HomeSecuritySpying campaign uses backdoor to steal data

Spying campaign uses backdoor to steal data

A spying campaign is targeting the Foreign Ministry of a European Union country with the help of new malware that provides a secret backdoor to compromised Windows.

backdoor
Spying campaign uses backdoor to steal data

The campaign was discovered by security firm ESET and, according to researchers , aims to steal sensitive documents and other files by secretly exporting them through Dropbox accounts controlled by the attackers.

Hackers have dubbed this malware campaign (and the backdoor itself) Crutch and it is said to have been active since 2015. Researchers have linked it to the hacking group Turla (also known as Waterbug and Venomous Bear), due to its similarity to previous campaigns by the group (e.g. Gazer). The UK's National Cyber ​​Security Centre (NCSC) is among those who have attributed the campaign and backdoor to the Russian Turla.

The Crutch campaign appears to be focused on very specific targets with the aim of stealing sensitive documents . ESET has not revealed details about the latest target. All it has said is that it is the foreign ministry of an EU country. This is another clue, as Turla hackers mainly focus on such targets

However, Crutch is not a first-stage payload. It is deployed only after the attackers have already compromised the target's network. Most likely, the compromise begins with specially designed spear-phishing attacks, if we consider other similar attacks.

Espionage campaign
Spying campaign uses backdoor to steal data

Once Crutch is installed as a backdoor on the system , it communicates with a hardcoded Dropbox account, which is used to unobtrusively retrieve files.

Analysis shows that the backdoor has received many updates and been modified over the years in order to maintain its effectiveness. At the same time, it manages to remain hidden.

The main malicious activity is the extraction of documents and other sensitive files. The sophisticated attacks and technical details further strengthen the hypothesis that the Turla group is behind the campaign, as it has significant resources to operate such a large and diverse malware arsenal,” said Matthieu Faou, a researcher at ESET.

However, there are some measures security that organizations can implement to avoid these types of attacks.

During this investigation, we observed that attackers were able to move around the network and compromise additional machines by reusing administrator passwords,” Fauo said.

The researcher said that if organizations take steps to limit the network's ability to move, hackers will have a harder time attacking. This can be done by prohibiting users from acting as administrators, implementing two-factor authentication on administrator accounts, and using unique and strong passwords.

Source: ZDNet

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS