HomeinetKaspersky Lab: Miniduke is active again

Kaspersky Lab: Miniduke is back

researchers Kaspersky Lab have discovered that legacy Miniduke implants from 2013 are still being used in active cyber campaigns against government agencies and other entities. In addition, Miniduke’s new platform, called BotGenStudio, can now be used not only by cybercriminals launching Advanced Persistent Threat (APT) attacks, but also by law enforcement agencies and traditional criminals.

Kaspersky Lab Miniduke security Kaspersky Lab Kaspersky Lab Kaspersky Lab

Last year, in the wake of the announcement made by Kaspersky Lab and its partner, CrySyS Lab, the Miniduke APT attackers stopped their campaign, or at least reduced its intensity. However, in early 2014, Miniduke became fully active again. This time, Kaspersky Lab experts have noticed changes in the attackers’ modus operandi and the tools they use.

After the 2013 revelation, the perpetrators behind Miniduke began using another custom backdoor, which has the ability to intercept various types of information. The malware “tweaks” popular applications designed to run “deep” in systems, including file information, icons, and even file size.

Unique features

The main "new" Miniduke backdoor ( also known as TinyBaron or CosmicDuke ) is created using a customizable framework called BotGenStudio , which has the flexibility to enable or disable features when the bot is ready. The malware is able to intercept a wide range of information. The backdoor also has many other capabilities, such as the functions: keylogger , collecting general network information, capturing screen snapshots, recording keystrokes, extracting information from Microsoft and Windows Address Book , intercepting passwords for Skype , extracting information from Google Chrome , Google Talk , Opera , TheBat !, Firefox and Thunderbird , as well as intercepting confidential information from protected storage systems , as well as extracting certificates/private keys, etc.

The malware makes various network connections to extract data, including FTP uploads and three different variations of HTTP communication mechanisms. The storage of extracted data is another interesting feature of MiniDuke. When a file is uploaded to the Command & Control server, it is split into small pieces (about 3Kb), which are compressed, encrypted, and placed in a containerbefore the upload is complete. If the file is large enough, it can be placed in several different containers that are uploaded independently. All these layers of additional processing guarantee that very few researchers will be able to access the original data.

Each MiniDuke victim is assigned a unique ID, which allows specific updates to be pushed to each victim individually. For self-protection, the malware uses a custom obfuscated loader that has a high impact on CPU resources before executing the payload. In this way, the perpetrators prevented anti-malware solutions from analyzing the implant and detecting malicious operation via simulator. This also complicates the analysis of the malware.

C&C – dual purpose

During the analysis, Kaspersky Lab experts managed to obtain a copy of one of the CosmicDuke command and control ( C & C ) servers . It appears that it was used not only for communication between those behind CosmicDuke and the infected computers, but also for other activities of the group members, including hacking into other servers on the Internet, with the aim of collecting any information or media that could lead to potential targets. For this purpose, the C & C server was equipped with a number of available hacking tools to search for vulnerabilities in websites using different engines in order to attack them.

The victims

Interestingly, while the older Miniduke were primarily used against government targets, the new CosmicDuke have a different typology of victims. In addition to government organizations, they also target diplomatic missions, the energy sector, telecommunications, military equipment suppliers, and individuals involved in the trafficking and sale of illegal and controlled substances.

Kaspersky Lab experts analyzed both CosmicDuke and Miniduke servers . From the latter, Kaspersky Lab experts were able to extract a list of victims and the countries they corresponded to, and thus the experts discovered that users of the legacy Miniduke servers were interested in targets in Australia, Belgium, France, Germany, Hungary, the Netherlands, Spain, Ukraine, and the USA. The victims in at least three of these countries fall into the category of “government targets.”

One of the CosmicDuke servers analyzed had a long list of victims (139 unique IP), starting in April 2012. In terms of geographical distribution, the ten countries where the most victims were found are Georgia, Russia, the United States, Great Britain, Kazakhstan, Belarus, Cyprus, Ukraine and Lithuania. The attackers also showed a slight interest in expanding their activities and scanned IP and servers in Azerbaijan, Greece and Ukraine.

Trading platform

The most unusual victims discovered were individuals who appeared to be involved in the trafficking and sale of controlled and illegal substances, such as steroids and hormones. These victims were only observed in Russia.

“It’s a bit unexpected – normally, when we hear about APT attacks , we tend to think that these are state-sponsored cyber espionage campaigns. But we see two explanations for this. One possibility is that the BotGenStudio malware platform used in Miniduke is also available as one of the so-called ‘legitimate spyware tools ’, such as HackingTeam ’s RCS , which is widely used by law enforcement agencies. Another possibility is that the platform is simply available in the underworld and is being bought by various pharmaceutical competitors to spy on each other,” commented Vitaly Kamluk , Principal Security Researcher in the Global Research & Analysis Team at Kaspersky Lab . 

Localization

Kaspersky Lab products detect the CosmicDuke backdoor , under the codenames Backdoor.Win32.CosmicDuke.gen and Backdoor.Win32.Generic .​​ ​​

For Securelist.com.more information, read Kaspersky Lab 's blog at

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS