HomeSecurityModifiedElephant: The hacking group that went unnoticed for a decade

ModifiedElephant: The hacking group that went unnoticed for a decade

A hacking group, tracked by the name ModifiedElephant, has been using tactics that allowed it to operate in complete secrecy for a decade, after security researchers had failed to link the attacks to them.

These hackers appear to be using existing trojans, and through spear-phishing attacks, are targeting human rights defenders, free speech advocates, academics, and lawyers in India. These attacks have been occurring since at least 2012.

See also: Microsoft: Fixes bug in Defender that allows malware scans to be bypassed

ModifiedElephant

Malicious emails deliver keyloggers and remote access trojans (RATs) such as NetWire and DarkComet. They are even used to distribute Android malware.

SentinelLabs researchers have described the tactics of the ModifiedElephant hacking group in a report, explaining how recently published evidence helped them attribute previous attacks to these hackers.

Researchers observed significant similarities in the infrastructure used in multiple campaigns between 2013 and 2019, as well as consistency in the malware deployed in these campaigns.

Previous hacking campaigns

As mentioned above, ModifiedElephant has relied on spear-phishing emails with malicious attachments for over a decade. However, its techniques have evolved over that time.

Below you can see some of the techniques used by hackers:

  • 2013: hackers use email attachments with fake double extensions (file.pdf.exe) to install malware on victims' systems
  • 2015: group uses password-protected RAR attachments containing legitimate documents that mask signs of malware execution
  • 2019: ModifiedElephant begins hosting malware-dropping sites and abusing cloud hosting services, moving from fake documents to malicious links
  • 2020: Attackers use large RAR files (300 MB) to evade detection by bypassing scans

See also: Fake Windows 11 upgrade installers infect you with RedLine malware

In many cases, the attached documents leveraged known exploits to execute malware, including CVE-2012-0158, CVE-2013-3906, CVE-2014-1761, and CVE-2015-1641.

hacking

As for the topics they used in the emails to lure victims, they were related to political issues and were tailored for each victim.

Researchers noted that the ModifiedElephant hacking group does not use (or the researchers have not discovered) custom backdoors, so it does not appear to be very “sophisticated.”.

The key malware deployed in its campaigns are NetWire and DarkComet, two remote access trojans that are publicly available and widely used by many cybercriminals.

See also: Russia: Third hacking group arrested for stealing credit cards

Also, the Visual Basic keylogger used by ModifiedElephant has remained the same since 2012 and has been freely available on hacking forums over the years. SentinelLabs comments on the antiquity of the tool, noting that it no longer works even on modern operating system versions.

The Android malware they use is also a commodity trojan, delivered to victims in the form of an APK. Hackers trick victims into installing it themselves by presenting it as a news app or a secure messaging tool.

Are they supported by any government?

SentinelLabs makes several correlations between the timing of specific ModifiedElephant attacks and the capture of targets that followed shortly thereafter.

This coincidence, combined with the scope of the targeting, which aligns with the interests of the Indian state, makes it highly likely that the hackers are funded by the Indian government. However, this has not been verified.

However, most attacks on activists and academics are not financially motivated, so it is possible that there are political motives behind ModifiedElephant's attacks.

Source: Bleeping Computer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS