Kaspersky Lab’s Global Research and Analysis Team has discovered a new, sophisticated wiper (malware that deletes files), called StoneDrill. Just like another notorious wiper, Shamoon, it destroys everything on an “infected” computer. StoneDrill also has advanced anti-detection techniques and spying tools in its arsenal.
Besides the targets in the Middle East, a StoneDrill target has also been discovered in Europe, where the wipers used in the Middle East had not previously been identified in a free state.
In 2012, the Shamoon wiper (also known as Disttrack) gained attention by destroying approximately 35,000 computers at an oil and gas company in the Middle East. This devastating attack left 10% of the world’s oil supplies at potential risk. However, the incident was a one-off, and the operator was subsequently shut down. In late 2016, it returned in the form of Shamoon 2.0 – a much more extensive malware campaign using a “heavily” updated version of the malware from 2012.
Exploring these attacks, Kaspersky Lab researchers unexpectedly discovered a malicious software that was shaped in a similar style to Shamoon 2.0. At the same time, it was very different and more advanced than Shamoon. They named it StoneDrill.
StoneDrill – a wiper with interfaces
It is not yet known how StoneDrill spreads, but once it attacks the target device, it injects itself into the memory logging system of the user's selected browser. During this process, it uses two advanced anti-emulation techniques aimed at deceiving the security solutions installed on the victim's computer. The malicious software then begins destroying the computer's disk files.
So far, at least two targets of the StoneDrill wiper have been identified, one based in the Middle East and the other in Europe.
Besides the file deletion functionality, researchers at Kaspersky Lab have also identified a backdoor of StoneDrill, which appears to have been developed by the same code creators and is used for espionage purposes. The experts discovered four command and control tables that were used by attackers to conduct espionage operations with the help of the StoneDrill backdoor against an unknown number of targets.
Perhaps the most interesting fact regarding StoneDrill is that it appears to be linked to many other wipers and espionage activities that were observed in the past. When researchers at Kaspersky Lab discovered StoneDrill with the help of Yara rules that were created to detect unknown samples of Shamoon, they realized they were looking for a unique piece of malicious code that appears to have been created separately from Shamoon. Even if the two families – Shamoon and StoneDrill – do not share exactly the same code base, the mindset of their creators and their programming style seem to be similar. For this reason it was also possible to detect StoneDrill with the Yara rules that had been developed for Shamoon.
Similarities in the code were also observed with earlier known malicious software, but this time not between Shamoon and StoneDrill. In fact, StoneDrill uses certain code segments that have previously been identified in the NewsBeef APT, also known as Charming Kitten, another malware campaign that has been highly active in recent years.
“Our interest in the similarities and comparisons between these three malicious activities was very high. Was StoneDrill another file-deleting malware developed by the Shamoon? Or are StoneDrill and Shamoon two different and unrelated groups that just happened to be targeting organizations in Saudi Arabia at the same time? Or, two groups that are separate but aligned in their goals? The latter theory is the most likely: based on the findings, we can say that while Shamoon incorporates linguistic fragments from Arabic resources, as well as resources from Yemen, StoneDrill mainly incorporates linguistic fragments from resources of Persian origin. Geopolitical analysts would likely be quick to point out that both Iran and Yemen are players in the “proxy war” between Iran and Saudi Arabia, and Saudi Arabia is the country where most of the victims of these acts have been found. But of course, we do not rule out the possibility that these findings are “false flags,” said David Emm, Senior Security Researcher at Kaspersky Lab.
To protect organizations from such attacks, Kaspersky Lab security experts advise the following:
- Conduct a security assessment of the control network (i.e., a security audit, penetration testing, gap analysis) to identify and remediate any security gaps. Additionally, it is recommended to re‑evaluate external suppliers and third‑party security policies in case they have direct access to the control network.
- Ask for external intelligence: intelligence from trusted suppliers helps organizations predict future attacks on the company's industrial infrastructure. Emergency response teams, such as the Kaspersky Lab's ICS CERT team, provide inter‑professional intelligence for free.
- Train your employees, paying particular attention to operational and technical staff and raising awareness around recent threats and attacks.
- Providing protection inside and outside the perimeter. A proper security strategy must have significant resources for attack detection and response in order to prevent an attack before it reaches especially important and critical assets.
- Evaluate advanced protection methods: including regular integrity checks for controllers, as well as specialized network monitoring to increase the overall security of the company and reduce the likelihood of a successful breach, even if some inherently vulnerable nodes cannot be repaired or removed.
For more information about Shamoon 2.0 and StoneDrill, you can read the blogpost available on the dedicated website Securelist.com. More information about Shamoon attacks can be found here.
