HomeSecurityTurla Group: Developed two backdoors - LunarWeb and LunarMail

Turla Group: Developed two backdoors – LunarWeb and LunarMail

The European Ministry of Foreign Affairs (MFA) and its three missions in the Middle East fell victim to cyberattacks, known as LunarWeb and LunarMail.

Turla Group LunarWeb LunarMail backdoors

ESET, which detected the activity, attributes it to the cyberespionage Turla, also known as Iron Hunter, Pensive Ursa, Secret Blizzard, Snake, Uroburos and Venomous Bear. The company’s suspicions are based on the identification of tactics and methods associated with previous malicious actions, which have been identified as being organized by this threat actor.

See also: Russian Turla hackers target NGOs with new TinyTurla-NG backdoor

LunarWeb, which runs on servers, uses the HTTP(S) protocol for command and control (C&C) communications, impersonating legitimate websites. On the other hand, LunarMail, which is installed on workstations, integrates with Outlook as an add-in and uses email for C&C communications, as security researcher Filip Jurčacko points out.

The Turla group, which is estimated to be linked to the Russian Federal Security Service (FSB), is an advanced persistent threat (APT) that is believed to have been active since at least 1996 and primarily targeted the government, embassies and military, education, research and pharmaceuticals.

This year, the actions of a cyber espionage group targeting organizations in Poland were revealed, aiming to distribute a backdoor called TinyTurla-NG (TTNG).

«The Turla group is a persistent competitor with an extensive history of actions», Trend Micro reports in its analysis of the dynamically evolving set of tools of the threat actor. «The origin, methods and goals of the group indicate an organization with significant funding and particularly specialized operational factors».

The exact timeframe of the attack used to breach MFA is currently unknown, although it is suspected that it may have included a spear-phishing element and the exploitation of the flawed Zabbix software.

The starting point of the attack chain combined by ESET begins with a compiled version of an ASP.NET website used as a conduit for decoding two embedded blobs, which includes a loader named LunarLoader and the LunarWeb backdoor.

Specifically, when the page is requested, it expects a password in a cookie named SMSKey which, if provided, is used to generate a key to decrypt the payloads.

“The hacker already had access to the network, was using stolen credentials for lateral movement, and took careful steps to compromise the server without arousing suspicion,” Jurčacko noted.

LunarMail, on the other hand, spreads via a malicious Microsoft Word document sent via phishing, which, in turn, packages LunarLoader and the backdoor.

LunarWeb is equipped to collect system information and analyze commands within JPG and GIF image files sent from the C&C server, and then the results are exported in a compressed and encrypted format. It further attempts to integrate by disguising its network traffic as legitimate in appearance (e.g. Windows update ).

The C&C instructions allow the backdoor to execute PowerShell commands and Lua code, read/write files and archive specified paths. The second injection, LunarMail, supports similar capabilities, but mainly piggybacks on Outlook and uses email to communicate with its C&C server by searching for specific messages with attached PNG.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Turla Group: Developed two backdoors - LunarWeb and LunarMail

Read more: DinodasRAT: New Linux version of the backdoor

Some of the other commands that specifically pertain to LunarMail include the ability to configure Outlook profiles for use for C&C, create arbitrary processes, and capture screenshots. Then, the execution outputs are embedded into a PNG image or a PDF document before being exported as attachments to incoming emails controlled by the hackers.

“This backdoor is designed to be deployed on user workstations, not servers — because it is maintained and intended to run as an Outlook add-in,” Jurčacko said. “LunarMail shares ideas for operation with LightNeuron, another Turla backdoor that uses emails for C&C purposes.”

Source: thehackernews

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS