Kaspersky Lab researchers are observing a new and rather significant trend in how sophisticated threat actors operate. It is increasingly common for threat actors to not use sophisticated and costly attack techniques, such as zero-day vulnerabilities, but to use highly targeted social engineering campaigns in combination with known effective malicious techniques. 
As a result, they are able to exploit malicious campaigns that are extremely difficult to detect with standard enterprise quality assurance solutions.
This shift in the way threat actors operate demonstrates that, in general, the IT infrastructure of modern organizations contains enough vulnerabilities to allow attackers with relatively inexpensive attack tools to achieve their criminal goals. Microcin, a malicious campaign recently investigated by Kaspersky Lab experts, is an example of such a low-cost, yet dangerous attack.
It all started when the Kaspersky Anti Targeted Attack Platform (KATA) discovered a suspicious RTF file. The file contained an exploit (malicious software that exploits security weaknesses in widely used software to install additional malicious components) to a known and already patched vulnerability in Microsoft Office. It is not uncommon for regular cybercriminals to use exploits of known vulnerabilities to “infect” their victims with common, massively distributed malware, but as a more detailed investigation showed, this particular RTF file was not part of another large wave of “infection”, but a much more sophisticated and highly targeted campaign.
The suspected spear-phishing document was distributed via websites for a very specific group of people: forums for discussing issues related to receiving subsidized housing – an exemption available primarily to employees of government and military organizations in Russia and some neighboring countries.
When the exploit is activated, a modular malware program is installed on the target computer. The module is installed via malicious injection into iexplorer.exe, and the automatic execution of this module is accomplished via dll-hijacking. Both are well-known and widely used malicious techniques.
Finally, once the main module is installed, a number of additional modules are “downloaded” from the command and control server. At least one of these uses steganography – the practice of hiding information within seemingly innocuous files, such as images, another well-known malicious technique for secretly transferring data.
Once the entire malicious platform is deployed, the malware looks for files with extensions such as .doc, .ppt, .xls, .docx, .pptx, .xlsx, .pdf, .txt, and .rtf., which are then bundled into a password-protected file and transferred to the attack operators. In addition to using known “infection” and lateral movement techniques, when conducting the attacks, the perpetrators actively use known backdoors that have been observed in previous attacks and also use legitimate tools created for penetration testing and generally not detected as malicious by security solutions.
“When broken down into parts, this attack is nothing serious. Almost every piece of it is well documented by the security industry, and is relatively easy to detect. However, they are combined in a way that makes it difficult to attack. Most importantly, this malicious campaign is not unique. It seems that some cyber espionage threat actors are shifting their focus from developing malicious tools that are difficult to detect, to designing and delivering sophisticated functionality, which may not involve complex malware, but are still dangerous,” said Alexey Shulmin, Lead malware analyst at Kaspersky Lab.
In order to protect their information systems from attacks like Microcin, Kaspersky Lab experts advise organizations to use security tools that allow for the detection of malicious operations rather than malware.
Such complex solutions, such as the Kaspersky Anti-Targeted Attack, include not only endpoint protection technologies but also technologies that allow monitoring and correlation of events across different parts of the organization's network, thereby identifying malicious patterns present in sophisticated targeted attacks.
Kaspersky Lab products successfully detect and block Microcin and similar campaigns.
Details of the Microcin campaign can be found at the dedicated Securelist.com, which also includes further technical information about the attack.
