HomeSecurityUsers of Ukrainian military DELTA system targeted by info-stealing malware

Users of Ukrainian military DELTA system targeted by info-stealing malware

A compromised email account belonging to the Ukrainian Ministry of Defense was detected sending phishing emails and instant messages targeting users of the military program “DELTA,” in an attempt to infiltrate their systems with info-stealing malware.

See also: T-Mobile: New SIM Protection feature released!

DELTA

Today, CERT-UA (Computer Emergency Response Team of Ukraine) issued a warning to Ukrainian military personnel about the malicious malware attack, publishing an official report highlighting their campaign.

DELTA, created by Ukraine with the help of its allies, is a powerful intelligence collection and management system designed to help military personnel monitor the activities of their adversaries.

See also: CRM platform SevenRooms confirmed to have been hacked

The innovative system offers a full suite of real-time information, seamlessly connecting data from multiple sources into an interactive digital map that can run on any device – regardless of whether it is a laptop or smartphone.

Digital certificates are used to sign software code and authenticate servers, telling security products running on the operating system that the application has not been compromised and that the server operator is who they claim to be.

Infection process

This campaign used malicious emails or messages with fabricated warnings to convince users that they needed to update their “DELTA” certificates in order for their system to remain secure.

A malicious email has been circulating that contains a PDF document with misleading instructions to download a file named “certificates_rootCA.zip.” Be careful not to click on any links contained in the message, as they may lead to dangerous malware or viruses!

info-stealing malware
Sample email used in the campaign (CERT-UA)
Users of Ukrainian military DELTA system targeted by info-stealing malware
Landing page where victims download the ZIP file (CERT-UA)

The file includes a digitally signed executable file, “certificates_rootCA.exe”, which creates various DLL files on the target user’s machine and launches “ais.exe”,
which simulates the certificate installation process.

This action leads the victim to believe that everything was authentic, significantly reducing the likelihood of them recognizing that they have been hacked.

DELTA info-stealing malware

Both EXE and DLL files are protected by VMProtect, a legitimate software used to wrap files in standalone virtualized machines, encrypting their contents and making them impossible to analyze or detect by AV.

The dropped DLLs, “FileInfo.dll” and “procsys.dll,” are malware, identified by CERT-UA as “FateGrab” and “StealDeal.”.

FateGrab is an FTP file stealer that targets documents and emails with the following file formats: '.txt', '.rtf', '.xls', '.xlsx', '.ods', '.cmd', '.pdf' , '.vbs', '.ps1', '.one', '.kdb', '.kdbx', '.doc', '.docx', '.odt', '.eml', '.msg' , 'email'.

See also: H-Hotels: Play ransomware responsible for cyberattack

StealDeal is an information stealer malware that can be used to obtain confidential information, such as web and passwords stored in web browsers.

After a thorough investigation, CERT-UA was unable to trace the business to any known malicious actors.

Users of Ukrainian military DELTA system targeted by info-stealing malware
Users of Ukrainian military DELTA system targeted by info-stealing malware

Info-stealing malware is an increasingly common form of malicious code that can be used to steal confidential information from unsuspecting victims’ computers and networks. While it’s impossible to completely prevent infections, there are steps you can take to protect yourself from falling victim to this type of attack. Make sure you’re using up-to-date antivirus software and regularly scanning your system for any suspicious activity. Additionally, make sure you never open suspicious email or links sent from unknown sources – these may contain information-stealing malware that can wreak havoc on your computer system if left unchecked!

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS