HomeSecurityMalware campaign targets Windows, Android and macOS

Malware campaign targets Windows, Android and macOS

Threat actors with ties to Pakistan have been involved in a malware known as Operation Celestial Force since 2018.

malware campaign Pakistan

This activity, which remains ongoing, involves the use of Android malware GravityRAT and a Windows malware loader called HeavyLift, according to Cisco Talos. These tools are managed through another standalone tool called GravityAdmin.

Also read: New Cross-Platform “Noodle RAT” Malware Targets Windows and Linux

The attack is reportedly being carried out by a hacker named Cosmic Leopard (aka SpaceCobra), who shares similarities with Transparent Tribe. “Operation Celestial Force has been active since 2018 and continues to operate with a constantly growing and evolving malware, suggesting that the operation has likely seen a high degree of success targeting users in the Indian subcontinent,” security researchers Asheer Malhotra and Vitor Ventura said in a report shared with The Hacker News.

GravityRAT first emerged in 2018 as Windows malware targeting Indian entities via spear-phishing emails, with the ability to harvest sensitive information from compromised computers. Since then, the malware has been adapted to run on Android and macOS, turning it into a cross-platform tool.

Subsequent findings by Meta and ESET last year revealed the continued use of the Android version of GravityRAT to target military personnel in India and the Pakistan Air Force, disguised as cloud, entertainment, and chat apps.

Read more: Warmcookie malware is promoted through fake job offers

Cisco Talos ' findings bring together all of these disparate but related activities, based on evidence indicating the threat actor's use of GravityAdmin to orchestrate these attacks.

Cosmic Leopard primarily uses spear-phishing and social engineering to build trust with potential targets, before sending them a link to a malicious website that directs them to download a seemingly harmless program that installs GravityRAT or HeavyLift, depending on the operating system used.

GravityRAT has reportedly been in use since 2016. On the other hand, GravityAdmin is a binary used to manage infected systems since at least August 2021, establishing connections to the servers of GravityRAT and HeavyLift.

See also: Phishing attacks: Significant increase in the US and Europe

“GravityAdmin includes multiple embedded user interfaces (UIs), corresponding to specific malicious campaigns,” the researchers noted. “For example, “FOXTROT,” “CLOUDINFINITY,” and “CHATICO” are names assigned to all Android-based GravityRAT infections, while “CRAFTWITHME,” “SEXYBER,” and “CVSCOUT” are names for attacks using HeavyLift.”

This newly discovered item in the hacker is HeavyLift, an Electron-based malware payload family distributed via malicious installers targeting the Windows operating system. It also bears similarities to Electron versions of GravityRAT, previously documented by Kaspersky in 2020.

malware campaign

Once launched, the malware is able to collect and export system metadata to a hard-coded C2 server, periodically polling the server for any new payloads to execute on the system. Additionally, it is designed to perform similar functions on macOS.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: New phishing toolkit uses PWA to steal login credentials

"This multi-year operation consistently targeted Indian entities and individuals likely in the defense, government, and technology spaces," the investigators said.

Source: thehackernews

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS