The MATA malware framework exploits the EDR (Emergency Detection and Recovery) system in attacks against defense companies.
An updated version of the MATA backdoor framework was detected in attacks from August 2022 to May 2023, targeting oil and gas companies and the defense industry in Eastern Europe.
The attacks used spear-phishing emails to trick targets into downloading malicious executables that exploit CVE-2021-26411 in Internet Explorer to start the infection chain.
The updated MATA framework combines a loader, a main trojan, and an infostealer to create backdoors and gain a permanent presence in targeted networks.
The MATA version in these attacks is similar to previous versions linked to the North Korean hacking group Lazarus, but with updated capabilities.
In particular, the spread of malware to all accessible corners of the corporate network is carried out through the violation of security compliance solutions and the exploitation of their shortcomings.
See also: Lazarus hackers target users with fake interviews via trojanized VNC apps

See also: A serious cyberattack could cost up to $3.5 trillion
EDR abuse in attacks
The cybersecurity firm discovered the activity in September 2022, after examining two MATA samples communicating with command and control servers (C2) within breached organizations' networks.
Upon further analysis, it was determined that the compromised systems were the financial data software servers connected to multiple subsidiaries of the target.
The investigation revealed that the hackers had expanded their foothold from a single domain controller to a production unit across the entire corporate network.
The attack continued with the hackers gaining access to two security management panels, one for endpoint protection and one for compliance checks.
Hackers abused access to the security software's administrative panel to monitor the organization's infrastructure and spread malware to its subsidiaries.

Updated MATA malware
In cases where the targets were Linux servers, the attackers used a variant of MATA for Linux in ELF file format, which appears to have similar functionality to the third generation of the Windows implant.
According to Kaspersky, it tested three new versions of the MATA malware: one (v3) evolved from the second generation observed in previous attacks, the second (v4) named 'MataDoor', and the third (v5) created from scratch.
The latest version of MATA is provided in DLL format and features extensive remote control capabilities, supports multi-protocol (TCP, SSL, PSSL, PDTLS) connections to control servers and supports proxies (SOCKS4, SOCKS5, HTTP+web, HTTP+NTLM).
The 23 commands supported by the fifth generation of MATA include actions for establishing connectivity, managing the implant, and retrieving information.
By adding additional plugins to the malware, it becomes capable of executing another 75 commands related to information collection, process management, file management, network exploration, proxy operation, and remote command execution.
Other interesting findings include a new malware that can use removable storage media, such as a USB, to infect systems that are isolated from the network, various theft tools that can capture credentials, cookies, screenshots, and clipboard content, as well as EDR/security bypass tools.
Researchers report that hackers bypassed EDR and security tools using a publicly available exploit for CVE-2021-40449, called “CallbackHell.”.
Using this tool, attackers modify kernel memory and focus on specific calling processes, rendering endpoint security ineffective.
If this bypass method failed, they switched to previously documented Bring Your Own Vulnerable Driver (BYOVD) techniques.

Although Kaspersky previously associated MATA with the North Korean Lazarus group, the cybersecurity firm is having difficulty linking the recently observed activity with increased certainty.
While there are still obvious links to Lazarus activity, newer MATA variants and techniques such as TTLV serialization, multilayered protocols and handshake mechanisms more closely resemble those of 'Five Eyes' APT groups such as Purple, Magenta and Green Lambert.
Also, executing multiple malicious MATA frameworks and framework versions in a single attack is highly unusual, betraying a particularly well-prepared malicious actor.
Information source: bleepingcomputer.com
