HomeSecurityYoroTrooper cyberspies target EU embassies

YoroTrooper cyberspies target EU embassies

Since June 2022, an insidious threat actor known as “YoroTrooper” has been actively engaged in espionage activities against governments and energy entities located in the Commonwealth of Independent States (CIS).

YoroTrooper

As Cisco Talos reports, a malicious actor gained access to the accounts of a key EU institution dealing with healthcare, the World Intellectual Property Organization (WIPO), and several European embassies.

The YoroTrooper threat actor is known to use a combination of off-the-shelf and custom-made cyber threats, such as remote access trojans, Python -based malware , and information stealers . The infection process is primarily initiated via phishing emails with dangerous LNK or PDF attachments.

Cisco Talos has evidence that YoroTrooper steals massive amounts of data from compromised endpoints, including passwords, cookies, and browsing history.

Although signs indicate that YoroTrooper uses malware associated with other culprits, including PoetRAT and LodaRAT, Cisco researchers are confident that this is an entirely different operation.

Targeting CIS countries

During the summer of 2022, YoroTrooper compromised Belarusian entities via malicious PDF files sent from email domains pretending to be Russian or Belarusian organizations.

Last September, the group recorded several typosquatting domains impersonating Russian government entities and experimented with distributing .NET-based implants based on VHDX.

In the months that followed, cyberespionage agents turned their attention to Belarus and Azerbaijan. To aid them in this mission, they used a specially designed Python implant called “Stink Stealer.”

In 2023, malicious actors used an HTA attack to deploy deceptive documents and dropper implants on the target system. Through this attack, they were able to successfully install their own custom Python stealer against the government networks of Tajikistan and Uzbekistan.

YoroTrooper cyberspies target EU embassies

Recently, cyber attackers have used phishing emails containing RAR or ZIP file attachments to lure victims with misleading use of national strategy and diplomacy issues

By exploiting “mshta.exe”, LNK files are able to retrieve and launch a malicious HTA file, then drop the primary payload onto the infected system. To further evade detection, an inconspicuous decoy document is also opened alongside this process.

YoroTrooper

Creating custom malware

Initially, the YoroTrooper threat actor had used common malware, such as AveMaria (Warzone RAT) and LodaRAT, however, the perpetrators of these attacks later shifted to using custom Python RATs hidden in Nuitka.

Nuitka eliminates the need to install Python on devices, allowing you to easily distribute payloads as standalone applications.

This custom RAT deploys Telegram for management and leak communication, allowing it to execute any command on the compromised device.

YoroTrooper cyberspies target EU embassies

In January 2023, YoroTrooper used a Python-based stealer script to maliciously collect account credentials stored in Chrome web browsers and secretly transfer them via a Telegram bot .

In February 2023, attackers unleashed a new modular credential stealer called “Stink”.

Stink is capable of stealing personal data from Chrome-based browsers, such as passwords, bookmarks , and browsing history. In addition, it can take screenshots and extract information from various other sources, such as Filezilla, Discord, or Telegram. In addition, the malware collects system information, such as the hardware components installed on the device or its operating system version - not to mention what processes are running in the background at any given time.

Any stolen data is temporarily stored in a folder on the compromised system and is finally compressed before being transferred to the malicious actors.

With Stink, users get an additional performance boost from Python modules running in isolated processes – each with its own processor thread for accelerated data collection.

Additionally, in some cases YoroTrooper has used Python-based reverse shells and C- based keyloggers .

YoroTrooper

The source of YoroTrooper is a mystery, and funders or connections remain uncertain.

The fact that the espionage threat group uses customized malware tools indicates that these are attackers with great knowledge and skill.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS