HomeSecurityStrongPity APT targets encryption software users

StrongPity APT targets encryption software users

An APT group named StrongPity has put a lot of effort into a recent campaign that targets encryption software users, such as TrueCrypt and WinRAR.

Kaspersky Lab says the group has been active for the past few years, but they were mainly exploiting zero-days to compromise targets and spying on users and their activities.

The most recent attacks, which were detected in the summer of 2016, were based on new tactics that the group had never used before.

StrongPity APT targets encryption software users

Kaspersky says the group used watering hole attacks and infected installers to reach users' computers that are generally harder to compromise because they use encryption software. This is a victim-side encryption trend that attackers are targeting.

The group is targeting two encryption software packages in different attacks. The first is WinRAR, a software package known for its archiving capabilities, but which also comes with a feature that allows users to encrypt their data using the AES algorithm and lock it inside a password-protected RAR archive.

The second is TrueCrypt, a full-disk encryption utility that locks all files on a hard drive. This software package was very popular two years ago, but most users abandoned it when its developers said the software is insecure and urged them to use other utilities instead.

Targeting users of these two software packages, StrongPity is trying to put at risk users it could not have endangered before, because they were protecting their data.

%cf%τruecrypt

Kaspersky says that StrongPity was registered to a similar domain to ralrab.com, which was very similar to the official rarlab.com website, through which the WinRAR developers distribute their software.

Using this fake domain, the APT managed to trick the administrators of the winrar.be website into linking to their own malicious version of WinRAR on the ralrab.com website, instead of the official one. Their own version of WinRAR came with a backdoor trojan, allowing the StrongPity attackers to spy on anyone who installed this altered package.

They used the same trick with the website winrar.it, but instead of linking it to the ralrab.com website, the team persuaded the winrar.it site to host the malicious version of the same files.

The two incidents occurred in May 2016, but the group did not stop there, and by September 2016 they had managed to deceive the administrators of the Tamindir software downloads website so that it redirected users who wanted to install the TrueCrypt software to the true-crypt.com website, which was controlled by the attackers.

Just like with WinRAR, the version of TrueCrypt distributed through this website contained a backdoor trojan that allowed crooks to access the user's system and steal or tamper with data.

Because the trojans were sent inside the WinRAR and TrueCrypt packages, the attackers had access to the encrypted data, which they had not had during previous attacks.

winrar

According to Kaspersky, the attacks put users from Italy, Turkey, Belgium, Algeria and France at risk, but traces of the StrongPity backdoor trojan were found across Europe, Africa and the Middle East. Researchers say that over 1,000 systems appear to have been compromised by recent StrongPity attacks.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS