HomeSecurityFancy Bear is back with renewed backdoor malware

Fancy Bear is back with updated backdoor malware

A recent attack campaign launched by Fancy Bear has revealed an updated toolkit that includes a backdoor written in a new language. Fancy Bear, also known as APT28, Sednit, Sofacy, and Strontium, is an APT ) group that has been linked to a number of politically motivated attacks. Previous APT victims include the U.S. Democratic National Committee (DNC), the World Anti-Doping Agency (WADA), the Ukrainian military, the International Association of Athletics Federations (IAAF), and various government entities. Fancy Bear is believed to be a Russian group and has been operating since at least 2004, constantly developing and changing its arsenal, including a variety of malware payloads such as Trojans and UEFI rootkits.

Fancy Bear

The cyberattackers may also have connections to Earworm, another politically motivated group, given its use of shared command-and-control (C2) servers. A new Fancy Bear campaign has been discovered by ESET. The group uses phishing emails containing malicious payloads, as well as a new backdoor system.

A new programming language, Nim, has been added, which was designed to bring together aspects of Python, Ada, and Modula. One of the malware downloaders has been written in Nim.

The phishing email contains a Word that is empty, but refers to a remote template hosted on Dropbox, wordData.dotm. The template has embedded malicious macros that run lmss.exe, the new Nim downloader for the Zebrocy Trojan. Another downloader is loaded by the Nim module. This payload is written in Golang and is based on Delphi code.

In total, six malicious modules are included in the attack chain before the final deployment of a backdoor . The hackers will use these elements to collect basic information for transfer to their C2, as well as to take screenshots every 35 seconds during the first few minutes of the infection, and eventually manage to grab additional payloads and commands from the C2.

“It appears that the Sednit team is porting the original code to other languages ​​or rewriting it, in the hope of avoiding detection,” ESET says. “It’s probably easier this way and it means they don’t have to change their entire TTP [Tactics, Techniques and Procedures]. The original compromise vector remains unchanged, but using a service like Dropbox to download a remote template is unusual for the team.”

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS