On Wednesday, the Kaspersky Security Analyst Summit was held in Singapore. There, researchers revealed that the company had discovered a new spyware with a number of plugins for espionage purposes. Its name is Tajmahal. Tajmahal can do a lot more than other spyware. In addition to keylogging and screengrabbing, Tajmahal can monitor documents that are scheduled to be printed and steal files automatically when a USB is connected to the infected device.
According to Kaspersky, there does not appear to be any known state-owned hacking group behind this unique spyware toolkit.
The most interesting thing is that this spyware has managed to go unnoticed for 5 whole years. It was first detected last fall, on the network of the embassy of a Central Asian country. However, it is almost certain that it is used elsewhere as well. It is a very well-developed program, which has certainly targeted other victims. It is almost unlikely that it was built for a single target. Therefore, there may still be many victims that have not been discovered or there may be different versions of this malware.
One expert claims that this software is likely state-funded. There is certainly a large team of developers behind its development. Also, the fact that it went undetected for so many years and that only one victim has been known to exist means that great attention has been paid to targeting, secrecy, and security.
Kaspersky has not yet been able to link Tajmahal to any known hacking group. Furthermore, the target (Central Asia) also does not help in discovering the identity of the hackers as there are many countries that could be monitoring it, such as China, Iran, Russia and the US.
The company still doesn't understand how the hackers initially gained access to the victim's network. However, there is a backdoor program on the machines, which the hackers have dubbed Tokyo. The backdoor uses PowerShellto allow the hackers to connect to the command-and-control server and install the Tajmahal spyware payload, which has been dubbed Yokohama.
Yokohama's versatility is what sets this spyware apart. While it includes many of the usual features of government-sponsored spyware, it also has some more specialized capabilities. For example, when a USB is plugged into an infected device, the program scans its contents and uploads a list of them to the command-and-control server. The hackers then decide which files they are interested in. Meanwhile, if the USB is unplugged before the files are retrieved, TajMahal automatically monitors the USB port and, once it is plugged back in, steals the files.
It can also access files that are scheduled for printing or that are burned to CDs.
These features may not sound that impressive, but they are, if we consider that they are aimed at information that is important to the user. Saving it on a USB stick or burning it to a CD is done precisely because we consider some information important and want to protect it.
The special attention that has been paid to this particular program explains why it was not detected for so long. The Central Asian embassy seems to have been infected by the TajMahal 5 years or more ago.
