Kaspersky Lab is pleased to announce its contribution, together with Novetta and other partners from the broader security industry, to “Operation Blockbuster”. The aim of the operation is to stop the activity of the Lazarus Group, an extremely dangerous malicious actor responsible for data destruction as well as traditional digital espionage operations against many companies around the world. These attackers are believed to be behind the attack on Sony Pictures Entertainment in 2014, as well as the DarkSeoul campaign, which targeted media and financial institutions in 2013.
Following the notoriously devastating attack on Sony Pictures Entertainment (SPE), one of the most famous film production companies, in 2014, Kaspersky Lab’s Global Research and Analysis Team (GReAT) began investigating samples of the publicly known Destover malware used in the attack. This led to further investigation into a series of related cyber espionage and sabotage campaigns targeting financial institutions, media outlets, and manufacturing companies, among others.
Based on common features observed across different malware families, the company’s experts were able to group dozens of individual attacks together and conclude that they all belonged to a single threat actor. This was confirmed by analysis conducted by other participants in “Operation Blockbuster.”.
The Lazarus Group threat actor was active several years before the Sony Pictures Entertainment incident, and appears to still be active. Kaspersky Lab and other participants in “Operation Blockbuster” confirm a connection between malware used in various campaigns, including Operation DarkSeoul against Seoul-based banks and broadcasters, Operation Troy targeting military forces in South Korea, and the Sony Pictures Entertainment incident.
During the investigation, Kaspersky Lab researchers exchanged preliminary findings with AlienVault Labs. Gradually, researchers from both companies decided to join forces and conduct the investigation together. At the same time, the Lazarus Group’s activity became the subject of investigation by many other companies and security experts. One of these companies, Novetta, launched an initiative aimed at publishing the most comprehensive and actionable information about the Lazarus Group’s activity. As part of “Operation Blockbuster,” together with Novetta, AlienVault Labs and other industry partners, Kaspersky Lab is publishing its findings for the benefit of the wider public.
Kaspersky Lab: Looking for a flea in thehaystack …
By analyzing multiple malware samples detected in different cybersecurity incidents and creating specific detection rules, Kaspersky Lab, AlienVault and other experts from Operation Blockbuster were able to identify a series of attacks by the Lazarus Group.
The linking and grouping of multiple samples into a single group emerged during the analysis of the methods used by this actor. In particular, it was discovered that the attackers were actively reusing code. Specifically, they were “borrowing” pieces of code from one malicious program to use in another.
Beyond that, the researchers were able to identify similarities in the attackers’ modus operandi. While analyzing objects from different attacks, they discovered that all droppers (special files used to install different variants of a malicious payload) kept their payloads inside a password-protected ZIP file. The password for the files used in different campaigns was the same and was embedded within the dropper. The password protection was implemented to prevent automated systems from extracting and analyzing the payload, but in reality it simply helped researchers identify the group.
A special method used by criminals to erase traces of their presence from an “infected” system, as well as some techniques used to avoid detection by antivirus products, gave researchers additional means to group related attacks. Eventually, dozens of different targeted attacks, whose operators had been considered unknown, were linked to a single threat actor.
Kaspersky Lab: The "geography" of the Enterprise
Analysis of the sample collection dates showed that the first ones could have been written as early as 2009, several years before the infamous attack on Sony Pictures Entertainment. The number of new samples has increased dynamically since 2010. This characterizes the Lazarus Group as a stable threat actor with a long history of activity. Based on the metadata obtained from the samples investigated, most of the malware used by the Lazarus Group appears to have been written during business hours, in the GMT + 8 and GMT + 9 time zones.
“As we predicted, the number of data-destroying attacks is steadily growing. This type of malware is proving to be an extremely effective type of cyber-weapon. The power to “wipe” thousands of computers at the click of a button is a significant reward for a Computer Network Exploitation team tasked with disinformation and disruption of a target business. Its value as part of a “hybrid warfare” strategy, where such attacks are combined with physical attacks to paralyze a country’s infrastructure, remains an interesting “thought experiment,” but one that is closer to reality than we realize – and one we cannot be comfortable with. Together with our security industry partners, we are proud to have delivered a powerful blow to the operations of a rogue actor eager to exploit these destructive techniques,” said Juan Guerrero, Senior Security Researcher at Kaspersky Lab.
“This entity has the necessary capabilities and determination to execute digital espionage operations, with the aim of stealing data or causing damage. Combining this with the use of disinformation and deception techniques, the attackers have been able to successfully carry out several operations in recent years,” said Jaime Blasco, Chief Scientist at AlienVault. “Operation Blockbuster is an example of how our industry, through information sharing and collaboration, can raise the bar and prevent such entities from continuing their activities,” he added.
“Through Operation Blockbuster, Novetta, Kaspersky Lab and our partners continue our efforts to establish a methodology to disrupt the activities of global threat actors and limit their efforts to cause further damage,” said Andre Ludwig, Senior Technical Director of Novetta Threat Research and Interdiction Group. “The level of in-depth technical analysis conducted for Operation Blockbuster is rare, and the fact that we shared our findings with other industry partners for the benefit of all is even rarer,” he concluded.
More details about Kaspersky Lab's findings on the Lazarus Group's activities are available on Securelist.com.
More details about Novetta's findings on the Lazarus Group's activities are available at www.OperationBlockbuster.com.
