HomeSecurityHackers abuse SyncThing to steal data

Hackers are abusing SyncThing to steal data

The Computer Emergency Response Team of Ukraine (CERT-UA) reports a new campaign called “SickSync,” which exploits the SyncThing software for attacks against the Ukrainian defense forces.

See also: New Fog ransomware targets educational institutions

SyncThing

The group is linked to the Luhansk People's Republic (LPR) region, which Russia has occupied almost entirely since October 2022. The hacker's activities are usually aligned with Russia's interests.

The attack uses the legitimate SyncThing file synchronization software in conjunction with the SPECTR malware . The apparent motive of the Vermin group is to steal sensitive information from military organizations.

Attack details

The attack begins with a phishing email sent to the target, which carries a RARSFX file named “turrel.fop.wolf.rar”.

When the file is launched, it extracts a PDF (“Wowchok.pdf”), an installer (“sync.exe”) , and a BAT script (“run_user.bat”). The BAT executes sync.exe, which contains the SyncThing and SPECTR malware, along with the required libraries.

SyncThing creates a peer-to-peer connection for data synchronization, which is used to steal documents and account passwords. The legitimate tool is modified with new directory names and scheduled tasks to avoid detection, while the component that displays a window when active has been removed.

See also: Hackers abuse legal packer software to distribute malware

SickSync

SPECTR is a modular malware that has the following capabilities:

  • SpecMon: Uses PluginLoader.dll to execute DLL files containing the “IPlugin” class.
  • Screengrabber: Takes screenshots every 10 seconds when specific program windows are detected.
  • FileGrabber: Uses robocopy.exe to copy files from user directories such as Desktop, MyPictures, Downloads, OneDrive , and DropBox.
  • Usb: Copies files from removable USB media.
  • Social: It steals authentication data from various apps such as Telegram, Signal, Skype , and Element.
  • Browsers: It steals data from browsers, including Firefox, Edge , and Chrome, focusing on authentication data, session information, and browsing history.

Data stolen by SPECTR via SyncThing software is copied to subfolders in the '%APPDATA%\sync\Serve_Sync\' directory and then transferred via synchronization to the threat actor's system.

CERT-UA believes that Vermin decided to use a legitimate tool to extract data, to reduce the likelihood that security systems would flag the network traffic as suspicious.

See also: Malware can steal data collected by Windows Recall

Malware, such as that exploited by SyncThing, includes a variety of harmful programs designed to infiltrate, damage, or disable computers and networks. Common types include viruses, which attach themselves to legitimate files and spread through them. Worms, which replicate without user intervention. Trojans, which disguise themselves as harmless software, and ransomware, which locks users out of their systems until a ransom is paid. The effects of malware range from data theft and financial loss to severe disruption to personal and professional environments. As threats evolve, understanding and implementing strong cybersecurity measures is becoming increasingly important to protect against these pervasive risks.

Source: bleepingcomputer

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS