HomeSecuritySpying campaign hits telecommunications companies

Spying campaign hits telecommunications companies

A new espionage campaign targeting telecommunications and IT service providers in the Middle East and Asia was recently discovered by security researchers.

Espionage campaign

See also: Corporate espionage group RedCurl resumes attacks

The espionage campaign took place over the past six months and there are possible links to the Iranian government hacking group MERCURY also known as MuddyWater, SeedWorm or TEMP.Zagros.

The report comes from Symantec 's Threat Hunter team , which has collected evidence and tool samples from recent attacks in Israel, Jordan, Kuwait, Saudi Arabia, the United Arab Emirates, Pakistan, Thailand, and Laos.

The attackers seem to be particularly interested in vulnerable Exchange servers, which they use to deploy the web shell.

After the initial breach, they steal account credentials and move laterally through the corporate network. In some cases, they use their base to target other affiliated organizations.

Symantec also discovered a case where a ZIP file named “Special discount program.zip” contained an installer for a remote desktop software application.

See also: State hackers target telecommunications providers and IT companies

Therefore, malicious actors may distribute spear-phishing emails to specific targets.

telecommunications companies

First, hackers typically create a Windows service to launch a Windows Script File (WSF) that performs reconnaissance on the network.

PowerShell is then used to download more WSF and Certutil to download tunneling tools and run WMI queries.

Having established their presence in the target organization, agencies use the eHorus remote access tool, which enables them to do the following:

  • Delivery and execution of a Local Security Authority Subsystem Service (LSASS) denial of service tool.
  • Delivery of tunnel boring tools to Ligolo.
  • Run Certutil to request a URL from Exchange Web Services (EWS) and other targeted organizations.

See also: Microsoft: Seizes websites used by Chinese state hackers

Symantec recorded two IP addresses that overlap with the infrastructure used in past MuddyWater.

Furthermore, the set of tools bears several similarities to the March 2021 attacks reported by Trend Micro researchers.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS