ESET security researchers have discovered a new APT group that has been stealing sensitive and confidential data from governments and businesses in Eastern Europe , and particularly Belarus and Russia, for at least nine years. According to ESET, the APT group, codenamed “XDSpy”, bears no resemblance in malicious code, network infrastructure or targets to any other APT group known in the threat landscape. Furthermore, it operates largely in a GMT + 2 or + 3 time zone, the same as its targets, with operations only operating Monday-Friday.
The new APT group targeting Belarus and Russia uses spear-phishing to compromise its targets, while the emails it sends may also contain malicious attachments or files .

On the one hand, it has used the same malware architecture for nine years, with the main XDDown malware being downloaded to a victim's computer from a C&C server. This installs additional plugins aimed at collecting basic information, scanning the C drive, dropping local files, collecting browser passwords, and more.
On the other hand, it was recently detected exploiting CVE-2020-0968. ESET reported that at the time XDSpy exploited CVE-2020-0968, however very little information about this specific vulnerability was known on the Internet. The company speculates that XDSpy either purchased this exploit from a vendor or developed a 1-day exploit itself, looking at previous exploits for inspiration.

ESET declined to speculate on who might be behind XDSpy. It is more concerned that information was stolen from government agencies in Eastern Europe and the Balkans, including a campaign against Belarusian government agencies and organizations in February and against Russian-speaking people in September. It is worth noting that Moldova , Serbia, Russia and Ukraine have been under attack since 2011.
Mathieu Faou, a researcher at ESET, said that the APT group has attracted little public attention so far, with the exception of an advisory issued by the Belarusian CERT in February 2020. Faou added that since the company did not find any code similarities with other malware families and did not observe any overlap in network infrastructure, he concluded that XDSpy is a group that has not been recorded in the threat landscape before.
