HomeSecurityCyber-espionage group Bitter targets South Asian governments with new malware

Bitter cyberespionage group targets South Asian governments with new malware

New activity has been observed from Bitter, an APT group focused on cyberespionage, targeting the Bangladeshi government with new malware with remote file execution capabilities.

Bitter team

Bitter, also known as T-APT-17, is a suspected threat actor from South Asia. It has been active since 2013, targeting the energy, engineering, and government sectors in China, Pakistan, and Saudi Arabia. In their latest campaign, they expanded their targeting to government entities in Bangladesh.

The campaign has been ongoing since at least August 2021 and is a prime example of the Bitter group's targeting scope, which has remained unchanged since 2013.

The discovery and details of this campaign come from threat analysts at Cisco Talos, who shared their report with BleepingComputer.

Cisco Talos researchers attribute this campaign to the Bitter group based on C2 IP address overlaps with previous campaigns, common string encryption , and the module naming scheme.

Bitter cyberespionage group targets South Asian governments with new malware

Chain of infection

During this campaign, which targeted various organizations within the Bangladeshi government, Cisco observed two infection chains, both starting with a spear-phishing email.

These messages are sent through fake email addresses to appear as if they come from Pakistani government organizations.

This was likely possible by exploiting a flaw in the Zimbra mail server that allowed attackers to send messages from a non-existent email account/domain.

The difference between the two infection chains lies in the type of file attached to the malicious email: one has a .RTF document and the other a .XLSX document.

The topics used in these emails are related to call records and number verification related to real government operations.

Bitter team

RTF documents are rigged to exploit CVE-2017-11882 and enable remote code execution on machines running vulnerable versions of Microsoft Office.

“When the victim opens the RTF file with Microsoft Word, it invokes the Equation Editor application and executes the equation formula containing the Return-Oriented Programming (ROP) gadgets” – Cisco Talos

“ROP loads and executes the shellcode located at the end of the maldocs in an encrypted form that connects to the malicious host olmajhnservice[.]com and downloads the payload,” the researchers explain.

Bitter cyberespionage group targets South Asian governments with new malware

In the case of the Excel spreadsheet, opening this file triggers an exploit for CVE-2018-0798 and CVE-2018-0802, which leads to remote code execution in older versions of Microsoft Office.

In this case, payload retrieval is handled by two scheduled tasks created by the exploit that run every five minutes after the initial infection to connect to the hosting server and download the trojan.

The ZxxZ trojan

Cisco Talos named the trojan ZxxZ. It is a 32-bit Windows executable that downloads and executes modules with generic file names such as “Update.exe”, “ntfsc.exe” or “nx.exe”.

These files are “either downloaded or dropped into the victim’s local application data folder and executed as a Windows security update with medium integrity to elevate the privileges of a standard user ,” the report details.

The malware has anti-detection features, such as obfuscated strings, and also looks for the existence of Windows Defender and Kaspersky to kill them.

Bitter team

After this, an information theft operation is triggered, which dumps victim profile data into a cache and sends it to the command and control server (C2). The C2 then responds with a portable executable stored in “%LOCALAPPDATA%\Debug\”.

In case of failure to download this executable file, the ZxxZ trojan retries 225 more times before giving up and exiting.

The Bitter team is still out there, updating its arsenal with new tools and putting more effort into avoiding detection.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS