HomeSecuritySecurity researchers analyze PowerShell scripts used by Russian hackers

Security researchers analyze PowerShell scripts used by Russian hackers

PowerShell

ESET security researchers are investigating PowerShell scripts used in recent attacks by a Russian hacking group called Turla.

The group's main targets are various diplomatic organizations, such as the US and French military and the German Foreign Ministry, as well as entities in the Middle East.

The group, which has also gone by other names such as Snake, Waterbug, KRYPTON, and Venomous Bear, has recently begun using PowerShell scripts to load and execute malware in an attempt to evade detection. According to Eset researchers, while the group previously used a loader based on Posh-SecMod, it has now refined its PowerShell scripts.

The team's PowerShell loader is designed to achieve persistence, decrypt the code, and load the embedded executable or library into memory. To do this, Turla uses Windows Management Instrumentation (WMI) or PowerShell profile modification.

The first method involves creating two WMI event filters and two WMI event consumers to launch PowerShell commands and load a script stored in the Windows registry. The second method involves changing the PowerShell profile, which is a script that runs when PowerShell starts and results in the execution of a PowerShell command similar to the one used in WMI consumers.

Researchers also discovered some samples from March 2019 that have modifications to bypass the Antimalware Scan Interface (AMSI), an interface that allows Windows applications to integrate with installed antimalware.

ESET revealed that hackers used PowerShell scripts to load payloads, including an RPC backdoor and a PowerShell backdoor.

The Turla group is known for its use of backdoors, which are based on the RPC protocol. The backdoors allow the group to gain control of other machines on the local network even when there is no external C&C server.

Using the RPC backdoor, hackers can upload and download files and execute commands via cmd.exe or PowerShell. The backdoor is divided into two parts and has a client, which allows hackers to execute commands on systems where a server is installed.

One of the PowerShell backdoors developed by the Turla team is PowerStallion. It is a lightweight tool that uses Microsoft's online storage service, OneDrive, as a C&C server. It also exploits the free email service, GMX.

According to ESET, the malware is used as a recovery tool. That is, hackers use it in case the main backdoors, such as Carbon or Gazer, are removed and there is no longer any access to the infected computers.

The Turla team may now be using open-source tools, but that doesn't mean they've stopped using their custom tools. In fact, the payloads, which are loaded from PowerShell scripts, as well as the RPC backdoor and PowerStallion, fall into the latter category of tools.

ESET stated that the Turla team will continue to be of concern for a long time, as they are constantly developing new and complex malware.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS