HomeSecurityLazarus Group: Steals data using MATA malware

Lazarus Group: Steals data using MATA malware

A malware framework known as MATA was recently discovered and linked to the Lazarus hacking group, and was used in attacks targeting corporate entities from multiple countries since April 2018 to deploy ransomware and steal data.

Among the targeted countries are Poland, Germany, Turkey, Korea, Japan and India, according to researchers from Kaspersky Lab's Global Research and Analysis Team (GReAT).

Lazarus Group: Steals data using MATA malware

Lazarus (also identified as HIDDEN COBRA by the United States Intelligence Community and Zinc by Microsoft) used MATA to compromise and infect systems of companies operating in various industries , including but not limited to a software development company, an internet service provider, and an e-commerce company .

While Kaspersky's report does not mention the attackers' motives, the hackers in question are known for their financial motivations as their campaigns show – they hacked Sony Films in 2014 as part of Operation Blockbuster and were behind the global WannaCry ransomware outbreak of 2017.

Since they were first identified in 2007, the Lazarus group has carried out attacks against financial institutions from India, Mexico, Pakistan, the Philippines, South Korea, Taiwan, Turkey, Chile, and Vietnam, as well as the media and technology sectors.

The MATA malware framework

MATA is a modular framework with many components, such as a loader, an orchestrator, and many plugins, and can be used to infect Windows, Linux , and macOS.

During their attacks, attackers can use MATA to load multiple plugins into commands executed in the infected system's memory, manipulate files and processes, perform DLL injection, and create HTTP.

Lazarus MATA malware ransomware

MATAs also allow attackers to scan for new targets on macOS and Linux-based computers (routers, firewalls , or IoT devices). On the macOS platform, MATA can also load a plugin_socks module that can be used to configure proxy servers.

During their analysis, Kaspersky researchers discovered that hackers use a malware loader to load an encrypted next-stage payload.

 "We are not certain that the loaded payload is the malware orchestrating the attack, but almost all victims have the loader and orchestrator on the same computer," the report explains.

Once the MATA malware is fully deployed, operators attempt to find databases with sensitive customer or business and will execute database queries to collect and remove customer lists.

While researchers had no conclusive evidence that Lazarus was actually able to steal the data they collected during attacks, exfiltrating such databases from their victims is certainly one of goals , along with the VHD ransomware as seen in the case of one of the companies that was breached.

Researchers at Qihoo 360 Netlab published a related analysis of the components of the MATA malware framework (which they named Dacls) in December 2019.

MATA's connection with the Lazarus group

The MATA framework was linked to the Lazarus APT group by Kaspersky based on unique “orchestrator” file names used in versions of the Manuscrypt trojan (also known as Volgmer).

Manuscrypt samples were publicly shared by the Department of Homeland Security (DHS) and the Federal Bureau of Investigation (FBI) in 2017 via a US-CERT malware analysis report.

Kaspersky's report also mentions similar global configuration data that MATA shares with Lazarus' Manuscrypt trojan, such as "a randomly generated session ID, date-based version information, a wait time, and multiple C2 server addresses."

“The MATA framework is important as it can target multiple platforms: Windows, Linux, and macOS,” Kaspersky concludes.

“In addition, the hacker behind this advanced malware framework used it for a type of cybercrime attack that steals customer databases and distributes ransomware.”

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS