HomeinetTurla: uses satellites for absolute level of anonymity

Turla: uses satellites for absolute anonymity

During an investigation into the notorious Russian-speaking digital espionage actor Turla, Kaspersky Lab researchers discovered how it evades detection of its activities and physical location.

To ensure its anonymity, this group exploits security vulnerabilities in global satellite networks.Turla

Turla is a sophisticated cyber espionage group that has been active for over 8 years. The attackers behind the Turla group have infected hundreds of computers in over 45 countries, including Kazakhstan, Russia, China, Vietnam, and the United States.

Affected organizations include government agencies and embassies, military organizations, academic and research institutions, and pharmaceutical companies. In the initial stage, the Epic proceeds to develop a profile of the victims. Then – and only for the most high-level targets – the attackers use an extensive satellite-based communication mechanism in later stages of the attack, which helps them cover their tracks.

Satellite communications are best known as a tool for broadcasting television signals and for secure communications. However, they are also used to provide Internet access. These services are mainly used in remote areas, where all other types of Internet access are either unstable and slow or not available to everyone. One of the most widespread and inexpensive types of satellite Internet connections is the so-called one-way satellite connection, which only allows downloading.

In this case, outgoing requests from a user's computer are communicated via conventional lines (wired or GPRS connection), with all incoming traffic coming from the satellite.

This technology allows the user to have a relatively fast download speed. However, it has a major drawback: all downstream traffic returns to the computer unencrypted. Any unscrupulous user in possession of suitable and relatively inexpensive equipment and software could simply monitor the traffic and gain access to all the data that users of these connections "download".

The Turla group exploits this weakness in a different way, using it to hide the location of its Command & Control (C&C) servers, which are among the most important parts of the malicious infrastructure.

The C&C server is essentially the "headquarters" of the malware that runs on targeted machines. Discovering the location of such a server can lead researchers to uncover details about the actor behind an operation.

Below is how the Turla team avoids these risks:

  1. The team first "listens" to the data "download" from the satellite to identify active IP addresses of Satellite Internet users who are online at the given moment.
  2. It then selects an IP address that will be used to mask a C&C server, without the legitimate user having any knowledge of it.
  3. The machines that have been “infected” by the Turla carrier are then instructed to transfer the data to the selected IP addresses of the Satellite Internet users. The data travels through conventional lines to the Satellite Internet provider’s telecommunications, reaches the satellite and, finally, from the satellite reaches the users with the selected IP addresses.

Interestingly, the legitimate user whose IP address has been used by the attackers to receive data from an “infected” machine will also receive these data packets, but will barely notice them. This is because the Turla attackers assign “infected” machines to send data to ports that, in most cases, are closed by default. Thus, the legitimate user’s computer will simply discard these packets, while the Turla C&C server, which keeps these ports open, will receive and process the “stolen” data.serpent map 4 hires

Another interesting aspect of Turla’s tactics is that it tends to use satellite internet providers based in the Middle East and Africa. In their research, Kaspersky Lab experts have identified the Turla group using IP addresses from providers located in countries such as Congo, Lebanon, Libya, Niger, Nigeria, Somalia or the United Arab Emirates.

The satellite beams used by providers in these countries usually do not cover areas of Europe and North America, which makes investigating such attacks very difficult for most security researchers.

“In the past, we have encountered at least three different actors using satellite connections to cover their activities. Of these, the solution developed by the Turla team is the most interesting and unusual. It is able to reach the absolute level of anonymity, leveraging a widely used technology, one-way satellite Internet. Attackers can be located anywhere within the range of their chosen satellite, that is, within an area that can cover thousands of square kilometers,” said Stefan Tanase, Senior Security Researcher at Kaspersky Lab. He continued by commenting: “This makes it almost impossible to track the attacker. As the use of these methods becomes increasingly popular, it is important for system administrators to develop sound defense strategies in order to mitigate attacks.”

Kaspersky Lab products detect and block malware used by the Turla threat agent with the codenames: Backdoor.Win32.Turla*, Rootkit.Win32.Turla*, HEUR:Trojan.Win32.Epiccosplay.gen and HEUR: Trojan .Win32.Generic.

For more information on the satellite link abuse mechanisms used by the digital espionage group Turla, as well as to view the Indicators of Compromise, you can visit the Securelist.com.

Watch videos and learn more about how Kaspersky Lab products can help protect against the Turla group's activities on the company's dedicated website .

Also, more information about the activities of other Russian-speaking digital espionage groups is available on another dedicated Kaspersky Lab website

For more information on investigating advanced targeted attacks, you can watch a short video from Kaspersky Lab.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS