HomeSecurityTrickBot gang is now a malware supplier for North Korean hackers

TrickBot gang is now a malware supplier to North Korean hackers

A report published today reveals that North Korean government-backed hacking units are leasing access to elite hacking tools and access to hacked networks from operators of the TrickBot botnet.

The revelation comes as a confirmation of a trend that has been observed in recent years – namely that the lines between tactical cybercrime and national government espionage operations are blurring. This trend came to light in 2017 when a report revealed how the mastermind behind the GameOver Zeus malware helped Russian intelligence collect sensitive documents from the computers it infected.

But Bogatchev was not an isolated case. Just last week, the US arrested the operator of the Dridex malware botnet, charging him with the same thing – collaborating with Russia’s state intelligence agency in the search for sensitive data.

These two cases show direct contact between the creators of popular malware and a country's intelligence gathering.

malware

In reality, those lines have blurred to a much lower level. For years, we’ve seen nation-state hacking groups adopt malicious products. Rather than develop their own tools, state-owned operators choose to buy malware that’s already available for sale online.

This helps them conceal “targeted” operations, carried out by financially motivated hackers.

In a report published today by cybersecurity firm SentinelOne, we learn of a new connection between a state-backed support group (North Korea's Lazarus Group) and TrickBot.

According to SentinelOne, the Lazarus group has recently become a client of the TrickBot gang, from which it leases access to already infected systems, along with a new type of attack framework that researchers call Anchor. SentinelOne describes Anchor as “a collection of tools” that are combined together into a new malware strain. The Anchor malware strain is delivered as a TrickBot module.

TrickBot is one of the top three malware botnets today, along with Emotet and Dridex. It is a giant network of computers infected with the TrojanBot trojan. However, TrickBot is also a Cybercrime-as-a-Service operation. The TrickBot gang rents access to computers infected with TrickBot to other malware gangs.

These gangs range from ransomware operators to online spammers, scammers, and more. Tenants can use the TrickBot trojan to install their own malware or one of the available TrickBot modules, depending on the operations they wish to perform on infected hosts.

In reports published today by Cybereason and SentinelOne, the two companies say that Anchor is a new TrickBot module built for a specific market, specifically for hackers who want to remain undetected on the systems they infect.

TrickBot is a tool used in attacks targeting large companies, where hackers need to remain undetectable for weeks or months – while stealing data – and even long after the intrusion is over.

SentinelOne describes Anchor as “an all-in-one attack framework designed to attack enterprise environments.” It consists of different submodules that provide the various features needed for targeted attacks, but have no utility for TrickBot’s other clients.

At first glance, Anchor looks like a tool that the TrickBot team developed for hacker groups interested in financial espionage or for operators of POS malware handlers.

SentinelOne said it linked the attacks carried out by North Korea's Lazarus Group to TrickBot and the new Anchor attack framework.

In the report it published today, SentinelOne said it found a case where the Lazarus group appears to have rented access to an infected system through the TrickBot botnet and then used the Attack Anchor framework (TrickBot Module) to install PowerRatankba, a PowerShell backdoor from a hacked company, on the network.

SentinelOne did not elaborate on what the Lazarus Group did to the company's network it hacked, but North Korean hackers are known for conducting cyberattacks . However, North Korean hackers were not Anchor's only clients.

Cybereason did not see the Lazarus Group using Anchor, but instead saw “a new wave of targeted campaigns against financial, construction, and retail businesses that began in early October” where Anchor had been used.

“Unlike previously reported related Trickbot attacks that result in mass ransomware infection, this new wave of attacks focuses on stealing sensitive information from POS (Point of Sale) systems and other sensitive resources on victims’ networks, rather than on the entire network,” the Cybereason team said.

"These attacks further highlight the risk posed by malware infections that can sometimes be underestimated, due to their common nature and high volume," the researchers added.

“It is important to remember that once an endpoint is infected with malware, it is up to the attackers to decide whether to proceed.”

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS