Cybersecurity researchers discovered a new attack and C2 framework called «Alchimist», which appears to be actively used in attacks targeting Windows, Linux and macOS.

The framework and all its files are 64-bit executables written in GoLang, a programming language that greatly facilitates cross-platform compatibility among different operating systems.
Alchimist offers a web-based interface that uses Simplified Chinese language and closely resembles Manjusaka, an attack framework post-exploitation that recently appeared and is becoming popular among Chinese hackers.
The researchers at Cisco Talos who discovered both of these frameworks emphasize their similarities, but explain that there are several technical differences to conclude that they were developed by different authors.
Attack development
Alchimist provides operators with an easy-to-use framework that allows them to create and configure payloads that are placed on infected devices to remotely take screenshots, execute arbitrary commands , and execute remote shellcode.
The framework supports the creation of custom infection mechanisms to drop the 'Insekt' remote access trojan (RAT) on devices and assists hackers by creating PowerShell (for Windows) and wget (for Linux) code snippets for RATs deployment.

The Insekt payload can be configured in the Alchimist interface using various parameters such as C2 IP/URL, platform (Windows or Linux), communication protocol (TLS, SNI, WSS/WS) and whether it will run as a daemon or not.

The C2 address is hard-coded into the generated implant and contains a self-signed certificate generated during compilation. The C2 is pinged ten times every second and if all connection attempts fail , the malware retries after an hour.

The Insekt RAT
While the Alchemist C2 servers provide commands for execution, the Insekt implant is the one that executes them on infected Windows and Linux systems.
The malicious behavior that an Insekt implant can perform is the following:
- Retrieving file sizes.
- Retrieving operating system information.
- Executing arbitrary commands via cmd.exe or bash.
- Upgrading the current Insekt implant.
- Executing arbitrary commands as a different user.
- Sleep for periods defined by the C2.
- Start/stop screenshot capture.

Additionally, Insekt can serve as a proxy (using SOCKS5), handle SSH keys, perform port and IP scanning, write or decompress files to disk and execute shellcode on the host.
Alchimist operators can also send predefined commands to the implant regarding user creation, administrator user search, terminal activation, and firewall.
macOS attacks
Insikt doesn't yet work on macOS, so Alchimist fills this gap using a Mach-O file, a 64-bit executable written in GoLang that contains an exploit for CVE-2021-4034.
This is a privilege escalation flaw in Polkit's pkexec utility, but the framework will not inject it into the target, meaning that for the attack to work , hackers must install the utility on the target machine.
Alchimist offers the same exploit for the Linux platform, as long as pkexec is installed on the system.
Rise of all-in-one frameworks
Alchimist is another attack framework available to cybercriminals who lack the knowledge or ability to create all the components required for advanced cyber attacks.
Unfortunately, these ready-made frameworks are high-quality, feature-rich, good at evading detection, and effective at dropping implants onto targets.
Because of the above, it is very useful for hackers who want to minimize their operating expenses and combine them with random malicious traffic from other hackers to avoid performance.
Information source: bleepingcomputer.com
