HomeSecurityCranefly hackers use a new hacking technique

Cranefly hackers use a new hacking technique

The Geppei dropper is used by a threat actor that Symantec calls Cranefly (also known as UNC3524) to install another piece of the undocumented Danfuan malware and other tools. The technique of reading commands from IIS logs is not something that Symantec researchers have seen used in real-world attacks to date.

See also: A zero-day in Windows 10 gets an unofficial fix

Cranefly hackers use a new hacking technique

Malware is being spread by cybercriminals through the misuse of legitimate tools, in a way that has never been seen before.

Cybersecurity researchers at Symantec say attackers can spend up to 18 months inside victims' networks without being detected. This activity is believed to be part of an intelligence gathering and espionage operation.

The infection begins in an unknown manner, but victims receive a previously undocumented form of malware called Geppei. With this access, another form of backdoor malware called Danfuan is delivered. This allows for covert access to compromised machines, along with the ability to spy on any data stored or entered into systems.

In an effort to remain undetected, attackers install backdoors on devices that are not supported by security tools. This way, they can stay under the radar. Some examples of these devices are SANS arrays, load balancers, and wireless access point controllers.

See also: The ForceNet platform used by the Australian military was hacked

What makes this campaign unique is the way Geppei abuses Internet Information Services (IIS) logs to remain undetected. This is something that researchers say they haven't seen used in attacks before, making it a new modus operandi.

IIS logs are part of Windows server services and provide website data about user interaction and behavior . They are commonly used to troubleshoot web applications.

Geppei collects commands from an IIS log, which supposedly records information from IIS, such as web pages and apps. In this case, however, hackers can send commands to a compromised web server pretending to be normal access requests . And although IIS logs them as normal, Geppei reads them as commands. The commands obtained by Geppei contain maliciously encoded files that are then stored in any random folder and executed as backdoors.

Cranefly

See also: S3crets Scanner: Free tool to scan exposed Amazon S3 buckets

The attacks have been linked to a group that Symantec is naming Cranefly – also known as UNC3524. Researchers suggest that the creative and highly discreet methods used in this campaign are indicative of a “fairly sophisticated threat actor” whose primary motivation is intelligence gathering.

Symantec did not reveal who it believes is behind the attacks, but Mandiant researchers said the way the Cranefly/UNC3524 group conducted its campaign bears similarities to methods used by known Russian-based threat actors.

Although this campaign is not well-known, it still poses a threat to organizations, as the individuals carrying it out use different methods to conceal their attacks.

Information source: zdnet.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS