HomeSecurityClasiopa group uses new Atharvan malware in its attacks

Clasiopa group uses new Atharvan malware in its attacks

Cybersecurity experts have identified the malicious hacking group Clasiopa targeting businesses in the materials research industry with an unusual set of tools, including their own custom remote access trojan (RAT), known as Atharvan.

The threat actor is tracked as Clasiopa by Symantec, a Broadcom company, whose analysts found a clue that it originated in India. However, the attribution remains unclear because there is little evidence to support any theory.

See also: Google Bug Bounty: $12 million awarded to researchers in 2022

Clasiopa group uses new Atharvan malware in its attacks

Details about the Clasiopa attack

Although the exact source of Clasiopa's initial infection is unknown, Symantec researchers have discovered evidence that suggests it uses brute force methods to penetrate publicly accessible servers.

According to Symantec, after carrying out a successful attack, perpetrators often take various further measures, such as:

  • checking the IP address of the compromised system
  • disabling endpoint protection products by stopping their services
  • developing malware that can scan for specific files and extract them as ZIP files
  • clearing Sysmon logs and eventlogs to wipe traces of malicious activity
  • creating a scheduled task (“network service”) to list file names

Symantec's investigation revealed that the Clasiopa group was using both a backdoor and genuine applications, such as Agile DGS and Agile FD, signed with expired certificates.

The hackers cleverly leveraged two backdoors for their attack: the custom Atharvan and the open-source Lilith RAT. Using the latter, they had access to a powerful arsenal of functions, such as command execution, PowerShell script execution, and process manipulation on the infected system.

Clasiopa used both a custom proxy tool and the Thumbsender application, which accesses files in its hosting environment to store them in a database that can be exported at any time to an IP of its choosing.

See also: New S1deload Stealer malware hacks YouTube and Facebook accounts

Atharvan's capabilities

Of all the exploits used by the Clasiopa group, Atharvan stands out because it is a custom backdoor that has not been found in other attacks.

Upon activation, it creates a deadlock process to avoid multiple executions of itself, and then communicates with a coded command-and-control address in an unusual location: Amazon Web Services located in Seoul , South Korea.

Below is a sample of the backdoor's communication with the C2 server, configured as HTTP POST requests to a supposedly legitimate host, Microsoft's update server.

Clasiopa group uses new Atharvan malware in its attacks

An outstanding capability of this system is its ability to be configured for scheduled communication with the C2, as well as its ability to attempt connections during specific days or weeks.

See also: Hydrochasma hackers target medical research labs

Atharvan is capable of downloading files to the infected computer, launching executable programs, executing commands , and sending them back output .

Clasiopa group uses new Atharvan malware in its attacks

The researchers point out that Atharvan uses a rudimentary algorithm to encrypt its communications with the C2. When implemented, each byte of plaintext is XORed with the number “2,” creating ciphertext. This isn’t particularly secure, but it can allow the malware to evade some network monitoring tools.

During their investigation, the researchers discovered a mutex in Hindi – “SAPTARISHI-ATHARVAN-101” – which refers to Atharvan, an ancient priest from Vedic mythology. Another clue is a password the attacker used for a ZIP file, which was “iloveindea1998^_^”.

However, both hints may simply be distractions intended to mislead us.

Clasiopa group uses new Atharvan malware in its attacks

The Atharvan backdoor remains largely unnoticed. Currently, it only has one sample available on the VirusTotal scanning platform - however, it has been flagged as a threat by just two antivirus engines.

Apparently, the purpose of Clasiopa's attacks is cyberespionage. According to the researchers' findings, the malicious actor is actively targeting victims in Asia.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS