HomeSecurityRussian hackers target organizations with fake NATO training files!

Russian hackers target organizations with fake NATO training files!

Russian hackers from the group known as APT28, Fancy Bear, Sofacy, Sednit and STRONTIUMare behind a series of attacks targeting organizations. The Russian hackers are delivering a difficult-to-detect Zebrocy Delphi malware, which is presented to potential victims as NATO training materials. Researchers, examining the files containing the payload, discovered these fake and misleading JPG files that display NATO images when opened on a computer.

Last August, Qi'anxin's Red Raindrops team reported discovering a campaign organized by Russian hackers APT28, which has delivered the Zebrocy malware in the form of NATO training materials.

Russian hackers vs NATO

It is worth noting that the threat intelligence company “QuoIntelligence” had been alerting organizations to this campaign since August 8, before information about it was made public. QuoIntelligence told BleepingComputer that the campaign targets NATO member countries, as well as Azerbaijan. The researchers explained that despite the fact that Azerbaijan is not a NATO member, it cooperates closely with North Atlantic organizations and participates in NATO exercises. In addition, the same campaign is likely to target other NATO members or countries that cooperate with NATO exercises. Moreover, after QuoIntelligence researchers discovered the campaign in question, they reported their findings to the French authorities.

The malicious file distributed by APT28 is titled, “Lesson 5 – October 16, 2020.zipx”. To an unsuspecting user, this appears to be a ZIP file containing course materials. As BleepingComputer reports, the ZIP file behaves almost like a legitimate image file. According to researchers at QuoIntelligence, this is because the file contains a legitimate JPG image with a ZIP file attached to it. The metadata and properties of the file also show a MIME type of “image/jpeg” with references to “JPEG image data”.

NATO files

The researchers explain how this technique works because JPEG files are parsed from the beginning of the file, and some applications parse Zip files from the end of the file, without looking at the signature at the front.

At the time of analysis by Qi'anxin Red Raindrops and QuoIntelligence, the malware sample had a very low detection rate of 3/61 on VirusTotal. Even today, less than half of the known antivirus flag the infection on VirusTotal.

The technique is also used by hackers to evade AVs or other filtering systems. When extracted, the ZIP contains a corrupted Excel file (.xls) and another file with the same name “Lesson 5 – October 16, 2020” but an EXE extension. On Windows systems , the file “Lesson 5 – October 16, 2020.exe” displays a PDF icon.

NATO

The Zebrocy malware used by this campaign has many capabilities, including system identification, file creation/modification, taking screenshots on the infected device, arbitrary command execution, and creation of scheduled Windows tasks. The malware also “drops” many files on an infected system, which makes it “quite noticeable,” as its activities trigger alerts in leading security.

In this case, the Zebrocy payload (present in “Lesson 5 – October 16, 2020.exe”) works by replicating itself in “%AppData%\Roaming\Service\12345678\sqlservice.exe” and further appends a random 160-byte blob to the newly created file. In addition, the malware created a scheduled Windows task, which runs every minute, sharing stolen data to the Command & Control (C2) server

QuoIntelligence suspects that this malware targets Azerbaijani organizations, based on a previous ReconHellcat campaign analyzed by the company.

Three similarities among these samples lead researchers to the conclusion that this attack was aimed at a specific organization, at least in Azerbaijan:

  • The upload of both the compressed Zebrocy malware and the Organization for Security and Co-operation in Europe (OSCE)-themed lure used to deliver the BlackWater backdoor occurred on the same day, August 5th.
  • The upload of both samples was performed by the same user in Azerbaijan and is very likely from the same organization.
  • Both attacks occurred around the same time.
📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS