HomeSecurityRussian cyber-spies use Gmail to control updated ComRAT malware

Russian cyber-spies use Gmail to control updated ComRAT malware

ESET security researchers have discovered a new version of the ComRAT backdoor that is controlled using the Gmail web interface and was used by the Russian state-backed hacker group Turla for harvesting and stealing in attacks against government institutions.

Russian cyber-spies use Gmail to control updated ComRAT malware

The use of Gmail for command-and-control purposes fits right in with other exploits by the Russian-speaking Turla group (also identified as Waterbug, Snake, or VENOMOUS BEAR) given that it is known for using unorthodox methods to achieve its cyberespionage goals.

In the past, they have developed backdoor Trojans with their own APIs designed to reverse communication flows, used comments on Britney Spears Instagram photos to control malware, sent PDF email attachments with commands to control servers infected with the Outlook , and hijacked - funded OilRig infrastructure and malware for use in their own campaigns.

Abuse of Gmail for cyber espionage

The ComRAT (also known as Agent.BTZ and Chinch) remote access trojan (RAT) is one of the oldest tools in Turla's arsenal and has been deployed in attacks dating back to at least 2007.

It rose to fame after being used to compromise US military systems in 2008, including but not limited to computers used by Central Command to oversee combat zones in Afghanistan and Iraq.

Turla uses the Gmail web user interface as one of two command and control channels for the updated malware, the other being an old HTTP comm channel.

This latest iteration of ComRAT compiled in November 2019 connects to Gmail to receive mail attachments containing encrypted commands sent by Turla operators from other email providers.

Since 2017, when the current ComRAT version was first discovered by ESET, Turla has used it in attacks against two Ministries of Foreign Affairs and a national parliament.

“ESET has found evidence that this latest version of ComRAT was still in use in early 2020, showing that the Turla group is still very active and a significant threat to diplomats and the military.”

Gmail

A Turla exclusive

While the backdoor upgrade features a completely new codebase and looks much more complex compared to previous versions, it still uses the internal name Chinch, has the old HTTP C&C protocol , and shares part of the network infrastructure with Turla's Mosquito malware.

ComRAT v4 was introduced to compromised systems using stolen credentials or other Turla backdoors, or has dropped other known malware associated with the group, such as the PowerStallion backdoor, the RPC backdoor, or a custom PowerShell loader.

Once deployed on a compromised device, ComRAT was used by Russian cybercriminals to steal confidential documents and exploited public cloud services like 4shared and OneDrive to exfiltrate stolen data .

“In one case, its operators even developed a .NET executable to interact with the victim’s central MS SQL Server database containing the organization’s documents,” ESET found.

Russian cyber-spies use Gmail to control updated ComRAT malware

They also collected and extracted information about the organization's network infrastructure, Active Directory groups, and Windows, and were observed attempting to evade security software.

Turla “frequently runs security-related logs to understand if malware samples have been detected.”

Designed to bypass security software

“This shows the level of sophistication of this group and its intention to remain on the same machines for a long time,” explained ESET researcher Matthieu Faou.

“In addition, the latest version of the ComRAT malware family, thanks to its use of the Gmail web interface, can bypass certain securitybecause it is not based on a malicious domain.

“Based on other malware samples found in the same compromises, we believe that ComRAT is used exclusively by Turla,” Faou concluded.

Earlier this month, Kaspersky also detected what it believes “with a medium to low level of confidence” to be another Turla malware, a RAT variant called COMpfun that checks using unusual HTTP status codes and is used in attacks against European diplomatic entities.

COMpfun, like early versions of ComRAT, also has the ability to infect other devices by monitoring and spreading to all removable devices connected to compromised computers.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS