, we can orchestrate and build products in environments where Visual Studio is not installed. The malware authors earlier also in several instances abused the Microsoft Build Engine (MSBuild) to deploy remote access tools (RATs) and password-stealing malware.

The first stage (Decoder.exe) is a simple .NET downloader that will execute a second-stage payload in memory. The downloaded second-stage payload injects inside another process (MSBuild.exe).

The compromised MsBuild.exe make a connection with IP (116[.]202[.]179[.]139) and later download the zip file:

hxxp[:]//116[.]202[.]179[.]139/1547 hxxp[:]//116[.]202[.]179[.]139/9642742070[.]zip

At a different running instance, the MsBuild.exe make a connection with another IP (79[.]124[.]78[.]206) and further download a similar zip file:

hxxp://79[.]124[.]78[.]206/1547

hxxp://79[.]124[.]78[.]206/1317434164[.]zip

The downloaded zip file contains a series of DLL files:

“Freebl3.dll, mozglue.dll, msvcp140.dll, nss3.dll, softokn3.dll, vcruntime140.dll” In the past same set of DLLs were used by information Stealer malware – “Vidar”

The threat actor delivers malicious Zoom applications through phishing URLs masquerading as legitimate Zoom website as well app. Upon execution of malicious “Zoom.exe”, it drops “Decoder.exe” which acts as a downloader to download additional payloads (RAT and Information Stealer), and the legitimate zoom app setup “ZOOMIN~1.EXE” to install the zoom app. The injected MSBuild.exe also downloads DLLs related to information stealers Vidar.

Conclusion

Usage of impersonated popular web application download pages in cyber-attack is not a new tactic but using the most downloaded application like Zoom to distribute malware is a dangerous move by threat actors indicating their intention of compromising a large number of systems worldwide. Based on their association with the ransomware group it is an even more worrying factor that compromised systems can be potential ransomware victims.

MITRE ATT&CK:

Tactic Technique
TA0002: Execution T1059: Command and Scripting Interpreter
T1204: User Execution
TA0003: Persistence T1546: Event Triggered Execution
TA0004: Privilege Escalation T1546: Event Triggered Execution
TA0005: Defense Evasion T1553: Subvert Trust Controls
TA0006: Credential Access T1555: Credentials from Password Stores
T1539: Steal Web Session Cookie
T1552: Unsecured Credentials
TA0007: Discovery T1012: Query Registry
T1518: Software Discovery
T1082: System Information Discovery
TA0009: Collection T1114: Email Collection

IOCs

Type IOC
SHA256 b76cad93d0501d69746c84db3f7bfc158968900c2e472121019efe5d234ffa34
MD5 19AFF3D6ED110A9037AFF507CAC4077F
MD5 98C8C28B790BBCE2BC2F20CC8FF2BD8E
MD5 21ABAC012CAA151DA5ED7C760198FAC6
URL http://116.202.179.139
URL http://193.106.191.223
IP 92.53.96.41
IP 5.101.159.26
IP 87.236.16.226
IP 92.53.113.155
IP 92.53.114.144
IP 92.53.114.172
IP 79.124.78.206

 
 

HTML smuggling: A Stealthier Approach to Deliver Malware

HTML smuggling: A Stealthier Approach to Deliver Malware

HTML smuggling is a highly evasive technique that abuses legitimate HTML5 and JavaScript features to evade detection and deploy RATs, banking malware, and other malicious payloads. The nation-backed hacking groups and other cyber criminals are extensively using this technique to compromise governments, individuals, and organizations. For example, the NOBELIUM group – suspected to be associated with Russia – targeted government and diplomatic entities around the globe and used the HTML smuggling technique in past. Microsoft researchers have tracked the malicious HTML attachments used by the NOBELIUM group in one of the campaigns as EnvyScout and described it as a malicious dropper capable of de-obfuscating and writing a malicious ISO file to disk.

Key Takeaways

  • Nation-sponsored threat actors and cybercriminals are using techniques like HTML smuggling to evade detection and constantly shift their tactics towards stealthier techniques to increase their success rate.
  • HTML smuggling by phishing/spear-phishing email is used to deliver malicious payloads and is highly effective.
  • A testament to this is the increasing number of malware campaigns like QakBot and nation-backed groups like NOBELIUM a.k.a APT29, using this technique to deliver malicious payloads stealthily in the victim’s environment.
  • In the emerging threat landscape, to mitigate such risks, organizations must update their cybersecurity strategy, processes, procedures, and security programs to include defense and awareness against new techniques like HTML smuggling.

ETLM Attribution

HTML smuggling is a stealth technique adopted to deliver malicious payloads. Over decades threat actors have used Macros in Microsoft documents as their primary infection/attack vector. With Microsoft blocking VBA macros by default in Office applications, threat actors had to find alternative techniques to lure victims and deliver malicious payloads. For example, malware like Emotet, Icedid, and QakBot have already started using LNK files, ISO files, or IMG files and techniques like HTML smuggling to deliver malware. Even though such attacks and techniques are still evolving, researchers have observed a many-fold increase in their adoption since January 2022. Particularly nation-backed groups like NOBELIUM/APT29 along with prominent malware like Emotet, and QakBot are extensively utilizing the HTML smuggling technique to target individuals as well as organizations.
Generally, threat actors use HTML smuggling in one of the two ways:

  • The email body contains the link to the HTML smuggling page
  • The HTML smuggling crafted page itself is attached to the email as an attachment

There are several ways to write the same HTML smuggling logic in JavaScript code. Malware authors can use obfuscation and assemble the payload locally on the machine behind the firewall which makes this technique highly evasive. To mitigate such techniques, organizations need to adopt multi-layered and defense-indepth solutions in a collaborative manner.

Introduction

CYFIRMA has observed that the HTML smuggling technique has been used by threat actors like NOBELIUM to deliver malware like Mekotio, AsyncRAT, Trickbot, and recently QakBot. This malware is essentially used to gain control of victim machines, effectively deliver payloads, and execute ransomware attacks.

In HTML smuggling, the attacker uses a specially crafted HTML attachment that carries an encoded malicious script. When the victim opens this malicious HTML file in their web browser, the browser decodes this embedded malicious script which on execution further assembles the payload on the victim machine. The main advantage to threat actors is that instead of passing the payload over the network, the malicious payload assembles on the victim’s machine. This makes the technique highly evasive because it could bypass standard security controls like web proxies, firewalls, and email gateways. As the payload is only created when the malicious HTML file is loaded on the victim’s machine through the web browser, the security solutions only see HTML or JavaScript traffic which can be further obfuscated to evade detection.

Campaigns that have used HTML smuggling Technique:

  • Recently in July 2022, researchers observed a spam-email campaign used to deliver QakBot malware. In this campaign, the threat actors used the HTML smuggling technique to initiate a download of a password-protected malicious zip file on the victim’s machine. This attachment contains an ISO file that when mounted shows a shortcut file (.Ink) disguised as a PDF file. When the victim clicks on it, the system gets infected with the QakBot malware payload.
  • In February 2022, the Methods’ Group security and risk consultants detected and defended against a sophisticated HTML smuggling campaign targeting a major global UK public sector organisation as part of a larger campaign. A total of 77 HTML smuggling emails were detected.
  • In 2021, the NOBELIUM group used the HTML smuggling technique intensively post the SolarWinds attack. “Envy Scout” was the name given by Microsoft to this attack technique performed by NOBELIUM. The target was the Turkish and Iranian Embassies.
  • In the Duri malware campaign observed at the beginning of July 2020, researchers observed that the malware was being dropped using the HTML smuggling technique (previously delivered via Dropbox links).

How its works

HTML smuggling uses legitimate features of HTML5 and JavaScrip browsers – to create malicious binaries behind the firewall. Specifically, the technique leverages HTML5’s “download” attribute for anchor tags, as well as the creation and use of a JavaScript Blob to put together the malicious payload on the victim’s machine.

Anchor Tag <a>: The anchor tag <a> is a tag in HTML which defines a hyperlink and is used to link from one page to another resource like the script, other HTML pages, or downloadable files.
The most important attribute of the <a> element is the href attribute, which indicates the link’s destination.

For example:

When <a> is used with the “download” attribute, it can be used to provide links to a downloadable file.
For example:

As shown above, when the user clicks a link “Click_Here” in our case, the “download” attributes automatically download the file referenced in “href” tag. The above code instructs the browser to download “malicious_document.docx” from the specified location and save it onto the victim’s machine as “trusted_document.docx”.
The JavaScript code also has an equivalent to an HTML anchor tag and its download attribute as shown below.

JavaScript Blob

The use of JavaScript Blobs adds to the “smuggling” aspect of the HTML smuggling technique.

A Blob is an immutable object that represents raw data – simply a collection of bytes that holds the data stored in a file. The Blob data is stored in memory or file system depending upon the size of the Blob and the browser features. A Blob can be used anywhere, for instance, the Blob allows us to construct file-like objects on the user machine that can be passed as parameters to JavaScript APIs that expect URLs.

Therefore, instead of requiring that the web server provides a file, a Blob can be constructed locally using JavaScript. For example, a “malicious.exe” file hosted on a server is downloaded on the target system using HTML anchor tag and attribute download . In the same way, bytes of malicious.exe file or JavaScript Blob can be provided as input which can be downloaded and compiled on the user machine.

If the Blob is large in size, the Slice() function is used to divide a large payload and provide it as an input.

For example:

This will result in triggering the anchor’s click event, which in turn points to our blob to be downloaded as “maliciousfilename.doc”. These features are supported by all modern browsers. For older versions of Internet Explorer, msSave Blob method may be used to save a Blob object to disk.

In nutshell, a JavaScript Blob can store encoded data of a malicious file, which is later decoded and passed to a JavaScript API that expects a URL. So instead of providing a link that a user clicks manually to download such a file, it is automatically downloaded and created locally on the user’s machine using JavaScript code.

Complete Code Example

QakBot Malware Real Example using HTML smuggling Technique

CYFIRMA research team is continuously monitoring new tactics, techniques used by threat actors along with ongoing campaigns and methodology followed by cyber-criminals to compromise organizations and individuals. Recently, in July 2022, our research team monitored an operation consisting of a series of emails related to the QakBot malware campaign.

QakBot, is also known by the name QBot, QuackBot, and Pinkslipbot. The malware is an information stealer that has been active since 2008. For initial infection, QakBot malware uses spam or phishing email, and it continuously evolved its infection techniques ever since it was initially identified in the wild. In this campaign, the spam emails contain an “HTML” file as an attachment which used the “HTML smuggling” technique to deliver a password-protected zip file. “HTML smuggling” is one of the other possible attack vectors using HTML attachments and JavaScript. And this is what is being used in this campaign in combination with the QakBot malware in spam emails.

Below are the snapshots of the code available in the attached HTML file of spam email:

As shown below, the HTML file code has Base64 encoded malicious file code stored in the variable “text” which gets downloaded with the name “Report Jul 14 47787.zip”. There is also a series of functions defined at the end of the snapshot which is further obfuscated to implement the HTML smuggling technique and finally download the malicious zip archive with the name “Report Jul 14 47787.zip”.

Above is a code snippet corresponding to the HTML smuggling technique’s implementation extracted and attributed for better understanding. In this instance, first, a JavaScript Blob is created containing data corresponding to a malicious Base64 encoded malicious zip archive. Subsequently, Anchor and URL objects are created where the anchor object point to the URL object, after which a click to download the malicious zip file is automatically simulated.

The zip file is password protected – the password is stored in the HTML file.

As shown below, when the victim opens the file, the zip file automatically downloads to the user’s system through the HTML smuggling technique as depicted above. The password is also displayed to the user to extract the zip file. The zip file contains an ISO file with the same name as the zip file but with extension iso |(i.e., Report Jul 14 47787.iso).

Upon extraction of this .iso file we get four files: a .Ink file, a legitimate calc .exe, WindowsCodecs.dll, 7533.dll.

This shortcut (.Ink) file points to calc.exe as shown below

Upon clicking the shortcut file, the calc.exe gets executed and automatically loads the malicious WindowsCodecs DLL file. Here the malware authors are observed using another technique known as DLL sideloading to execute the malicious code. In this technique, malware author place legitimate applications (calc.exe) and malicious .dll (WindowsCodecs.dll) files together in the same folder. The malicious DLL name should be the same as the DLL or support file required by the legitimate application during execution so that the threat actor can leverage this technique and load the malicious DLL file. In this case, as specified calc.exe is a Microsoft legitimate application and WindowsCodecs.dll is the malicious DLL which disguised as a valid DLL, and loads by the calc.exe application, which further executes the final QakBot payload 7533.dll using windows living off the land binary regsvr32.exe as shown below.

Conclusion

Threat actors and malware authors are using techniques like HTML smuggling in their operations to deliver malware stealthily. The technique is more effective because it relies on the legitimate use of HTML and JavaScript as both are used to render valid webpages and as such their malicious users cannot be mitigated through conventional procedures. Groups like NOBELIUM and other cybercriminals continue to mature their tools and tactics, including new techniques like HTML smuggling to target governments, institutions, and organizations.

Mitigation against HTML smuggling attack

  • Regular Training and awareness among users regarding/ such stealthier techniques.
  • Consider monitoring files downloaded from the Internet, possibly by HTML smuggling, for suspicious activities. Data and events should not be viewed in isolation but as part of a chain of behaviour that could lead to other activities.
  • Manual review of suspicious email attachments.
  • Configure behaviour rules for HTML pages that obfuscate a JS script or decode base64 code.
  • Configure security products to block pages using JS or VBScript from automatically running a downloaded executable.

MITRE ATT&CK Tactics and Techniques (HTML smuggling)

Sr No. Tactic Technique
1 Initial Access (TA0001) T1566 Phishing
2 Execution (TA0002) T1204 User Execution
T1204.002 Malicious File
T1059.007 Java Script
T1027.006 Obfuscated Files or Information: HTML smuggling

 

AsyncRAT and MrAnonymous Backdoor Report

AsyncRAT and MrAnonymous Backdoor Report

Date: 14-July-22
Suspected Malware: AsyncRAT
Function: Malware RAT
Risk Score: 8
Confidence Level: High
Threat actor Associations: Unknown

Executive Summary :

AsyncRAT is a Remote Access Tool (RAT) created to remotely monitor and manipulate other computers through a secure encrypted connection. It is an open-source remote administration program and has capabilities like keylogging, remote desktop control, and many other functionalities. Threat actors also leverage this tool to mislead the victim’s host. CYFIRMA research team observed AsynRAT as part of our routine threat hunting activity. The threat actor deployed AsyncRAT along with mrAnonymous backdoor in the free services “duckdns[.]org” as a .PNG and .txt file format. Threat actors might be delivering this file to the user through spear-phishing techniques such as an essential scanned document attached to the email.

AsyncRAT Analysis:

Sample Details:
File Type: PNG
MD5: 01EBCFC538CA67B75F8F7AEA0A28A7F5
SHA1: 8396F31BB3A0432C2FD4A10AF2DD4BBCC12A3100
SHA256: 68B488B2860BC9749B0FD742A96D94D5DB901C13E6E5F9203D01B30FDF98C2E1

URL : hxxp://c2server[.]duckdns[.]org/

This domain hosts a free service that points a DNS (sub domains of duckdns.org) to an IP of the user’s choice. Unfortunately, phishers frequently misuse this service.

As shown in the below figure, threat actors leverage the base64 format to deliver this RAT to the user. This file name is doc.png

File Type: Windows PE
Architecture: 32 Bit
MD5: AF10973252E953258CF9CAE81C53A383
SHA1: B9730B3AECFAE5F054D1BA898D0777898D4F722E
SHA256: 68B488B2860BC9749B0FD742A96D94D5DB901C13E6E5F9203D01B30FDF98C2E1

After the base64 file is decoded we get this RAT file. This malware was written using the .net programing language. This malware binary shows a compile time of 10 May 2020.

As shown in the below figure, before executing this malicious code, the malware sleeps for 3000 milliseconds. This delays the malware execution or reverse engineering of these codes.

After that, the threat actor initializes all the configuration settings. The malware decrypts all the configurations by using a combination of UT8 decoding + AES algorithms.

All those configuration settings are hardcoded in the binary files in obfuscated format.

After executing the configuration settings methods, this RAT’s malware code decoded the configuration details. Those details are as follows.

Port:4444
Host name:”161[.]35[.]90[.]195″
Version:”0.5.7B”
Install:false
Mutex:AsyncMutex_6SI8OkPnk
pastebin:null
Anti:false
BDOS:false
GRoup:default
HWID:

After that, the malware code verifies whether this malware instance is already running or not by checking Mutex. If it is determined that the malware instance is running in the victim host already, it will terminate the execution. This RAT sample created mutex name is AsyncMutex_6SI8OkPnk.

Later, the RAT verifies anti-vm techniques by checking keywords like “Virtual” or ” VMware” or “VirtualBox”, and this malware is checking, if the malware is running under a debugger or not by CheckRemoteDebuggerPresent API, tries to detect sandbox by the handle of the SbieDll.dll, and also checks if this malware file is running in Windows XP machine. If any of the aforementioned conditions are detected then the malware will not execute.

Next, the RAT binary code is the first to be compared with the running process name and configuration setting in the binary code. If it is not the same setting in the binary code, the malware enumerates the running process from the victim system and kills that process if it is the same process name and file name. The threat actor is trying to install the latest version of the RAT binary by doing this check. The RAT also checks if this malicious process is running with administrator privilege. If yes, the malware code creates a scheduled task by creating a new process instance in the window hidden style so that the user is not able to notice this activity.

This malware code creates a run entry for persistence so that the RAT will run each time the victim boots up their system. This run entry is hardcoded in the binary reverse order.

Again, this file checks if a new version of the RAT file already exists, if yes, that file will be deleted and the malware sleeps for 1000 milliseconds. Next, it creates a .bat file in the %temp% location and then reads that bat file script to create a new process in the %appdata% location, which it is hardcoded in the binary code.

Finally, the RAT establishes the TCP connection to the below IP address: then waits for 5 milliseconds for the hacker to establish a connection/command for further operation. This code will run in the infinite time.

Ip address : 161[.]35[.]90[.]195[:]4444

MrAnonymous Backdoor Analysis :

As mentioned above, the other file “file.txt” is also hosted on “duckdns[.]org” and contains base64 encoded “MrAnonymous” backdoor as explained below.

Sample Details:
File Type: Text
MD5: DEFC2FC6E82D64D942BAE61899286586
SHA1: C3C96468538178A7A82F71B0C47DC5D365A3B576
SHA256: 625883104B31BDF3BE8A57D74BE8E60B20153F1B173ADF90B5F954CC09F2F38D

Similar to the file name, the Doc.png threat actor leverages base 64 encoding to deliver this file to the user. This file is showing as a normal text file but contains the base64 encoded data.

File Type: Windows PE
Architecture: 32 Bit
MD5: 438074A082AC9F9F946B62AE3D2D04FC
SHA1: 9DFB916846BB8EAFCF3402A8B7F90F35DD480550
SHA256: EEDA805C200E68733FC10726DA8B34B398D23AABF0D794A3FB0E82A0293549B2
Subsystem: Console

After decoding the base64 file, we arrive at this Backdoor file. This malware was written by the .net programing language. The malware binary shows a compile time of 12 June 2063.

The backdoor binary file has the version information but includes no company name. The size of this backdoor file is 7 kb.

As shown in the below figure, this backdoor file first establishes a TCP connection to IP address “161[.]35[.]90[.]195” and port number:4545. Next, it creates a stream object followed by the threat actor launching a new process with a hidden window and writing code/command in the created new process instance property of standard input to hide from the user as well as security products. It is indicated that the threat actor creates the customized backdoor binary and deploys it along with this RAT.

Conclusion:

AsyncRAT is spread through several tactics, including spear-phishing, malicious advertising, exploit kits, and others. This RAT is deployed in the free dynamic DNS hosted along with the mrAnonymous backdoor. The identity of the threat actor is unknown for this malware sample. AsyncRAT and mrAnonymous backdoor are delivered to the user in base64 encoded format. This RAT’s capabilities include anti-VM techniques, detecting sandbox, and debugger. This variant of the AsynRAT is trying to install a new version in the %appdata% location, create a scheduled task, and run an entry for persistence that finally culminates in the establishment of a TCP connection. The mrAnonymous backdoor also establishes the connection in the victim host and awaits commands/instructions from the threat actor for further operations.

List of IOCs:

Sr No. Indicator Type Remarks
1 01EBCFC538CA67B75F8F7AEA0A28A7F5 MD5 Doc.png
2 DEFC2FC6E82D64D942BAE61899286586 MD5 File.txt
3 AF10973252E953258CF9CAE81C53A383 MD5 AsyncRAT
4 438074A082AC9F9F946B62AE3D2D04FC MD5 mrAnonymous backdoor
5 161[.]35[.]90[.]195:4444 IPadress:port Communication
6 AsyncMutex_6SI8OkPnk String Mutex Name
7 mrAnonymous backdoor.pdb String pdb path

Mitre Attack Tactics and Techniques (Based on our analysis):

Sr No. Tactic Technique
1 Execution (TA0002) T1059.003: Command and Scripting Interpreter: Windows Command Shell
T1204.002 : User Execution: Malicious File
2 Persistence (TA0003) T1547.001:Boot or Logon Autostart Execution:Registry Run Keys / Startup Folder
T1053.005: Scheduled Task/Job:Scheduled Task
3 Defense Evasion (TA0005) T1070.004:Indicator Removal on Host: File Deletion
T1497:Virtualization/Sandbox Evasion
T1564.003:Hide Artifacts:Hidden Window
T1622:Debugger Evasion
4 Discovery (TA0007) T1083: Files & Directory Discovery
T1057: Process Discovery

 

 

 

NukeSped RAT Report

NukeSped RAT Report

Suspected Malware: NukeSped Malware
Function: RAT
Risk Score: 8
Confidence Level: High
Threat actor Associations: Lazarus Group (North Korea)

Executive Summary:

The NukeSped malware is a remote access trojan (RAT) and has been attributed to the threat actor Lazarus Group. The group has been active since 2009 and remain active in 2022 and continue its operation to target countries mainly in Asia Pacific Region. The malware sample we have analyzed is a Microsoft Word document containing malicious macro using windows WMI object and system binaries to drop 1st stage loader which further drops a 2nd stage payload to exfiltrate data, capturing keyboard and screenshots, and for downloading additional payloads on the victim machine. Upon opening the malicious document, the document gets saved in %TEMP folder with .htm extension that shows the decoy document in the Korean language to the victim, converts PNG file in %TEMP% folder to BMP file with .zip extension, executes it to create payload “AlgStore.exe” at “C:\Users\Public\Libraries\AlgStore.exe.” The malware strings and APIs are obfuscated and encoded with Base64 and RC4 encryption. The “AlgStore.exe” decrypt the embedded malicious executable in it and acts as a loader, decrypts decode, and loads the embedded 2nd stage payload in memory.

NukeSped RAT Analysis:

Sample Details:
File Type: MS Word Document
MD5: 71759cca8c700646b4976b19b9abd6fe
SHA256: 79e15cc02c6359cdb84885f6b84facbf91f6df1254551750dd642ff96998db35

Opening of malicious Document:

Upon opening the document, it displays the message in the Korean language to enable the macro to view the contents of the document.

By default, for security reasons, the macros are disabled from Microsoft and when we enable them, the macro will execute, and here, this document’s macro contains malicious code which we explain later in the document.

When we enable the macro, a message box will pop up having the message “This document is created in an earlier version of Microsoft Word” and when the user clicks on the “OK” button, the contents of the document shown to the user is written in Korean language.

Below is the process tree corresponding to the execution of the malicious document. The malware exploits the windows service “wmiprvse.exe”, which spawns the child “mshta.exe” system binary and further executes 1st stage payload “AlgStore.exe.” The first payload is used to run the command prompt to execute file “edg89C0.bat” and finally drop and execute the 2nd stage payload.

Malicious Macro Analysis:

The word document contains the malicious macro as shown below. We have extracted it and analyzed its functioning. The malicious document spread via phishing emails.

We extracted the macro from the malicious document and the code snippets for the same given below. The macro contains functions “Encode” and “Decode” corresponding to encode and decode text to and from base64. The macro starts with “MsgBoxOKCancel” which pops up a message box with the message “This Document is created in an earlier version of Microsoft Office Word”.

The macro also contains the function “Document_Open” which is executed when the victim opens the document. It used the WMI object, LoLBins like mshta to capture the active document name, separate the extension, and create a copy of the active document in HTML format with.htm extension (DocumentName.htm: MD5 hash: B94BFCB5E955DDC7490C5CEBB7E7FB83) and save it in %TEMP% folder by using code “ActiveDocument.SaveAs TempPath, wdFormatHTML, , , , , True.”  The strings (process name, path name, extension, lolbins names) are encoded with base64 in macro code.

Afterward, the function calls another function “show” defined in the macro which is used to protect the document so that no one changes it, and also a password “taifehjRTYB$%^45” is hardcoded in the code. Further, the function takes the image file (.PNG embedded in the document) having embedded zlib object and converts into BMP format by using the function “WIA_ConvertImage” and saving it in %TEMP% folder with extension .zip with name image003.zip.

Image003.zip MD5 Hash: B6FDF2AB9368C86D80879D289CD3DD67
The malware added the .zip extension to pretend to be a zip file and avoid detection. Afterward, the function used the WMI object “winmgmts://./root/cimv2:Win32_Process” and call system binary “mshta.exe” to execute bmp file that has an embedded file containing javascript code to drop a payload.

The “imageoo3.zip” (MD5 Hash: B6FDF2AB9368C86D80879D289CD3DD67) file contains embedded javascript code as shown below. The javas script drops “AlgStore.exe” executable in directory “C:\Users\Public\Libraries\AlgStore.exe” and later executes it by calling “Wscript.shell” object.

1st Stage Payload (Loader):

AlgStore.exe MD5 hash: 1BB267C96EC2925F6AE3716D831671CF
The payload “AlgStore.exe” has a malicious section “OTC” containing the other 2nd stage executable in an encrypted format.

The hard coded decryption key “!zGYX*ei$%HrW9#a” is present at the beginning of this malicious “OTC” section available within the “AlgStore.exe” to decrypt the embedded malicious executable in it as shown in the figure below. The “AlgStore.exe” acts as a loader, decrypts decode, and loads this embedded 2nd stage payload in memory. It then deletes itself subsequently.

Extracting the 2nd stage payload, embedded in “AlgStore.exe” in encrypted form.

2nd stage payload:

MD5 Hash: 0ECFA51CD4BF1A9841A07BDB5BFCD0AB

Gather system information

Mutex Creation:
Later, the 2nd stage payload creates a mutex with the name “Microsoft32.” It checks if it already exists to verify that only one instance of the malware is running. The strings and important API calls are encoded with base64 and RC4 encrypted. The 2nd stage payload is used to exfiltrate data and establish connections with C2 servers.

Network Communication:
Below are some of the URLs extracted from the memory dump of the payload:

  • /skin_img/skin[.]php
  • hxxp://snum[.]or[.]kr/skin_img/skin[.]php
  • hxxp://www.ddjm[.]co[.]kr/bbs/icon/skin/skin[.]php
  • snum[.]or[.]kr
  • hxxp://www[.]ddjm[.]co[.]kr/bbs/icon/skin/skin[.]php

New Variant:

The new variants of the NukeSped malware are exploiting the recently release Log4shell vulnerability in unpatched VM horizon servers since January 2022.
Following are the details related to a new variant of NukeSped Malware:
MD5 Hash: 945BE4D3D95C5C22E7D836B4641F4404

The compiler timestamp is modified, and from the debugger timestamp, we came to know that it is a new one and dated March 2022. The malware has the following capabilities:

  • Multiple Anti-debugging capabilities
  • Ability to enumerate drives
  • Ability to enumerate paths, files, and folders
  • Sandbox evasion capability
  • Capability to inject malicious code into a valid process
  • Capability to load other libraries, processes, and DLLs in memory
  • Capability to handle command-line arguments and command execution
  • Ability to Gather System Information
  • Network communication capability
  • Encryption/Decryption capability

The threat actor runs a power-shell script to exploit the Log4j vulnerability and installs the NukeSped on the victim machine. The malware is used for data exfiltration, keyboard and screen capturing, and downloads other malicious payloads on the system.

Conclusion:

“NukeSped” Malware is distributed through phishing or spear phishing emails having malicious attachments. The malware is associated with North Korean APT Group Lazarus which is known to target US, South Korea, Japan and Asia Pacific countries. The group is known to use new techniques, and exploit new vulnerabilities and custom tools to be more effective in its operation. The malicious Microsoft Word document is spread through phishing emails and uses the technique of BMP files embedded with malicious hta objects to drop its loader. The new variants of the NukeSped malware have been observed from Jan 2022 exploiting recently disclose vulnerability log4j on unpatched Vmware Horizon servers and used to exfiltrate data, capture keyboard and screen, and download other malicious payloads on the system.

List of IOCs:

Sr No. Indicator Type Remarks
1 71759cca8c700646b4976b19b9abd6fe MD5 Word Doc
2 B94BFCB5E955DDC7490C5CEBB7E7FB83 MD5 .htm file
3 B6FDF2AB9368C86D80879D289CD3DD67 MD5 Image003.zip
4 1BB267C96EC2925F6AE3716D831671CF MD5 AlgStore.exe
5 0ECFA51CD4BF1A9841A07BDB5BFCD0AB MD5 2nd stage payload: NukeSped
6 945BE4D3D95C5C22E7D836B4641F4404 MD5 New Variant
7 hxxp://snum[.]or[.]kr/skin_img/skin[.]php URL Communication
8 hxxp://www.ddjm[.]co[.]kr/bbs/icon/skin/skin[.]php URL Communication
9 hxxp://www[.]ddjm[.]co[.]kr/bbs/icon/skin/skin[.]php URL Communication
10 !zGYX*ei$%HrW9#a String Decryption Key
11 taifehjRTYB$%^45 String Hardcoded Password
12 Microsoft32 String Mutex Name
13 AlgStore.exe String Malicious file name
14 AlgStore.exe String Malicious file name
15 Image003.zip String Malicious file name

 

Mitre Attack Tactics and Techniques

Sr No. Tactic Technique
1 Initial Access (TA0001) T1566 Phishing
2 Discovery (TA0007) T1082 System Information Discovery
T1083 File and Directory Discovery
3 Execution (TA0002) T1204.002 Malicious File
T1059.001 Power Shell
T1059.003 Windows Command Shell
T1059.007 Java Script
4 Defense Evasion (TA0005) T1070.004 File Deletion
T1027 Obfuscated Files or Information
5 Discovery (TA0007) T1083 Files & Directory Discovery
T1057 Process Discovery
T1082 System Information Discovery
6 Collection (TA0009) T1005 Data from Local System
T1056.001 Keylogging
T1113 Screen Capture
7 Exfiltration (TA0010) T1041 Exfiltration over C2 Channel

 

Matanbuchus Loader Report

Matanbuchus Loader Report

Date: 29-June-22
Author: Manoj Kumar (CYFIRMA-Malware Research Team)

Suspected Malware: Matanbuchus
Function: malware Loader
Risk Score: 8
Confidence Level: High1`
Threat actor Associations: BelialDemon
DeCyfir presence: Yes

Executive Summary:

Matanbuchus, offered as part of malware-as-a-service, has been available on underground forums for a rental price of $2500 since February 2021. Recently, the CYFIRMA research team observed this malware reappear through spam campaigns. CYFIRMA team monitoring the campaign has attributed this malware to the BelialDemon threat actor. The email contains a malicious attachment in .html format having embedded base64 which on execution drops a zip file. Upon clicking the Html attachment, it drops a zip archive file and this zip file contains an MSI file. On executing the MSI file, it shows the fake Adobe error message to the user while dropping the malicious dll file in the background. This malicious dll file is loaded by regsvr32.exe along with the command-line argument. This dll file belongs to the Matanbuchus malware family, and it is trying to download additional payloads through C&C servers.

Matanbuchus Analysis:

Sample Details:
File Type: Html
MD5: 5303835908B6D8313A9E226F7B025217
SHA1: EB10D1FBCC4D10899E532C6D8B4AFADDF08EBC9C
SHA256: E3B98DAC9C4C57A046C50CE530C79855C9FE4025A9902D0F45B0FB0394409730

This malware sample was written in a combination of Html and JavaScript language. Threat actors deliver this malicious Html file to the user through spear-phishing techniques such as the scanned document attached to the email.

Threat actors are using the OneDrive string as a title in the HTML title tag and using a drive image in the Html file to pretend that this scanned document is in the OneDrive location to lure the user and convince them that this file is legitimate.

As shown in the below figure, the Threat actor embedded the malicious zip file in the JavaScript in base64 format, where the file name is Scan-23112.zip[MD5: A2D5F84B134F7A0F00C18770AB29876E].

Once the user clicks that attached file, this Html drops the zip file in the Downloader folder and executed Matanbuchus malware from this location. After extraction, the dropped zip file is found to contain an MSI installer file.

Dropped File_1:

MD5: 4D5DA2273E2D7CCE6AC37027AFD286AF
SHA256: 5DCBFFEF867B44BBB828CFB4A21C9FB1FA3404B4D8B6F4E8118C62ADDBF859DA
File Size: 229376 (bytes)

This MSI file is having a digital signature as “Westeast Tech Consulting, Corp.” This certificate was revoked by its certification authority.

Upon execution of this MSI file, as shown in the below figure, the file pretends to configure Adobe Font pack version 3.0.12.9 in the user system and follows it up by throwing a fake error message to deceive users.


Fake error message

In the background, the MSI file creates the AdobeFontPack folder in the location “C:\Users\username\AppData\Local”, followed by dropping two files – dll[main.dll] file and vbs[notify. vbs] file.

Notify.vbs file[MD5: 0308AA2C8DAB8A69DE41F5D16679BB9B] contains the fake error message that is displayed on execution of this MSI file.

This MSI file loads this malicious dll file[ main.dll] through regsvr32.exe with arguments being -n -i “install”. regsvr32.exe is a command-line utility to register and unregister OLE controls, such as DLL files and ActiveX controls in the Windows Registry. This malware uses the -n parameter to prevent calling the DllRegisterServer method and uses the -i parameter which will invoke the DllInstall method.

This DLL file is establishing a connection to the C&C server for download and trying to download another malware which is Cobalt Strike beacon payload. At the moment these C&C servers are not alive.

Dropped_Dll file:

Sample Details:

File Type: Windows PE [dynamic-link-library]
Architecture: 32 Bit
MD5: 1C5A0D343167085442299C29F3D88056
SHA1: 3815625D50B7C9290C4BF424E356C332E6DD295B
SHA256: 8833F28DC0CADD4B3C5676981B2A76E1C0683F2E2B8E3DAC8270622C12E032EF
Subsystem: console
Compilation Time: Thu May 12 03:42:49 2022

This malicious dll file is having version information and the company name in version information as “Piriform Software Ltd” as well as using the internal name as cclener.dll to lure unsuspecting users to believe that this file is legitimate.

This DLL file is having the following three export functions.

This dll having anti-debugging capabilty ,this dll file is checking presences for any debugger by calling APIs such as IsProcessorFeaturePresent(),IsDebuggerPresent(), QueryPerformanceCounter().

This DLL file contains malicious code in the DLL main function instead of the Exported API function. Threat actors use a customized decryption method to decrypt the malicious code. This malicious DLL file is calling the below do.. while to decode the malicious content. This loop will execute a total of 11 times. In each iteration of this loop, this code will run a different function [XORing the encrypted file].

In that iteration of 5 to 10 [Do..while loop] this DLL file is calling the decryption functions. This malicious DLL file is using a combination of two key pairs to generate one XOR key for decrypting the encrypted contents. In this combination of key pairs, one of the keys is a constant value which is “1010101” while another key is different for each decryption function execution (6 times).


Decryption loops

These keys are listed in the following table:

Iteration Key Pair Decrypted Content
5th 7EBC317 DllRegisterServer
6th 7EBBFA3 hxxps://telemetrysystemcollection.com/m8YYdu/mCQ2U9/auth.aspx
7th 7EBB327 hxxps://collectiontelemetrysystem.com/m8YYdu/mCQ2U9/auth.aspx
8th 7EBCBE5 hxxps://telemetrysystemcollection.com/m8YYdu/mCQ2U9/home.aspx
9th 7EBB357 hxxp://collectiontelemetrysystem.com/m8YYdu/mCQ2U9/home.aspx
10th 7EBCD07 hxxp://telemetrysystemcollection.com/m8YYdu/mCQ2U9/home.aspx

The below code snippet is one of the functions [Key pair] associated with them.


Key pairs of the 5th Iteration in do..while loop

The following code snippet is decoded malicious content in the memory after these do .. while loop execution is completed.

After that this malicious dll file executes an exported API function, namely ?HackCheck@@YGXXZ (a.k.a HackCheck), which has customized decryption logic. This function runs this decryption loop and decrypts the encrypted string “klyjl8|tt8Py{s[p}{s.”[which is hardcoded in the binary file] by XORing logic then print that output string by OutputDebugStringA API call. The decrypted string is “start dll HackCheck”.

Conclusion:

Matanbuchus malware is distributed through phishing or spear-phishing emails having malicious attachments. The malware is attributed to threat actor BelialDemon, who is a member of several underground forums and marketplaces. This Matanbuchus malware loader has resurfaced and uses spear-phishing as an initial vector for infection having Html file as an attachment. The threat actor utilizes the HTML smuggling technique to deliver the malicious zip file to the user and disguises it as AdobeFontPack and installs the same into the system, while in the background, it is dropping Matanbuchus loader dll file in the location “C:\Users\username\AppData\Local\AdobeFontPack”. The threat actor loads the malicious main.dll file akin to an older trick known as Squiblydoo where Qbot was using regsvr32.exe along with arguments. Additionally, this malware loader tries to download the Cobalt Strike beacon payload.

List of IOCs:

Sr No. Indicator Type Remarks
1 5303835908B6D8313A9E226F7B025217 MD5 SCAN-231112.html
2 A2D5F84B134F7A0F00C18770AB29876E MD5 Scan-23112.zip
3 4D5DA2273E2D7CCE6AC37027AFD286AF MD5 SCAN-231112.pdf.msi
4 1C5A0D343167085442299C29F3D88056 MD5 main.dll
5 hxxps://telemetrysystemcollection[.]com/m8YYdu/mCQ2U9/auth[.]aspx URL C&C server
6 hxxps://collectiontelemetrysystem[.]com/m8YYdu/mCQ2U9/auth[.]aspx URL C&C server
7 hxxps://telemetrysystemcollection[.]com/m8YYdu/mCQ2U9/home[.]aspx URL C&C server
8 hxxp://collectiontelemetrysystem[.]com/m8YYdu/mCQ2U9/home[.]aspx URL C&C server
9 hxxp://telemetrysystemcollection[.]com/m8YYdu/mCQ2U9/home[.]aspx URL C&C server
10 FuHZu4rQgn3eqLZ6FB48Deybj49xEUCtDTAmF String File string
11 klyjl8|tt8Py{s[p}{s String Obfuscated string of start dll HackCheck
12 start dll HackCheck String Decoded string

Mitre Attack Tactics and Techniques (Based on our analysis):

Sr No. Tactic Technique
1 Initial Access (TA0001) T1566. 001: Phishing:Spearphishing Attachment
2 Execution(TA0002) T1059.007: Command and Scripting Interpreter:JavaScript
T1204.002 : User Execution: Malicious File
3 Defense Evasion(TA0005) T1218.007: System Binary Proxy Execution: Msiexec
T1218.010: System Binary Proxy Execution: Regsvr32
T1497.001:Virtualization/Sandbox Evasion : System Checks
T1497.003:Virtualization/Sandbox Evasion : Time Based Evasion
4 Command & Control (TA0011) T1132.001: Standard Encoding Technique
T1071.001: Application Layer Protocol: Web Protocols

AvosLocker Ransomware Report

AvosLocker Ransomware Report

Suspected Malware: AvosLocker Malware
Function: Ransomware
Risk Score: 8
Confidence Level: High
Threat actor Associations: Unknown
First Seen: July 2021

 

Executive Summary:

Ransomware-as-a-service can cause massive disruption to businesses as well as significant financial impact. Attackers behind these services have developed new techniques and attack patterns and this article provides a technical analysis of the latest malware sample.

The AvosLocker operates ransomware-as-a-service giving malware authors the ability to sell their code to other #cybercriminals and #threatactors. The AvosLocker was first noticed in early July 2021 and continued its operation into 2022. Initially, AvosLocker used to target Windows system and later, expands its operation by including Linux-based variants also. The threat actors use spam or phishing emails as initial vectors to deliver ransomware payload. The group has claimed that AvosLocker’s latest windows variant is one of the fastest available in the market and offers an affiliate program to cyber-criminals.

This is how the malware works: Upon execution, it encrypts the files and appends the extension “.avos” to the encrypted file. The updated variants append “.avos2” extension and Linux variants append the extension “.avoslinux” to the encrypted files. The ransomware sample we have analyzed appends the extension “.avos2” to the encrypted file. The sample contains a hard-coded ID and public encryption key. The sample is console-based and provides options to use while executing the sample and shows the status of encrypted or skipped files on the console window. The ransomware drops the ransom note in each folder and desktop with the name “GET_YOUR_FILES_BACK.txt”. The ransomware also creates a mutex with the name “Cheic0WaZie6zeiy” so that only one instance of the ransomware will run at a time.

 

AvosLocker Ransomware Analysis:

Sample Details:
File Type: Windows PE Executable
Architecture: 32 Bit
MD5: 825d6049ba8600ee5fefd817ac5444b4
SHA256: c0a42741eef72991d9d0ee8b6c0531fc19151457a8b59bdcf7b6373d1fe56e02
Subsystem: Console
Language: MS Visual C++
Compilation Time: 27 August 2021

 

Basic Information:

The sample malware is Windows PE-32 bit executable having a console subsystem. The binary can be run either through command line or by double-clicking. In both cases, the console window will open and shows the status of files being encrypted.

 

Command-line Options available with Malware Binary:

The below snapshot shows the options available with which the sample can be executed. The options are used to control certain aspects of the functionality like enabling/disabling SMB brute force, maximum concurrent threads, mutex creation, hiding console window, etc. By default, that is without no options, the malware ignores encryption of network drives and SMB share.

As shown in the above snapshot, our research team checked the options available with two different samples. There is a difference in the options available in both samples as the first sample is recent and another one is a little older. The recent sample has one more option “-s” (–unsafe) available which can be used to enable encryption of system and hidden files also.

 

Display Execution Progress and Status:

Upon executing the malware sample with no options, it runs with the default option and ignores encryption of SMB share and network drives. It runs 200 concurrent threads for file encryption. During execution, the console window shows progress status. Further, after completion, the console window also displays information regarding a total number of locked objects and the time taken to encrypt.

File Extension and Ransom Note:

The AvosLocker encrypts the files and appends “.avos2” extension to the encrypted files. It excludes some of the files with specific extensions like “.exe”, “.dll” and “.avos2”. The ransomware also drops a ransom note in each encrypted folder and Desktop with the name “Get_YOUR_FILES_BACK.txt”.

The ransom note as shown below mentions that the files are encrypted with AES-256 encryption and in order to decrypt the contents, the victim has to pay for the decryption key and application.

The ransom note also provides two Tor or onion links related to malware authors. The first link is given to contact malware authors with the specified ID mentioned in the ransom note:
http://avosjon4pfh3y7ew3jdwz6ofw7lljcxlbk7hcxxmnxlh5kvf2akcqjad.onion/
The second link is to the data leak blog of the group which contains the leaked data of the organization who are failed to pay or respond.
http://avosqxh72b5ia23dl5fgwcpndkctuzqvh2iefk5imp3pi5gfhel5klad.onion/

 

Hard-Coded ID and Public Key:

The ID “3276b4d5d73dc9de228691c8193c374f5c83ba83341cf9405130e0095f60437b” mentioned in the ransom-note and the public key used are hard-coded into the malware binary.

The malware reads the file, encrypts it, and writes the content in the encrypted file with a unique signature that appends to the file. This signature is used to identify whether the file is encrypted or not,

Code Snippets and Functioning:

The ransomware collects the command-line options if any passed at the time of binary execution.

Collecting system information

Checking the presence of any debug environment to thwart the analysis process.

The malware enumerates files, and drives. It also has the capability to enumerate network drives.

The malware creates the mutex with the name “Cheic0WaZie6zeiy” to ensure that only one instance of the malware runs at a time.

The malware use multi-threading by using APIs CreateIoCompletionPort(), PostQueuedCompletionStatus(), GetQueuedCompletionPort() to handle multiple files concurrently and thread priority is also set to high for quick encryption.

A picture containing a graphical user interface

 

Ransomware checking file attributes before encryption and skip files having “FILE_ATTRIBUTE_HIDDEN” or “FILE_ATTRIBUTE_SYSTEM” attributes.

 

Exclude system and hidden files from encryption. The malware also excludes files having specific extensions like “.exe”, ”.dll”, “avos”, “avos2” etc. and also some folders like “Program Files”, “Program Files (x86)”, “ProgramData” and Windows, etc.

 

The malware encrypting the files

 

Appends the extension “.avos2” to encrypted files

Data Leakage and Payment Site:

For the AvosLocker ransomware victims who failed to pay, the threat actors then leak their data on the site with the organization’s name and information.

 

The below-mentioned site where the victim enters the ID mentioned in the ransom-note and it will redirect the victim to the payment page.

The malware has the following capabilities:

  • Multiple Anti-debugging capabilities
  • Ability to enumerate drives
  • Ability to enumerate paths, files, and folders
  • Sandbox evasion capability
  • Capability to inject malicious code into a valid process
  • Capability to load other libraries, processes, and DLLs in memory
  • Capability to handle command-line arguments and command execution
  • Ability to Gather System Information
  • Network communication capability
  • Encryption/Decryption capability

Conclusion:

AvosLocker ransomware group was first noticed in 2021 and initially targets Windows machines. The newer variants also target the Linux environments. The Avos group is a financially motivated, well-funded group and follows the Ransomware-as-a-Service (RaaS) model. Avos group normally uses spam and phishing campaigns for the initial infection vectors. The Linux variants use Proxyshell to exploit vulnerable Microsoft Exchange Servers. The ransomware gets deployed on the victim machine to encrypt data and demand the ransom.

List of IOCs:

Sr No. Indicator Type Remarks
1 825d6049ba8600ee5fefd817ac5444b4 MD5 AvosLocker
2 Cheic0WaZie6zeiy String Mutex
3 3276b4d5d73dc9de228691c8193c374f5c83ba83341cf9405130e0095f60437b String ID
4 .MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAqJ4nbENO
VG3j8DcLa/+L.bXatoJd6NsiY9ULBUecwW1vMd7GvRq0tM+I0eeotIeFae3K38K8
3dB3OPfFwLDgf.nvUPTdD0m8NMEU2iVa0uvQMV+Ga1ekVspua3r3AAdsV+XX/Ff4
ocJLiTe2UOAD5I.r05DyIRadbfjaH6qQGRA8njneidoff3AQekR3TBVDwEn5UP93
k5Zgq4QbJnBYoQZ.7d8C2WZhr64VglrVkQ4P/gL/c36nfIJL488rxxv4pUM1KVnB
XXCF3QyOXOV7zR6A.M0lKfJGa64W1Sx6WU+KTieBcETf/LWT2fTfu5B91xpT9L3R
Cts/l0/WfUu1OUR12.eQIDAQAB.
String Public Key
5 hxxp[:]//avosqxh72b5ia23dl5fgwcpndkctuzqvh2iefk5imp3pi5gfhel5klad[.]onion URL Data Leak Site
6 hxxp[:]//avosjon4pfh3y7ew3jdwz6ofw7lljcxlbk7hcxxmnxlh5kvf2akcqjad[.]onion URL Payment Site

 

Mitre Attack Tactics and Techniques Used:

Sr No. Tactic Technique
1 Initial Access (TA0001) T1566 Phishing
2 Discovery (TA0007) T1082 System Information Discovery
T1083 File and Directory Discovery
3 Execution (TA0002) T1204.002 Malicious File
4 Defense Evasion (TA0005) T1027 Obfuscated Files or Information
5 Collection (TA0009) T1005 Data from Local System
6 Impact (TA0040) T1486 Data Encrypted

 

 

TA505 Recent Trends Report 10-06-2021

Threat Actor Profile

Threat Actor: TA505

Alias: ATK 103, Chimborazo, Evil Corp, Gold Evergreen, Gold Tahoe, Graceful Spider, Hive0065, SectorJ04, TA 505, TA-505, TA505

Origin: Russia

Description: The threat actor is a well-established financial crime group that has recently focused its operations on ransomware and extortion. The group has been active since 2008. They are notable not for their sophistication, but for the sheer volume of extraordinary messages they send. The group has leveraged a number of malware as part of their campaign, and this also shows their deep connections to underground malware resources. The threat actor is also believed to have an infrastructure that overlaps with other threat actors.

Targeted Countries:  Australia, Canada, Czech Republic, Germany, Hungary, India, Japan, Romania, Serbia, Singapore, South Korea, Spain, Thailand, Turkey, UK, and the US

Targeted Industries: Education, Financial, Healthcare, Hospitality, Restaurants, Retail, Supply Chain

Tools/ Malware: The group has been known to utilize the following tools and malware in their attacks chain
FlowerPippi, Locky Ransomware, AndroMut, GameOver Zeus, Gelup, Dudear, Get2, Bart, Amadey, CryptoLocker, EmailStealer, FlawedGrace, GlobeImposter, Shifu, EmailStealer, TinyMet, Shifu Trojan, SDBbot, Jaff, GameOver Zeus, RMS, Amadey, Dridex, FlawedAmmyy, FlawedAmmy RAT, Bart, Philadelphia, Zeus, Clop Ransomware, FlowerPippi, Dridex Malware, GlobeImposter Ransomware, FlawedGrace, Locky Ransomware, Dudear, CryptoLocker, CryptoMix, RockLoader, Snatch, AndroMut, Pony, Gelup, ServHelper, MINEBRIDGE, Kegotip, Get2, Jaff Ransomware, Neutrino

Motive: Financial Crime, Financial Gains, Espionage

Recent Activity:
The threat actor has launched a new ransomware dubbed Macaw Locker to evade US sanctions that prevent victims from making ransom payments. In two of the attacks, it was observed that the threat actors demanded a 450 bitcoin ransom, about USD 28 million, for one attack and USD 40 million for the other victim. The Macaw Locker seems to have evolved from Wasted Locker ransomware; it encrypts victims’ files and appends the .macaw extension to the file name when launching attacks.

Details of Recent Campaigns

These recent campaigns are tracked by CYFIRMA and are believed to be active during the following time frame:

  1. UNC054 : Jun 6, 2022 – Jun 7, 2022
  2. UNC053 : May 26, 2022 – May 27, 2022
  3. UNC051 : Mar 15, 2022 – May 9, 2022
  4. night blood : May 22, 2021 – Mar 16, 2022
  5. UNC031 : Jan 15, 2022 – Feb 6, 2022

Trends

Out of the 5 campaigns observed by CTI this year – attributed to TA505 – most campaigns were targeted at multiple counties across the globe. Almost all the campaigns targeted multiple nation-states.

TA505 attacked a total of 35 different nations in only 5 campaigns observed by CTI which is unusual when compared to other threat actor groups who often restrict their efforts to geographies of their interest and attack them repeatedly. Further, the campaign UNC054 targeted 29 countries.

The figure below illustrates all the counties which were targeted in these campaigns.

Most Targeted Countries

The following figure illustrates the targeted countries which were subject to the TA505 campaigns.

The United States, Japan, and the United Kingdom have been the top targets for TA505 and were targeted in all the five campaigns.

Most Targeted Technology

The TA505 leveraged vulnerabilities in Web Application, Virtual Private Network Solutions, Application Server Software, and Operating Systems to infiltrate the network and systems of potential victims.

The figure illustrates the technologies that were targeted by the threat actor group during these campaigns. From the trends, it can be observed that exploiting weaknesses in web application-related software and products is the most favoured method by the TA505.

Targeted Industries

From the campaign observed by CTI in 2022, TA505 attacked organizations from more than 25+ industry verticals. The targeted list of industries includes:

  1. Apparel & Luxury Goods
  2. Banks
  3. Chemicals
  4. Construction & Engineering
  5. Construction Materials
  6. Diversified Financial Services
  7. Electronic Equipment
  8. Energy Equipment & Services
  9. Food & Staples Retailing
  10. Government
  11. Health Care Equipment & Supplies
  12. Health Care Technology
  13. Industrial Conglomerates
  14. Instruments & Components
  15. Internet & Direct Marketing Retail
  16. IT Services
  17. Metals & Mining
  18. Personal Products
  19. Real Estate Management & Development
  20. Semiconductors & Semiconductor Equipment
  21. Storage & Peripherals
  22. Technology Hardware
  23. Textiles
  24. Trading Companies & Distributors
  25. Wireless Telecommunication Services

Malware Observed

Below is the list of all the malware used by TA505 in their campaigns.

  1. LockBit Ransomware
  2. Dridex
  3. Clop Ransomware
  4. MirrorBlast
  5. Emotet
  6. Fareit
  7. REvil Ransomware
  8. MineBridge
  9. FlawedAmmy RAT
  10. Zloader

The Dridex malware appears to be the go-to choice for TA505. In the campaign observed by CTI the malware was used in 4 out of 5 campaigns.

Attack Type

All of the observed campaigns carried out by the TA505 involved heavy use of exploiting vulnerabilities in internet-exposed systems or applications and the use of ransomware implants among other malware was also a common tactic.

MITRE ATT&CK TTPs

Insights

CTI has observed Russian cybercriminal groups, such as TA505 and its affiliates, collaborate with and leverage ransomware groups such as Conti, LockBit, REvil, etc. as part of the Ransomware-as-a-Service (RaaS) model. Recently, researchers and law enforcement agencies have correlated TA505 aka Evil Corp leveraging LockBit ransomware under the RaaS model to target organizations.

CYFIRMA has observed TA505 targeting organizations in Critical Infrastructure, Energy, Mining, and Manufacturing industries leveraging potential ransomware such as LockBit for reconnaissance or potential attacks under CYFIRMA tracked campaigns UNC053 and UNC054. These campaigns are suspected to be potential retribution from Russia against nations who have imposed sanctions on them due to the ongoing Russia – Ukraine conflict.

Recommended Actions

  1. Deploy a unified threat management strategy – including malware detection, deep learning neural networks, and anti-exploit technology – combined with vulnerability and risk mitigation processes
  2. Deploy Zero Trust Policy that leverages tools like security information management, advanced security analytics platforms, security user behaviour analytics, and other analytics systems to help the organization’s security personnel observe in real-time what is happening within their networks so they can orient defences more intelligently.
  3. Facilitate security teams with attack surface management capability for continuous discovery, inventory, classification, prioritization, and security monitoring to gain comprehensive visibility of the enterprise environment.
  4. Emphasize the responsible use of social media platforms, and train the workforce on the amount and nature of information being shared.
  5. Plan periodic Red Team exercises to measure the effectiveness of the people, processes, and security technologies used to defend the environment. Red Team exercise helps organizations to improve security control detection, enhance defensive capabilities, and measure the overall effectiveness of existing security operations.
  6. Perform regular Cyber Benchmarking exercises to benchmark the security performance against industry peers, measure the impact of risk mitigation efforts, and report security progress and results to the Board of Directors more clearly and effectively.
  7. Enable emerging security solutions like deception technology powered with machine learning helps in real-time breach detection and prevention.
  8. Classify and segregate the organization’s business-critical system a.k.a as crown jewels and have a special security monitoring on those assets.
  9. Ensure applications requiring authentication over the internet are protected with multi-factor authentication.
  10. Ensure combination security control such as CAPTCHA (Completely Automated Public Turing test to tell Computers and Humans Apart), Device fingerprinting, IP backlisting, Rate-limiting, and Account lockout are implemented and adequately strengthened to thwart automated brute-force attacks.
  11. Improve the detection signatures of Intrusion detection and prevention systems with custom rules to monitor and alert network intrusions.
  12. Exert caution when opening email attachments or clicking on embedded links received via email communications.
  13. Update all applications/software regularly with the latest versions and security patches alike.
  14. Deploy an email filter solution that screens based on headers and malicious content (e.g., malicious macros, infected attachments, etc.), categorizes email, inspects Uniform Resource Locators (URLs) against reputation feeds, and has customizable rule-based filters.
  15. Strip and/or block emails containing active content (e.g., ActiveX, Java, Visual Basic for Applications [VBA])or macros by default. Administrators should allowlist such content only for legitimate reasons.
  16. Ensure detection signatures and blocklists are up to date.
  17. Implement warning banners to alert users about emails with links and attachments that originate from outside the organization.

 

Phishing Sample Analysis 10-06-2021

Phishing Sample Analysis

MD5 : 140F716E974CD7483EEAA380A9C4FD82
SHA1 : 4D5B17CA34D8D15FBAE65AB637919E13E72A3476
SHA256 : 4DCED4DDB2FFA1E0E1E9C2F6A2D4B1302CEBCA59E7D340ADA0F2E421288B54FE
Motivation : Steal user credentials

Recently the CYFIRMA research team has observed an active phishing campaign to steal victims’ credentials. The email contains a malicious attachment in .html format containing an embedded JavaScript which upon execution will bring the user to a fake Sharepoint login page. The objective is to steal credentials and redirected the user to other malicious URLs.

This phishing malware sample was written in a combination of Html and JavaScript language. The identity of the threat actor is unknown at this point. Threat actors are delivering this phishing Html file using spear-phishing technique.

Upon execution of this malicious Html, it opens the share point online page. Threat actors hide the information about the share point details in excel behind a fake login page.


Fig: Phishing Page

To view the excel, users must enter their credentials on this phishing page. After the user enters their credentials, the threat actor tricks the user into believing the page is legitimate by showing “verifying”. Meanwhile, the unsuspecting user is redirected to the following phishing URL without their knowledge.

Phishing URL: hxxps://spanishcolonialcobs.com.

Next, the threat actor throws an error message such as “please try again later “. This error message is hardcoded in JavaScript to prompt the user to think that this could be due to a technical issue. Thus, users are unlikely to report this to their security provider/vendor.


Fig: Error message

The threat actor uses the Window object in JavaScript to hide the phishing link from the user.


Fig: Window object in JavaScript

The Threat actor calls the window object [In this code window.phpurl] after the user enters their credentials and clicks the Login button.

MITRE ATT&CK Tactics and Techniques

Sr No. Tactic Technique
1 TA0001: Initial Access T1566: Phishing
2 TA0002: Execution T1059.007: Command and Scripting Interpreter: JavaScript
3 TA0003: Persistence T1176: Browser Extensions
4 TA0005: Defense Evasion T1027: Obfuscated Files or Information
T1497.003: Virtualization/Sandbox Evasion: Time Based Evasion
5 TA0009: Collection T1056.003: Input Capture: Web Portal Capture
T1005: Data from Local System

Conclusion: Threat actors are using phishing or spear-phishing emails as the primary vector to exploit vulnerable users and organizations in order to steal user credentials. Additional verification and security countermeasures are required to deal with suspicious emails specifically those having .html, pdf, and JavaScript files as attachments or links.

 

MISSION2025 Recent Trends Report 31-05-2021

Recently Observed Campaigns

The following list contains recent campaigns observed by CYFIRMA Threat Intelligence (CTI) that are attributed to the MISSION2025 and or its affiliates last seen in 2022.
• C Guard
• Vision2025
• UNC038
• UNC041
• Think pocket
• UNC036
• Uplift19
• Slow Walker
• UNC026
• Bupa Street
• UNC033
• UNC044
• UNC032
• JQC18

Recently Observed Activities Details

These recent campaigns are tracked by CYFIRMA and believed to be active during following time frame.
• C Guard (Jun 19, 2020-May 15, 2022)
• Vision2025 (Oct 31, 2017-May 14, 2022)
• UNC038 (Jan 30, 2022-May 10, 2022)
• UNC041 (Feb 10, 2022-May 10, 2022)
• Think pocket (Aug 21, 2021-Apr 28, 2022)
• UNC036 (Jan 30, 2022-Apr 28, 2022)
• Uplift19 (Jul 31, 2020-Apr 27, 2022)
• Slow Walker (Dec 1, 2020-Apr 24, 2022)
• UNC026 (Mar 15, 2020-Apr 23, 2022)
• Bupa Street (Nov 17, 2020-Apr 18, 2022)
• UNC033 (Dec 19, 2021-Apr 18, 2022)
• UNC044 (Feb 25, 2022-Apr 1, 2022)
• UNC032 (Dec 19, 2021-Feb 14, 2022)
• JQC18 (Jan 1, 2021-Feb 2, 2022)

Trends

Out of the 14 campaigns observed by CTI this year – attributed to MISSION2025 – most campaigns were targeted at multiple counties across the globe. Almost all the campaigns were targeted at three or more nation states and not a single campaign observed by CTI appeared to target single specific nations.
The below figure illustrates all the counties which were targeted in these campaigns.

Most Targeted Countries

The following figure illustrates the targeted countries which were subject to the MISSION2025 campaigns.

The United States and Japan have been the most favourable targets for MISSION2025 and were targeted in all the 12 campaigns respectively out the total 14 campaign. Countries like Taiwan and South Korea – while not at the top – remain to be of particular interest to the this group and also featured in multiple campaigns.

Most Targeted Technology

The MISSION2025 leveraged vulnerabilities & exploits in Application Server Software, Web Application, Operating System, Server Virtualization Software, API Management Tools, Remote Desktop Software to infiltrate the network and systems of potential victims.
The below figure illustrates the technologies that were targeted by the threat actor group during these campaigns. From the trends, it can be observed that exploiting weaknesses in web application-related software and products is the most favoured method by the MISSION2025. In addition, attempts to exploit remote access solutions and virtualization have been observed.

Targeted Industries

From the campaign observed by CTI in 2022, MISSION2025 attacked organizations from more than 40+ industry verticals. The targeted list of industries includes:

• Aerospace & Defense
• Auto Components
• Automobiles
• Aviation infrastructure
• Banks
• Commercial Services & Supplies
• Communications Equipment
• Construction
• Construction & Engineering
• Construction Materials
• Diversified Financial Services
• Electronic Equipment
• Energy Equipment & Services
• Entertainment
• Food & Staples Retailing
• Gas Utilities
• Government
• Health Care Equipment & Supplies
• Health Research
• Hotels
• Housing
• Industrial Conglomerates
• Infrastructure Development
• Instruments & Components
• Insurance
• Interactive Media & Services
• Internet & Direct Marketing Retail
• IT Services
• Large Equipment Making Companies
• Media
• Metals & Mining
• Multiline Retail
• Oil Gas & Consumable Fuels
• Optical Sensor
• Professional Services
• Railways
• Restaurants & Leisure
• Software
• Storage & Peripherals
• Technology
• Technology Hardware
• Telecommunication
• Trading Companies & Distributors
• Transportation Infrastructure
• Wireless Telecommunication Services

Malware Observed

Below is the list of all the malware used by MISSION2025 in their campaigns. Interestingly, the threat actor group has used a single malware in entire campaign – examples include UNC026 campaign used Urnsif, and in Bupa Street campaign the Emotet malware was used.
A complete list of malware observed by CYFIRMA during these campaigns is as follows:

Top Malware

While numerous malware was used by the MISSION2025 in these campaigns, the malware namely Cobalt Strike, Emotet, and ASPXSpy were the most observed by CTI.

Threat Actor Profile

Alias: APT 41, APT-41, APT41, BARIUM, Gref, IQGRABBER, Mana Mr. StealYoShoes, PassCV, SparklingGoblin, UNC78, UNIT2025, Winnti, Winnti Umbrella Group

Origin: China

Description: MISSION2025 is suspected to be a Chinese state-sponsored threat actor, possibly working for the Chinese government. The threat actor is believed to be active since at least 2012. It is suspected of executing various campaigns against organizations in multiple industries such as Automotive, Retail, Healthcare, Energy, Hi-Tech, Media, Finance, Healthcare, Telecom, Supply Chain, Travel, etc. The threat actor group is believed to target nations such as the US, UK, Japan, India, France, Italy, Switzerland, Turkey, South Africa, South Korea, Hongkong, Thailand, Myanmar, etc. with the intent of financial gains and/or espionage purpose.

Targeted Countries:  Brazil, France, Germany, India, Italy, Japan, Kazakhstan, Myanmar, Netherlands, Pakistan, Province of China, Republic of Korea, Russia, Singapore, South Africa, Taiwan, Thailand, Turkey, United States of America, Cambodia

Targeted Industries: Aviation, Cryptocurrency, Education, Energy, Finance, Gaming, Government Entities, Healthcare, Hi-Tech, Manufacturing, Media, Military, Pharmaceuticals, Retail, Software Development, Supply Chain, Telecommunications, Travel, Automotive

Tools: The group has been known to utilize the following tools in their attacks chain:
LOWKEY etc. RATs such as GH0ST””, Meterpreter, BlackCoffee, MessageTap, Living off the Land, Crackshot, EASYNIGHT, Derusbi, HDRoot, FRONTWHEEL, XDOOR, ASPXSpy, DIRTCLEANER, TERA, HKDOOR, X-DOOR etc. Credential Stealing malware such as ACEHASH””, BIOPASS RAT, Cobalt Strike, HighNote, PlugX, pwdump, Barlaiy, LIFEBOAT, Mimikatz, POTROAST, DOWNTIME, Jumpall, WIDETONE, Skip-2.0, China Chopper, RedXOR, ZXShell, COLDJAVA, CROSSWALK, GearShift, NTDSDump, ROCKBOOT, WINTERLOVE, DEADEYE, ADORE.XSEC, PipeMon, TIDYELF, PACMAN, certutil, ShadowPad Winnti, xDll, HIGHNOON, LATELUNCH, SAGEHIRE

Malware: The group has been known to utilize the following malware in their attacks chain: “China Chopper, Speculoos Backdoor, ASPXSpy, Winnti, ROCKBOOT, njRAT, ZxShell, gh0st RAT, Derusbi, MoonBounce, BLACKCOFFEE”

Motive: CYFIRMA believes that MISSION2025 group is a state-sponsored and financially motivated threat group, as they have been targeting global companies in multiple industries in the past and possibly could have expanded their target base to other industries. They may have attempted to implant trojans and backdoors to steal sensitive information and are primarily motivated to carry out cyber-espionage campaigns. These campaigns could be carried out to assist the local Chinese companies as part of Made in China 2025 vision with IP, Trade Secrets, and Blueprints, with the possible intent of either Information Exfiltration, Corporate Espionage, or Financial Gains via sale across the Deep/Dark web.

Recent Activity:
The threat actor has been suspected of carrying out ‘Operation CuckooBees’ to deploy a previously undocumented malware strain called DEPLOYLOG along with new versions of their known malware, including Spyder Loader, PRIVATELOG, and WINNKIT. The attackers leveraged the Windows CLFS mechanism and NTFS transaction manipulations which provided them with the ability to conceal their payloads and evade detection by traditional security products. The intent of the threat actor in this campaign seems to be cyberespionage and intellectual property theft.

Link: https://www.cybereason.com/blog/operation-cuckoobees-a-winnti-malware-arsenal-deep-dive#iocs

MITRE ATT&CK TTPs

10TA0009: CollectionT1560.001: Archive Collected Data: Archive via Utility
T1005: Data from Local System
T1056.001: Input Capture: Keylogging11TA0011: Command and ControlT1071.001: Application Layer Protocol: Web Protocols
T1071.002: Application Layer Protocol: File Transfer Protocols
T1071.004: Application Layer Protocol: DNS
T1568.002: Dynamic Resolution: Domain Generation Algorithms
T1008: Fallback Channels
T1105: Ingress Tool Transfer
T1104: Multi-Stage Channels
T1090: Proxy
T1102.001: Web Service: Dead Drop Resolver12TA0040: ImpactT1486: Data Encrypted for Impact
T1496: Resource Hijacking

Sr No. Tactic Technique
1 TA0042: Resource Development T1588.002: Obtain Capabilities: Tool
2 TA0001: Initial Access T1190: Exploit Public-Facing Application
T1133: External Remote Services
T1566.001: Phishing: Spearphishing Attachment
T1195.002: Supply Chain Compromise: Compromise Software Supply Chain
T1078: Valid Accounts
3 TA0002: Execution T1059.001: Command and Scripting Interpreter: PowerShell
T1059.003: Command and Scripting Interpreter: Windows Command Shell
T1059.004: Command and Scripting Interpreter: Unix Shell
T1203: Exploitation for Client Execution
T1053.005: Scheduled Task/Job: Scheduled Task
T1569.002: System Services: Service Execution
T1047: Windows Management Instrumentation
4 TA0003: Persistence T1197: BITS Jobs
T1547.001: Boot or Logon AutoStart Execution: Registry Run Keys / Startup Folder
T1136.001: Create Account: Local Account
T1543.003: Create or Modify System Process: Windows Service
T1546.008: Event Triggered Execution: Accessibility Features
T1133: External Remote Services
T1574.001: Hijack Execution Flow: DLL Search Order Hijacking
T1574.002: Hijack Execution Flow: DLL Side-Loading
T1574.006: Hijack Execution Flow: Dynamic Linker Hijacking
T1542.003: Pre-OS Boot: Bootkit
T1053.005: Scheduled Task/Job: Scheduled Task
T1078: Valid Accounts
5 TA0004: Privilege Escalation T1547.001: Boot or Logon AutoStart Execution: Registry Run Keys / Startup Folder
T1543.003: Create or Modify System Process: Windows Service
T1546.008: Event Triggered Execution: Accessibility Features
T1574.001: Hijack Execution Flow: DLL Search Order Hijacking
T1574.002: Hijack Execution Flow: DLL Side-Loading
T1574.006: Hijack Execution Flow: Dynamic Linker Hijacking
T1055: Process Injection
T1053.005: Scheduled Task/Job: Scheduled Task
T1078: Valid Accounts
6 TA0005: Defense Evasion T1197: BITS Jobs
T1480.001: Execution Guardrails: Environmental Keying
T1574.001: Hijack Execution Flow: DLL Search Order Hijacking
T1574.002: Hijack Execution Flow: DLL Side-Loading
T1574.006: Hijack Execution Flow: Dynamic Linker Hijacking
T1070.001: Indicator Removal on Host: Clear Windows Event Logs
T1070.003: Indicator Removal on Host: Clear Command History
T1070.004: Indicator Removal on Host: File Deletion
T1036.004: Masquerading: Masquerade Task or Service
T1036.005: Masquerading: Match Legitimate Name or Location
T1112: Modify Registry
T1027: Obfuscated Files or Information
T1542.003: Pre-OS Boot: Bootkit
T1055: Process Injection
T1014: Rootkit
T1218.001: Signed Binary Proxy Execution: Compiled HTML File
T1218.011: Signed Binary Proxy Execution: Rundll32
T1553.002: Subvert Trust Controls: Code Signing
T1078: Valid Accounts
7 TA0006: Credential Access T1110.002: Brute Force: Password Cracking
T1056.001: Input Capture: Keylogging
T1003.001: OS Credential Dumping: LSASS Memory
8 TA0007: Discovery T1083: File and Directory Discovery
T1046: Network Service Scanning
T1135: Network Share Discovery
T1016: System Network Configuration Discovery
T1049: System Network Connections Discovery
T1033: System Owner/User Discovery
9 TA0008: Lateral Movement T1021.001: Remote Services: Remote Desktop Protocol
T1021.002: Remote Services: SMB/Windows Admin Shares

 

Insights

The MISSION2025 has been known to be linked to the Chinese government and working in alignment with their political and economic goals to target organizations and exfiltrate sensitive information. CTI suspects the MISSION2025 will likely continue collaboration with other threat actor groups to meet their objectives. In the past, it is suspected Chinese state-sponsored threat actor groups are continuously targeting strategically essential countries associated with their “Belt and Road” initiative – and opposing China in the South China Sea. It may be possible that with the help of state-sponsored hackers, China could retaliate and launch cyber-espionage activities against Quad nations.
With China’s growing influence across the world, its efforts to maintain bilateral relations, and pursuance of partnership in support of its Belt and Road Initiative, researchers have assessed that the Chinese threat actor groups will continue to target organizations to gain new insights to achieve objectives such as economic espionage or for intelligence-gathering purposes.
Page Break

Recommended Actions

  1. Deploy a unified threat management strategy – including malware detection, deep learning neural networks, and anti-exploit technology – combined with vulnerability and risk mitigation processes
  2. Deploy Zero Trust Policy that leverages tools like security information management, advanced security analytics platforms, security user behaviour analytics, and other analytics systems to help the organization’s security personnel observe in real-time what is happening within their networks so they can orient defences more intelligently.
  3. Facilitate security teams with attack surface management capability for continuous discovery, inventory, classification, prioritization, and security monitoring to gain comprehensive visibility of the enterprise environment.
  4. Emphasize the responsible use of social media platforms, train the workforce on the amount and nature of information being shared.
  5. Plan periodic Red Team exercises to measure the effectiveness of the people, processes, and security technologies used to defend the environment. Red Team exercise helps organizations to improve security control detection, enhance defensive capabilities, and measure the overall effectiveness of existing security operations.
  6. Perform regular Cyber Benchmarking exercises to benchmark the security performance against industry peers, measure the impact of risk mitigation efforts, and report security progress and results to the Board of Directors more clearly and effectively.
  7. Enable emerging security solutions like deception technology powered with machine learning helps in real-time breach detection and prevention.
  8. Classify and segregate the organization’s business-critical system a.k.a as Crown jewels and have a special security monitoring on those assets.
  9. Ensure applications requiring authentication over the internet are protected with multi-factor authentication.
  10. Ensure combination security control such as CAPTCHA (Completely Automated Public Turing test to tell Computers and Humans Apart), Device fingerprinting, IP backlisting, Rate-limiting, and Account lockout are implemented and adequately strengthened to thwart automated brute-force attacks.
  11. Improve the detection signatures of Intrusion detection and prevention systems with custom rules to monitor and alert network intrusions.
  12. Exert caution when opening email attachments or clicking on embedded links received via email communications.
  13. Update all applications/software regularly with the latest versions and security patches alike.
  14. Deploy an email filter solution that screens based on headers and malicious content (e.g., malicious macros, infected attachments, etc.), categorizes email, inspects Uniform Resource Locators (URLs) against reputation feeds, and has customizable rule-based filters.
  15. Strip and/or block emails containing active content (e.g., ActiveX, Java, Visual Basic for Applications [VBA])or macros by default. Administrators should allowlist such content only for legitimate reasons.
  16. Ensure detection signatures and blocklists are up to date.
  17. Implement warning banners to alert users about emails with links and attachments that originate from outside the organization.

 

Yashma Ransomware Report

Yashma Ransomware Report

Executive Summary:
Yashma is a new ransomware seen in the wild since May 2022. This ransomware is the rebranded version of an earlier ransomware named Chaos. The latter has been in the wild since June 2021. After encryption, the Yashma ransomware dropped a ransom note titled “read_it.txt” in each encrypted folder and the desktop.

Yashma Analysis:
MD5: 1063360427174b7e44ed747e6d78e034
File Type: EXE

The ransomware is written in Basic.NET and is 32-bit executable with compiler time stamp – Wed May 18 11:06:18 2022.

The ransomware checks for the country based on the current input language. It will terminate if the country is Azerbaijan or Turkey.

Then the ransomware makes registry changes by adding mutex to the current user registry. Next, it starts the execution and while executing checks whether any other instance is already running. If yes, it will terminate itself.

The ransomware then copies itself to Appdata Roaming folder with filename svchost.exe. Post this, the ransomware will sleep for 200 milliseconds.

The ransomware deletes the shadow copies and backup, while also disabling the recovery mode and task manager.

  • vssadmin delete shadows /all /quiet & wmic shadowcopy delete
  • bcdedit /set {default} bootstatuspolicy ignoreallfailures & bcdedit /set {default} recoveryenabled no
  • wbadmin delete catalog -quiet

It will stop a listing of backup services that are running in the background at a time when the ransomware instance is running.

Below is the list of valid extensions it will check before encrypting the file.

The ransomware excludes the following directories from the encryption.

Below is the list of directories whose content the ransomware will encrypt.

The ransomware looks for drives to spread the ransomware over the network so that it moves laterally and infects other devices.

The ransomware then encrypts the file using AES-256 encryption algorithm with the key size of 128 bits.

The password for the encryption is randomly generated.

The ransomware maintains persistence by modifying the registry change and creating shortcuts.

It will change the screensaver of the victim’s system by changing it into a .jpg image. This image is generated by the attacker with random characters.

Below is the RSA key used for this ransomware sample.

The major differences between the earlier version of Chaos and Yashma ransomware are as follows.

  • The new version has hardcoded country names to prevent it from targeting certain geographies. This is detected based on the language setting on the user’s system.
  • The earlier version of Chaos could only encrypt files reaching up to the size of 1MB and would destroy any file over this size limit. However, Yashma is able to encrypt larger files.

Below is the comparison between the earlier version of Chaos and Yashma.

Conclusion:
“Yashma” ransomware can be distributed by using tactics like social engineering, phishing, spam email, malicious attachment, etc. Yashma ransomware is based on the Chaos ransomware builder. Chaos ransomware builder is still far from being complete since it lacks features that new ransomware possesses, such as the ability to collect data from victims that could be used for further blackmail if the ransom is not paid or deploy DDOS attack to force the victims into paying the ransom.

TTPs based on MITRE ATT&CK Framework:

Sr No. Tactic Technique
1 Discovery (TA0007) T1016: System Network Configuration Discovery
T1083: File and Directory Discovery
T1135: Network Share Discovery
T1049: System Network Connections Discovery
2 Execution (TA0002) T1106: Native API
T1059.003: Windows Command Shell
3 Persistence (TA0003) T1547 Boot or Logon Auto-start Execution
4 Defensive Evasion (TA0005) T1027: Obfuscated Files or Information
5 Collection (TA0009) T1005: Data from Local System
6 Impact (TA0040) T1486: Data Encrypted for impact
T1489: Service Stop
T1490: Inhibit System Recovery

 

IOC Analysis of Russian threat actors Nobelium and Wizard Spider

IOC Analysis of Russian threat actors Nobelium and Wizard Spider

The Russian threat actors have been observed to be very active and have targeted multiple organizations in the past. The primary objective of these hacker groups in targeting foreign organizations appears to be to exfiltrate sensitive details to be sold in the grey market or potential competitors for financial gains. Russian threat actors have potential collaboration with other nation threat actors and it is suspected Russian groups could be offering Ransomware-as-a-Service (RaaS model) to them.

Recently, CYFIRMA analyzed a malicious sample in DeCYFIR and secondary OSINT tools for validation and suspect it to be leveraged by Russian threat actors Nobelium and Wizard Spider.

About Nobelium:

The threat actor is a well-resourced, highly dedicated and organized cyberespionage group that is believed to be working for the Russian Federation since at least 2008 to collect intelligence in support of foreign and security policy decision-making. It uses various tools such as PinchDuke , CozyCar , POSHSPY , PowerDuke , OnionDuke , GeminiDuke , MiniDuke , CosmicDuke , HAMMERTOSS , CloudDuke , SeaDuke.

Motivation: Espionage, Financial Gains, Political Motives

About Wizard Spider:

The threat actor is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. Wizard Spider, known as the Russia-based operator of the TrickBot banking malware, had focused primarily on wire fraud in the past.

Motivation: Financial crime, Financial gains

Sample Analysis:

  • MD5: 200ddfeb5d1515ba83d96614c048cd13
  • SHA1: ed2c6e24c89c7650a13df1c133adc2b3daf38834
  • SHA256: 9622b99618ceea9ecbb93d54380235919ac99abcd5e2bd56c7ae8aa5e8650a9b

Following are some of the hypotheses based on which Russian threat actors are suspected to have leveraged this malicious sample:

  • The malicious sample was found attributed to an unnamed campaign tracked by CYFIRMA dubbed UNC040 (as indicated in the screenshot below) found through DeCYFIR’s AI & ML engines on the dark web. Based on DeCYFIR’s AI & ML engines and mathematical algorithms on active threat groups, we suspect Nobelium aka APT29, Cozy Bear to be behind this campaign.

UNC040 Details:

The campaign is suspected to be active since 24 January 2022.

  • Target Geographies:
    • South Korea
    • United States
    • Japan
    • Germany
    • India
  • Target Industries:
    • Health Care Equipment & Supplies
    • Health Care Technology
    • Government
    • Energy Equipment & Services
    • Health Care Providers & Services
    • Transportation Infrastructure
    • Health Research
  • Motivation: Exfiltration of sensitive information & intellectual property, customer, and personal information for financial gains.

For validation, the sample was analyzed in secondary OSINT tools which indicated that it was potentially used by Nobelium based on a similar tactic i.e. ISO disk image -> LNK link file -> DLL implant in a phishing campaign that seemed to target multiple victims based in the United States, Great Britain, and Europe.

  • Upon further analysis of the malicious sample in OSINT tools, it was found to have contacted an IP Address: 172.241.27.209. Upon opening the IP address in DeCYFIR, the following Whois details and threat actor ‘Nobelium aka Cozy Bear’ associated with this IP address were identified:
  • The IP address was found communicating with malicious samples which are associated with BazarLoader malware and generic trojans such as Kryptik, Artemis, etc.
  • In addition, malicious detections by security vendors (indicated in the screenshot below) in DeCYFIR suggested it to be associated with the BazarLoader malware which is used by Russian threat actor Wizard Spider aka UNC1878.

Following are some of the other campaigns tracked by CYFIRMA that are found to be potentially carried out by Nobelium threat actor, found through DeCYFIR’s AI & ML engines on the dark web:

  • Natural Disaster:
    • The campaign is active since 17 March 2022.
    • Target Geographies
      • United States
      • Japan
      • United Kingdom
    • Target Industries
      • Trading Companies & Distributors
      • Banks
    • Motivation: Exfiltration of Sensitive Databases, Customer Information for financial gains.
  • Crop Up:
    • The campaign is suspected to be active since 11 May 2021.
    • Target Geographies
      • South Korea
      • United States
      • Japan
      • United Kingdom
      • France
      • Germany
    • Target Industries
      • Semiconductors & Semiconductor Equipment
      • Electronic Equipment, Instruments & Components
      • Industrial Conglomerates
      • Health Care Providers & Services
      • Automobiles
      • Chemicals
      • Technology Hardware, Storage & Peripherals
    • Motivation: Stealing of sensitive information, intellectual property, personal, customer, and financial information.
  • Loop Work
    • “петля работа” aka “Loop work” is active since October 2020.
    • Target Geographies
      • South Korea
      • United States
      • Japan
      • Taiwan
      • United Kingdom
    • Target Industries
      • Software
      • Communications Equipment
      • Technology Hardware, Storage & Peripherals
    • Motivation: Exfiltration of sensitive information, equipment design, and personal and customer information for financial gains.
  • Hurricane
    • The campaign is suspected to be active since November 2020.
    • Target Geographies
      • United States
      • Japan
      • United Kingdom
      • Australia
      • India
    • Target Industries
      • Health Care Equipment & Supplies
      • Health Care Technology
      • Trading Companies & Distributors
      • Industrial Conglomerates
      • Wireless Telecommunication Services
      • Transportation Infrastructure
    • Motivation: Exfiltration of intellectual properties: Company sensitive information; Customer information; Medical product information for geopolitical and financial gains.
  • Ub4rk0
    • The campaign is suspected to be active since July 2020.
    • Target Geographies
      • Japan
      • UK
      • Korea
      • USA
    • Target Industries
      • Air Conditioning
      • Heating
      • Ventilation
      • Building Management
    • Motivation: Exfiltration of sensitive information, equipment design, and personal and customer information for financial gains.
  • Cold Unseco33
    • This campaign is active since October 2020.
    • Target Geographies
      • United States
    • Target Industries
      • Healthcare
      • Hospital
      • Pharmaceutical
      • Medical Equipment
    • Motivation: Exfiltration of Sensitive Personal, Clinical Trial Information, Health Care Reports, Customer Information, and Medical Product Information for geopolitical and financial gains.

The following CYFIRMA tracked campaign was potentially carried out by Wizard Spider. In addition, Fin11 and Oceanlotus were also suspected to possibly have perpetrated this campaign:

  • UNC034
    • The campaign is suspected to be running from 24 January 2022.
    • Target Geographies
      • South Korea
      • Singapore
      • United States
      • Japan
      • Taiwan
      • Portugal
      • Spain
      • India
    • Target Industries
      • Internet & Direct Marketing Retail
      • Interactive Media & Services
      • Diversified Financial Services
      • Professional Services
    • Motivation: Stealing of sensitive information/content, PII, CII, and FII for financial gains.

The Russian threat actors have been observed to be very active and have targeted multiple organizations in the past. The primary objective of these hacker groups in targeting foreign organizations appears to be to exfiltrate sensitive details to be sold in the grey market or to potential competitors for financial gains. Russian threat actors are assumed to have potential collaborations with other nations’ threat actors, and it is suspected that Russian groups could be offering Ransomware-as-a-Service (RaaS model) to them.

Following are the TTPs of Nobelium based on the MITRE Attack Framework:

MITRE ATT&CK TTPs

Sr No. Tactic Technique
1 TA0043: Reconnaissance T1595: Active Scanning
T1589: Gather Victim Identity Information
2 TA0042: Resource Development T1583: Acquire Infrastructure
T1586: Compromise Accounts
T1584: Compromise Infrastructure
T1587: Develop Capabilities
T1588: Obtain Capabilities
3 TA0001: Initial Access T1190: Exploit Public-Facing Application
T1133: External Remote Services
T1566: Phishing
T1195: Supply Chain Compromise
T1199: Trusted Relationship
T1078: Valid Accounts
4 TA0002: Execution T1059: Command and Scripting Interpreter
T1203: Exploitation for Client Execution
T1053: Scheduled Task/Job
T1204: User Execution
T1047: Windows Management Instrumentation
5 TA0003: Persistence T1098: Account Manipulation
T1547: Boot or Logon Autostart Execution
T1136: Create Account
T1546: Event Triggered Execution
T1133: External Remote Services
T1053: Scheduled Task/Job
T1505: Server Software Component
T1078: Valid Accounts
6 TA0004: Privilege Escalation T1548: Abuse Elevation Control Mechanism
T1547: Boot or Logon Autostart Execution
T1484: Domain Policy Modification
T1546: Event Triggered Execution
T1068: Exploitation for Privilege Escalation
T1053: Scheduled Task/Job
T1078: Valid Accounts
7 TA0005: Defense Evasion T1548: Abuse Elevation Control Mechanism
T1140: Deobfuscate/Decode Files or Information
T1484: Domain Policy Modification
T1562: Impair Defenses
T1070: Indicator Removal on Host
T1036: Masquerading
T1027: Obfuscated Files or Information
T1553: Subvert Trust Controls
T1218: System Binary Proxy Execution
T1550: Use Alternate Authentication Material
T1078: Valid Accounts
8 TA0006: Credential Access T1110: Brute Force
T1555: Credentials from Password Stores
T1606: Forge Web Credentials
T1621: Multi-Factor Authentication Request Generation
T1003: OS Credential Dumping
T1558: Steal or Forge Kerberos Tickets
T1539: Steal Web Session Cookie
T1552: Unsecured Credentials
9 TA0007: Discovery T1087: Account Discovery
T1482: Domain Trust Discovery
T1083: File and Directory Discovery
T1069: Permission Groups Discovery
T1057: Process Discovery
T1018: Remote System Discovery
T1082: System Information Discovery
T1016: System Network Configuration Discovery
10 TA0008: Lateral Movement T1021: Remote Services
T1550: Use Alternate Authentication Material
11 TA0009: Collection T1560: Archive Collected Data
T1213: Data from Information Repositories
T1005: Data from Local System
T1074: Data Staged
T1114: Email Collection
12 TA0011: Command and Control T1071: Application Layer Protocol
T1001: Data Obfuscation
T1568: Dynamic Resolution
T1573: Encrypted Channel
T1105: Ingress Tool Transfer
T1095: Non-Application Layer Protocol
T1090: Proxy
T1102: Web Service
13 TA0010: Exfiltration T1048: Exfiltration Over Alternative Protocol

Following are the TTPs of Wizard Spider based on the MITRE Attack Framework:

Sr No. Tactic Technique
1 TA0042: Resource Development T1588: Obtain Capabilities
2 TA0001: Initial Access T1133: External Remote Services
T1566: Phishing
T1078: Valid Accounts
3 TA0002: Execution T1059: Command and Scripting Interpreter
T1053: Scheduled Task/Job
T1569: System Services
T1204: User Execution
T1047: Windows Management Instrumentation
4 TA0003: Persistence T1547: Boot or Logon Autostart Execution
T1543: Create or Modify System Process
T1133: External Remote Services
T1053: Scheduled Task/Job
T1078: Valid Accounts
5 TA0004: Privilege Escalation T1547: Boot or Logon Autostart Execution
T1543: Create or Modify System Process
T1055: Process Injection
T1053: Scheduled Task/Job
T1078: Valid Accounts
6 TA0005: Defense Evasion T1222: File and Directory Permissions Modification
T1562: Impair Defenses
T1070: Indicator Removal on Host
T1036: Masquerading
T1112: Modify Registry
T1027: Obfuscated Files or Information
T1055: Process Injection
T1553: Subvert Trust Controls
T1078: Valid Accounts
7 TA0006: Credential Access T1557: Adversary-in-the-Middle
T1003: OS Credential Dumping
T1558: Steal or Forge Kerberos Tickets
8 TA0007: Discovery T1087: Account Discovery
T1135: Network Share Discovery
T1018: Remote System Discovery
T1082: System Information Discovery
T1016: System Network Configuration Discovery
T1033: System Owner/User Discovery
9 TA0008: Lateral Movement T1210: Exploitation of Remote Services
T1570: Lateral Tool Transfer
T1021: Remote Services
10 TA0009: Collection T1557: Adversary-in-the-Middle
T1074: Data Staged
11 TA0011: Command and Control T1071: Application Layer Protocol
12 TA0010: Exfiltration T1048: Exfiltration Over Alternative Protocol
T1041: Exfiltration Over C2 Channel
13 TA0040: Impact T1489: Service Stop

Sigma Rules:

Rule 1:
title: Suspicious Call by Ordinal
id: e79a9e79-eb72-4e78-a628-0e7e8f59e89c
description: Detects suspicious calls of DLLs in rundll32.dll exports by ordinal
status: stable
tags:
– attack.defense_evasion
– attack.t1218.011
logsource:
category: process_creation
product: windows
detection:
selection:
Image|endswith: ‘\rundll32.exe’
CommandLine|contains:
– ‘,#’
– ‘, #’
– ‘.dll #’ # Sysmon removes , in its log
– ‘.ocx #’ # HermeticWizard
filter:
CommandLine|contains|all:
– ‘EDGEHTML.dll’
– ‘#141’
condition: selection and not filter
falsepositives:
– False positives depend on scripts and administrative tools used in the monitored environment
– Windows control panel elements have been identified as source (mmc)
level: high

Rule 2:
title: LOLBAS rundll32 without expected arguments (via cmdline)
description: Detects use of rundll32 as a LOLBAS binary where rundll32 is passed unexpected arguments such as a .iso instead of .dll (i.e. rundll32.exe test.iso, evilexport).
tags:
– attack.defense_evasion
– attack.execution
– attack.t1036
– attack.t1085
logsource:
category: process_creation
product: windows
detection:
selection_image:

Image|endswith: ‘\rundll32.exe’
filter:
CommandLine|contains:
– ‘.dll’
– ‘.cpl’
– ‘-localserver’
filter_re:
CommandLine|re: ‘.*[Mm][Ss][Ii][0-9A-Z]{4}\.[Tt][Mm][Pp].*’
condition: selection_image AND NOT (filter or filter_re)
falsepositives:
– none
level: medium

Rule 3:
title: Net.exe Execution
id: 183e7ea8-ac4b-4c23-9aec-b3dac4e401ac
status: experimental
description: Detects execution of Net.exe, whether suspicious or benign.
tags:
– attack.discovery
– attack.t1049
– attack.t1018
– attack.t1135
– attack.t1201
– attack.t1069.001
– attack.t1069.002
– attack.t1087.001
– attack.t1087.002
– attack.lateral_movement
– attack.t1021.002
– attack.t1077 # an old one
– attack.s0039
logsource:
category: process_creation
product: windows
detection:
selection:
Image|endswith:
– ‘\net.exe’
– ‘\net1.exe’
cmdline:
CommandLine|contains:
– ‘ group’
– ‘ localgroup’
– ‘ user’
– ‘ view’
– ‘ share’
– ‘ accounts’
– ‘ stop ‘
condition: selection and cmdline
fields:
– ComputerName
– User
– CommandLine
– ParentCommandLine
falsepositives:
– Will need to be tuned. If using Splunk, I recommend | stats count by Computer,CommandLine following the search for easy hunting by computer/CommandLine.
level: low

Rule 4:
title: Stop Windows Service
id: eb87818d-db5d-49cc-a987-d5da331fbd90
description: Detects a windows service to be stopped
status: experimental
tags:
– attack.impact
– attack.t1489
logsource:
category: process_creation
product: windows
detection:
selection:
Image|endswith:

– ‘\sc.exe’
– ‘\net.exe’
– ‘\net1.exe’
CommandLine|contains: ‘stop’
filter:
CommandLine: ‘sc stop KSCWebConsoleMessageQueue’ # kaspersky Security Center Web Console double space between sc and stop
User|startswith:
– ‘NT AUTHORITY\SYSTEM’
– ‘AUTORITE NT\Sys’ # French language settings
condition: selection and not filter
fields:
– ComputerName
– User
– CommandLine
falsepositives:
– Administrator shutting down the service due to upgrade or removal purposes
level: low

Source: Surface Web
 

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.