HomeSecurityHackers target Russia with Decoy Dog malware

Hackers target Russia with Decoy Dog malware

Russian companies and government agencies are being targeted by attacks distributing a Windows version of the Decoy Dog malware.

Decoy Dog malware Russia

Cybersecurity firm Positive Technologies is tracking the malicious activity under the name Operation Lahat, attributing it to an APT group called HellHounds .

According to researchers, the Hellhounds group gains access to targets' networks and can remain there for years, undetected.

The HellHounds group was first documented by the company in late November 2023, after an anonymous energy with the Decoy Dog trojan. It has been confirmed to have compromised 48 victims in Russia to date, including IT companies, government agencies, companies in the space industry, and telecommunications providers.

See also: DarkGate Malware replaces AutoIt with AutoHotkey

It is believed that hackers have been targeting Russian companies since at least 2021, with the development of the malware being underway as early as November 2019.

The Decoy Dog malware is considered a custom variant of the Pupy RAT. It was detected in April 2023, when Infoblox revealed the use of DNS tunneling for communications with the command-and-control (C2) server to remotely control infected hosts.

A key feature of the Decoy Dog malware is its ability to move victims from one controller to another, which allows it to maintain communication with compromised machines and remain on the systems for long periods of time.

Attacks with the Decoy Dog malware have been mostly limited to Russia and Eastern Europe. Initially, it exclusively targeted Linux systems , but now it appears that a Windows version also exists .

See also: Authorities seek clues about the “brain” of the Emotet malware

Hackers target Russia with Decoy Dog malware

“There are references to Windows in the code, suggesting the existence of an updated Windows client with new Decoy Dog capabilities, although all current samples target Linux,” Infoblox noted in July 2023.

The latest findings from Positive Technologies confirm the presence of a version of Decoy Dog for Windows.

Positive Technologies said that in at least two incidents, hackers were able to gain initial access to the victims' infrastructure.

“The attackers have long managed to maintain a presence within critical organizations located in Russia,” the researchers said. “Although almost all of the Hellhounds toolkit is based on open-source projects, the attackers have done a pretty good job of modifying it to bypass malware defenses and ensure a prolonged stealth presence within compromised organizations.”

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Malware protection

Using reliable and up-to-date antivirus software is essential for protection against malware. Antivirus programs can detect and remove malicious software, as well as provide continuous real-time protection.

Regularly updating your operating system and software is also critical. Updates include security that close gaps that attackers could exploit.

See also: Dora RAT Malware Targets South Korean Institutes

Hackers target Russia with Decoy Dog malware
Hackers target Russia with Decoy Dog malware

Next is using strong and unique passwords for each account. Passwords should include a combination of letters, numbers, and special characters to make them harder to crack.

Enabling multi-factor authentication (MFA) adds an extra layer of security. Even if someone gets your password, they'll still need the second factor to gain access.

It is also very important to avoid clicking on suspicious links and attachments in emails and messages. Attackers often use phishing emails to trick users into installing malware on their computers.

Source: thehackernews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS