HomeinetTurla: Spying tool targets governments and diplomats

Turla: Spying tool targets governments and diplomats

A cyberespionage campaign involving the notorious Wipbot and Turla malware has been systematically targeting governments and embassies in a number of former Eastern Bloc countries. Trojan.Wipbot (also known as Tavdig) consists of a backdoor used to facilitate the identification of activity before the attacker switches to long-term surveillance using Trojan.Turla (also known as Uroboros, Snake and Carbon). It is estimated that this malware combination has been used in classic espionage activities for the past 4 years. Due to the selected targets and the sophisticated malware used, Symantec believes that a state-funded group is behind these attacks.

Turla

Turla offers the attacker powerful espionage capabilities. Set to start every time the computer boots, as soon as the user launches a Web browser, it opens a back door that allows communication with the attackers. Through this back door, the attackers can copy files from the infected computer, delete files, and load and execute other forms of malware, among other capabilities.

The group behind Turla relies on a two-pronged attack strategy that involves infecting victims via spear phishing emails and watering hole attacks. Watering hole attacks have sufficient exposure capabilities, with attackers compromising a series of legitimate websites and infecting only victims who visit them from pre-selected IP addresses. These compromised websites carry Trojan.Wipbot. It is very likely that Wipbot is then used as a downloader to deliver Turla to the victim.

Victims

While the infections initially appeared in a number of European countries, a deeper analysis revealed that several infections in Western Europe occurred on computers connected to private networks in former Eastern Bloc countries. These infections occurred in the embassies of these countries.

Analysis of the infections revealed that the attackers had focused on a small number of countries. For example, in May 2012, the office of the prime minister of a former Soviet Union member state was compromised. This infection spread quickly, and more than 60 computers in the prime minister's office were compromised.

Another attack occurred on a computer at the French embassy in another former Soviet country in late 2012.During 2013, the infection spread to other computers connected to the network of that country's foreign ministry. The interior ministry was also infected. Further investigation revealed a systematic espionage campaign targeting the diplomatic corps. Similar infections had occurred at embassies in Belgium, Ukraine, China, Jordan, Greece, Kazakhstan, Armenia, Poland, and Germany.

At least five other countries in the region have been targeted in similar attacks. While the attackers have primarily focused on the former Eastern Bloc, other targets have been found. These include the health ministry of a Western European country, the education ministry of a Central American country, a state electricity authority in the Middle East, and a health care organization in the United States.

Attack points

The group behind Turla uses spear phishing emails and watering hole-type attacks to infect its victims. Some of the spear phishing emails purported to come from a military attaché at an embassy in the Middle East and had an attached file that depicted a summary of a meeting. Opening the file automatically installed Trojan.Wipbot on the victim's computer. It is believed that Wipbot may be the access mechanism for Turla, as they are similar in structure and code.

Since September 2012, the group has compromised at least 84 legitimate websites to facilitate watering hole attacks. Websites belonging to various governments or international agencies were among those compromised by the attackers.

Turla 1

Figure 1. Spear phishing emails and watering hole attacks are used to infect victims with the .Wipbot Trojan , which can then be used to install the .Turla Trojan .

Turla

Symantec attackers has not yet been confirmed, although all activity related to the attacks indicates that most attacks occur during a business day in the UTC +4 time zone.

The Turla trojan is an evolution of an older malware,  Trojan.Minit, which began operating in 2004. The current campaign is the result of a well-trained team capable of penetrating a range of networks. It focuses on targets that would be of interest to government agencies, while its purpose is espionage and the interception of sensitive data.

Detection

Symantec has the following detection tools for the malware used in the attacks :

AV

IPS

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS