HomeSecurityDesert Falcons the first Arab digital espionage group with thousands of victims worldwide

Desert Falcons, the first Arab digital espionage group with thousands of victims worldwide

Kaspersky Lab's Global Research and Analysis Team reveals the activities of the Desert Falcons group, a digital espionage organization targeting multiple high-profile organizations and individuals from Middle Eastern countries. falcon

Kaspersky Lab experts consider this organization to be the first known Arab group of “digital mercenaries” who have developed and carried out comprehensive digital espionage operations.

  • The campaign has been active for at least two years. The Desert Falcons began to develop and consolidate its operations in 2011. However, the beginning of the group's main activity and malware infections isplaced in 2013. The peak of their activity is recorded in early 2015.
  • The vast majority of targets are located in Egypt, Palestine, Israel and Jordan.
  • In addition to the Middle Eastern countries, which were the initial targets, the Desert Falconsis also active outside of this region. In total, its members have managed to attack more than 3,000 victims, in more than 50 countries worldwide, having stolen over 1 million files.
  • Attackers are using malicious tools they have developed themselves to launch attacks on Windows devices Android.
  • Kaspersky Lab have many reasons to believe that the native language of the experts Desert Falconsis Arabic. team members

The list of victims targeted includes military and government organizations – and in particular, officials tasked with combating money laundering. The campaign also targeted executives from the healthcare and financial sectors, leading media outlets, research and educational institutions, energy and utility providers, activists and political leaders, personal security companies, and other targets holding sensitive geopolitical information.Desert Falcons

In total, Kaspersky Lab experts were able to detect signs of attacks on over 3,000in more than 50 countries, detecting the interception of over one million files. Although the attacker appears to be operating in countries such as Egypt, Palestine, Israel and Jordan, many victims were also found in Qatar, Saudi Arabia, the United Arab Emirates, Algeria, Lebanon, Norway, Turkey, Sweden, France, the United States, Russia and other countries.

Transport, "Contagion", Espionage

The main method used by the Desert Falcons group to deliver malicious payloads was spearphishing via email, social media messages, and chat messages. The phishing messages contained malicious files (or links leading to malicious files) that mimicked legitimate documents or applications. The Desert Falcons group uses various techniques to lure its victims into executing the malicious files. One of the most characteristic techniques used by the group is the so-called “Right-to-LeftOverride”.Desert Falcons

This technique exploits a special Unicode character to reverse the order of characters in a file name, hiding a malicious extension in the middle of the name and placing a fake, seemingly harmless file extension near the end of the file name. Using this technique, malicious files (.exe, .scr) look like a harmless document or PDF file, while even careful users with good technical knowledge can be tricked into running these files. For example, a file ending in “.fdp.scr”would appear as“.rcs.pdf.”

After successfully infecting the victim, Desert Falcons members use one of two different backdoors, either their main Trojan or the DHS Backdoor, which appear to have been developed from scratch and are in constant development. Kaspersky Lab experts have identified over 100 malware samples used by this group for attacks.Desert Falcons

The malicious tools used have full Backdoor functionality. Thus, they can take screenshots, intercept keystrokes, upload or download files, collect information about all Word and Excel files on a victim's hard drive or connected USB devices, intercept passwords stored in the system registry (Internet Explorer and Live Messenger), and make audio recordings. Kaspersky Lab experts also managed to detect traces of the activity of a malicious software, which appears to be a backdoor for Android, with the ability to intercept calls and SMS logs.

Using these tools, members of the Desert Falcons group created and managed at least three different malicious campaigns, targeting different victims in different countries.

A "swarm" in the hunt for secrets

Kaspersky Lab researchers estimate that at least 30 individuals, in three groups, spread across different countries, are carrying out the Desert Falcons malware campaigns.Desert Falcons

“The individuals behind this actor are extremely determined, proactive, technically savvy, and well-informed about political and cultural issues. Using only phishing emails, social engineering techniques, tools, and backdoors they developed themselves, the Desert Falcons were able to infect hundreds of high-profile victims in the Middle East region via their computers or mobile devices, as well as decrypt sensitive data. We expect this campaign to continue developing more Trojans and using even more sophisticated techniques. With sufficient funding, they could acquire or develop exploitsthat could increase the effectiveness of their attacks,”said Dmitry Bestuzhev, a security expert and member of Kaspersky Lab’s Global Research and Analysis Team.

Kaspersky Lab products successfully detect and block the malware used by the Desert Falcons group.

More information about the campaign is available at Securelist.com.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS