Banks, telecommunications companies and government organizations in the US, South America, Europe and Africa are among the top targets, with the notorious GCMAN and Carbanak groups among the main suspects.
Kaspersky Lab experts have discovered a series of “invisible” targeted attacks that use only legitimate software: widely available tools for penetration testing and management tools, as well as the PowerShell collaboration framework for automating tasks in Windows – with no malware files on the hard drive, but hiding in memory. This combined approach helps to avoid detection by whitelisting technologies and leaves researchers with almost no malware artifacts or samples to work with.
Attackers remain on the system for a long time with the aim of gathering information before their traces disappear from it after the first reboot.
In late 2016, banks contacted Kaspersky Lab experts in the CIS, who detected Meterpreter (a penetration testing tool that is now often used for malicious purposes) in the memory of their servers at times when it was not supposed to be there. Kaspersky Lab discovered that the Meterpreter code was combined with a number of legitimate PowerShell scripts and other utilities. The combined tools were adapted into malicious code that could hide in memory, invisibly collecting the passwords of system administrators, so that attackers would be able to remotely control the victim’s systems. The ultimate goal appears to be to gain access to financial processes.
Kaspersky Lab has since revealed that these attacks are occurring on a massive scale: hitting over 140 enterprise networks across various business sectors, with most victims located in the US, France, Ecuador, Kenya, the UK and Russia.
The geography of organizations attacked by the discovered method
In total, "infections" have been recorded in 40 countries.
It is still not known who is behind the attacks. The use of open source exploits, common Windows utilities, and unknown locations make it nearly impossible to determine which group was responsible – or even whether it was a single group or multiple groups sharing the same tools. Known groups with the most similar approaches are GCMAN and Carbanak.
Such tools also make it more difficult to uncover the details of the attack. The usual procedure when dealing with incidents is for an investigator to follow the traces and samples left on the network by the attackers. And while data on the hard drive can remain available for a year after the event, objects hidden in memory will be erased with the first reboot of the computer. Fortunately, in this case, the experts got to them in time.
“The determination of attackers to hide their activity and make detection and response to incidents increasingly difficult explains the recent trend of anti-forensic techniques and malware based on device memory. This is why forensic research on memory is becoming critical for analyzing malware and its operations. In these specific incidents, the attackers used every possible anti-forensic technique, demonstrating that there are no malware files required to successfully exfiltrate data from a network, and how the use of legitimate and open-source utilities makes the feat almost impossible,” said Sergey Golovanov, Principal Security Researcher at Kaspersky Lab.
Attackers are still active, so it is important to note that detecting such an attack is only possible in RAM, network, and registry – and that, in such cases, using Yara rules based on malicious file scanning is of no use.
Details about the second part of the operation, which shows how attackers apply unique tactics to withdraw money via ATMs, will be presented by Sergey Golovanov and Igor Soumenkov at the Security Analyst Summit, which will take place from April 2 to 6, 2017.
Kaspersky Lab products detect operations using the above tactics, techniques and processes. More information about this story and Yara’s rules for forensic analysis can be found on the dedicated blog on the Securelist.com. Technical details, including Indicators of Compromise, are also provided to Kaspersky Intelligence Services customers .
