HomeSecurityOldGremlin group develops new malware on Russian mining org

OldGremlin group develops new malware on Russian mining org

The OldGremlin group, a little-known threat actor that uses its highly advanced skills to conduct carefully prepared, sporadic campaigns, returned last month after a year-long hiatus.

OldGremlin group develops new malware on Russian mining org

The group appears to have carried out fewer than five malicious campaigns targeting businesses in Russia since early 2021.

Despite the group being less active, OldGremlin demanded a ransom of up to $3 million from one of its victims.

Carefully prepared phishing

OldGremlin's most recent activity consists of two phishing campaigns that began towards the end of March 2022. It is too early to estimate how many companies were targeted, but security researchers say that at least one Russian mining company is on the list of victims.

The team did not deviate from its previously observed tactics for gaining initial access and took advantage of trendy news topics.

Security researchers at Singapore-based cybersecurity firm Group-IB say that this time the OldGremlin group impersonated a senior accountant at a Russian financial institution, warning that recent sanctions imposed on Russia would suspend the operations of Visa and Mastercard.

OldGremlin

New custom backdoor

The email directs the recipient to a malicious document stored in a Dropbox storage space that downloads a backdoor called TinyFluff, which launches the Node.js interpreter and gives the attacker remote access to the targeted system.

TinyFluff is a new variant of an older backdoor, TinyNode, that the gang used in previous attacks. The image below shows the infection chains from the two OldGremlin campaigns this year on March 22 and 25:

OldGremlin

Group-IB researchers discovered two variants of TinyFluff, an older one that is more complex and a newer, simplified version that copies the Node.js script and interpreter from its storage location at 192.248.176[.]138.

Both variants of the backdoor are currently detected by more than 20 antivirus engines on the Virus Total.

In a report shared with BleepingComputer, Group-IB provides indicators of compromise and a detailed technical analysis of the tools used by OldGremlin in the two phishing campaigns deployed last month.

After planting the backdoor, OldGremlin proceeds to the identification stage, checking whether the application is running in a test environment.

The commands for this stage of the attack are delivered in clear text, allowing researchers to examine them using a traffic sniffer

  • collecting information about the infected system/device
  • get information about connected drives
  • launching the cmd.exe shell, executing a command and sending the output to the command and control server (C2)
  • get information about plugins installed on the system
  • getting information about files in specific directories on the system drive

OldGremlin can spend months inside the compromised network before deploying the final stage of the attack: the delivery of TinyCrypt/TinyCryptor, the group's custom ransomware payload.

Just like with ransomware attacks from other gangs, the victim receives a ransom note that provides a contact to reach the threat actor for payment negotiations.

OldGremlin

Group-IB told BleepingComputer that OldGremlin had been encrypting at least three companies since researchers began tracking the gang in 2020.

While this number is insignificant compared to attacks by other ransomware, researchers note that OldGremlin is making a lot of money despite running few campaigns.

In 2021, the gang deployed only one phishing campaign, but it was enough to keep them busy throughout the year, as it provided initial network access to many businesses .

Group-IB says it is only a matter of time before a larger number of OldGremlin victims are revealed, in addition to the targeted Russian mining company, as a result of the group's phishing activity in March.

Based on the evidence they found and after analyzing the quality of the phishing messages and misleading documents, the researchers estimate that the OldGremlin group has Russian-speaking members.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS