HomeSecurityHackers target air-gapped devices in Eastern Europe with new malware

Hackers target air-gapped devices in Eastern Europe with new malware

air gapped

Chinese state-backed hackers have targeted industrial organizations with new malware that can steal data from air-gapped systems. Air-gapped systems typically fulfill critical roles and are isolated from the company’s network and the public internet either physically or through software and network devices.

Researchers at cybersecurity firm Kaspersky discovered the new malware and attributed it to the cyberespionage group APT31, also known as Zirconium.

See also:The possible existence of Chinese malware in US systems is a "time bomb"

According to the findings, hackers used at least 15 different implants in attacks in Eastern Europe, each for a separate stage of the operation, as well as the signature of the “FourteenHi” malware family.

Multi-stage attacks

Kaspersky reported that APT31 launched a three-stage attack last April. The first stage created remote access and collected data. The second stage involved stealing data from isolated systems using USB propagation. The third stage uploaded the collected data to the hackers’ servers. The malware targeting isolated systems had four modules: removable drive profiling, removable drive infection, device data collection, and a variant of the first module that acted as a payload dropper, keylogger, screenshot tool, and file stealer.

Suggestion: Hackers steal data from air-gapped computers

APT31: Hackers target air-gapped devices with new malware

In May 2022, Kaspersky observed an additional implant used in APT31 attacks, designed to collect local files from compromised systems.

This implant decrypts and injects its payload into the memory of a legitimate process to evade malware detection, then remains in a sleep state for 10 minutes and finally copies all files that match the file type extensions defined in its configuration.

The stolen files are archived using WinRAR (if unavailable, the malware exits) and then stored in temporary local folders created by the malware in “C:\ProgramData\NetWorks\”. Finally, the files are transferred to Dropbox.

APT31

Kaspersky emphasizes that the attacks were covert and lists the following tactics, techniques, and procedures (TTPs): Abuse of DLL instructions to load malicious payloads into memory and hiding payloads in encrypted form in separate binary data files.

The company provides a technical report that includes additional data, such as malware hashes, a full set of indicators of compromise, and details about the malware's activity from start to finish.

Air-sealed systems are an attractive target for APT groups, who typically turn to USB drives to transfer malware and wipe data from the isolated environment.

Read also: Chinese hacking group APT31 targets French organizations

source of information:bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS