HomeSecurityNew phishing campaign targets military contractors

New phishing campaign targets military contractors

Security researchers have discovered a new phishing campaign targeting multiple military contractors involved in weapons manufacturing, including a supplier of F-35 Lightning II fighter jet components.

New phishing campaign targets military contractors

See also: IRS warns of increased phishing attacks via SMS

Highly targeted attacks begin with a phishing email sent to employees, leading to a multi-stage infection that involves multiple persistence and detection evasion systems.

The campaign stands out for its secure C2 infrastructure and multiple layers of obfuscation in the PowerShell stages.

Securonix analysts discovered the attacks, but were unable to attribute the campaign to any known threat actor, although the report notes some similarities to previous attacks by the APT37 (Konni) group.

See also: Microsoft Exchange servers compromised via OAuth apps for phishing

Employee targeting

The phishing targeting employees includes a ZIP attachment containing a shortcut file (“Company & Benefits.pdf.lnk”), which, when executed, connects to the C2 and launches a chain of PowerShell scripts that infect the system with malware.

Interestingly, the shortcut file does not use the commonly abused “cmd.exe” or “powershell.exe” tools, but relies on the unusual “C:\Windows\System32\ForFiles.exe” command to execute commands.

The next step is to unravel a seven-stage PowerShell execution chain characterized by “heavy obfuscation” using multiple techniques.

phishing

The obfuscation techniques that Securonix analysts have seen are reordering/symbol obfuscation, IEX obfuscation, byte value obfuscation, raw compression, reordering, string replacement, and backtick obfuscation.

See also: Abuse of LinkedIn Smart Links in phishing attacks

Additionally, the script scans for a list of processes associated with debugging and monitoring software, checks that the screen height is above 777 pixels and memory is above 4 GB to avoid sandboxes, and verifies that the system was installed more than three days ago.

phishing

If any of these checks fail, the script will disable the system's network adapters, configure Windows Firewall to block all traffic, delete everything on all detected drives, and then shut down the computer.

The only case where the malware exits without causing any damage is when the system language is set to either Russian or Chinese.

If all checks pass, the script proceeds by disabling PowerShell Script Block Logging and adding Windows Defender exceptions for “.lnk”, “.rar” and “.exe” files, as well as directories important for the malware to function.

Persistence is achieved through multiple methods, including adding new registry keys, incorporating the script into a scheduled task, adding a new entry to the Startup directory, and WMI subscriptions.

phishing

After the PowerShell stager completes the process, a final AES-encrypted payload (“header.png”) is downloaded from the C2.

Infrastructure C2

Analysts found that the domains used for the C2 infrastructure supporting this campaign were registered in July 2022 and hosted on DigitalOcean.

Later, threat actors moved the domains to Cloudflare to take advantage of its CDN and security services, including IP address masking, geoblocking, and HTTPS/TLS encryption.

Some C2 domains mentioned in the report include “terma[.]wiki”, “terma[.]ink”, “terma[.]dev”, “terma[.]app” and “cobham-satcom.onrender[.] com”.

Overall, this campaign looks like the project of a sophisticated threat actor that knows how to evade detection, so be sure to check out the “hunting queries” and shared IoCs in the Securonix report.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS