A new sophisticated threat, known as 'TetrisPhantom', has used compromised USB drives to attack government systems in the Asia-Pacific region.
See also: Iranian OilRig hackers stayed in a Middle Eastern government network for 8 months

Secure USB drives store files in an encrypted space on the device and are used to securely transfer data between systems, including those in air-gapped environments. Access to the protected portion is possible through custom software that decrypts the content based on a password provided by the user. One such software is UTetris.exe, which is included in an unencrypted portion of the USB.
Security researchers have discovered trojanized versions of the UTetris application that install themselves on secure USB devices, in an attack that has been going on for at least a few years and is targeting governments in the APAC region.
According to Kaspersky's latest APT trends report , TetrisPhantom uses various tools , commands, and malware components, indicating a sophisticated and well-equipped threat group.
Kaspersky shared additional details with BleepingComputer, explaining that the attack with the modified Utetris application begins by executing a payload, called AcroShell.
See also: Lazarus hackers target users with fake interviews via trojanized VNC apps
AcroShell creates a communication channel with the attacker's command and control (C2) server and can retrieve and execute additional payloads to steal documents and sensitive files, as well as collect specific details about the USB drives used by the target.
Attackers also use the information gathered in this way to research and develop another malware called XMKR and the malicious UTetris.exe. XMKR's capabilities on the device include stealing files for espionage purposes and writing data to USB storage drives.
The information on the compromised USB is transferred to the attacker's server when the storage device is connected to a computer infected with AcroShell and connected to the internet.
Kaspersky examined and analyzed two variants of malicious Utetris executables, one used from September to October 2022 (version 1.0) and one installed on government networks from October 2022 to the present (version 2.0).
According to Kaspersky, these attacks have been ongoing for a few years, with espionage being a consistent focus of TetrisPhantom. Researchers have observed a small number of infections on government networks, indicating a targeted operation.
See also: Lazarus and Andariel hackers exploit TeamCity bug for network breaches

What security measures are in place to protect USB drives in government systems?
Securing government systems requires complex, multi-layered approaches to protect against potential attacks and hackers. One of these measures concerns the security of USB drives, which are so often used to transfer data.
First, government systems often use encrypted USB drives. These have a layer of protection that requires a password to decrypt and access the data contained within. This is important because even if a hacker manages to compromise the USB drive, they will face another layer of protection to access the data.
Threat Avoidance Techniques
Additionally, government systems use threat detection technologies to check every USB drive plugged into the system. This includes the use of Antivirus Software, Intrusion Detection Systems (IPS) , and Intrusion Information and Management Systems (SIEM) to verify that the USB drive is not already infected with a virus.
Another excellent security measure is staff training. Members of the government need to be aware of the techniques used by hackers so they can counter and prevent any attacks that could threaten the integrity of government systems.
Protection Levels
Finally, it is critical to have multiple layers of protection that encompass the full spectrum of capabilities. Achieving this level of protection requires continuous evolution and adaptation to technological changes and growing cyber threats.
Government security is an important task, requiring the ideal defensive measures for various potential cyberattacks. With the right protection, careful entry controls and monitoring, as well as all the technological knowledge that technological progress can produce, government systems can face hacker attacks in an effective manner.
Source: bleepingcomputer
