HomeSecurityGroup linked to Memento ransomware uses new PowerShell backdoor

Group linked to Memento ransomware uses new PowerShell backdoor

An Iranian-backed hacking group referred to as APT35 (also known as Phosphorus or Charming Kitten) is now developing a new backdoor called PowerLess.

PowerShell
Group linked to Memento ransomware uses new PowerShell backdoor

See also: Apple and Tesla supplier hit by ransomware

The group also used an unknown malware to develop additional functional modules, including info stealers and keyloggers, according to a report published today by the Cybereason Nocturnus Team.

The PowerLess backdoor features encrypted command and control communication channels and allows for the execution of commands and the elimination of processes running on compromised systems.

It also evades detection by running within the context of a .NET application, which allows it to hide from security solutions by not launching a new PowerShell instance.

See also: QNAP NAS: Forced firmware update for DeadBolt ransomware

In January, APT35 operators deployed another previously undocumented PowerShell backdoor called CharmPower in attacks leveraging Log4Shell exploits

Connection with Memento ransomware

While examining attacks where the PowerLess backdoor was used, researchers also found possible connections to the Memento ransomware.

This ransomware has been active since April 2021, and is deployed in attacks against VMware vCenter servers using exploits designed to abuse a critical pre-auth remote code execution flaw that was patched in February 2021.

PowerShell

Sophos has seen Memento operators switch from encryption systems with a Python-based ransomware strain to moving files to password-protected WinRAR archives due to the ransomware protection active on compromised devices.

The links include common TTP patterns, automatically generated strings, and a domain (google.onedriver-srv[.]ml).

See also: LockBit ransomware: Linux version targets VMware ESXi servers

This domain is linked to an IP address mentioned in a joint advisory issued by US and UK cybersecurity agencies in November regarding Iranian hacking groups targeting Microsoft Exchange and Fortinet servers.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS