HomeSecurityAwaken Likho group targets Russian government agencies

Awaken Likho group targets Russian government agencies

The Awaken Likho hacking group is targeting Russian government agencies and industrial entities, according to a report Kaspersky

Awaken Likho

The initial attacks began in 2021. However, while investigating the activity of this APT, researchers discovered a new campaign that began in June 2024 and continued at least until August. Researchers saw that the attackers had changed the software they were using in attacks .

"Attackers now prefer to use the agent for the legitimate MeshCentral instead of the UltraVNC module, which they had previously used to gain remote access to systems."

See also: ESET: GoldenJackal hackers target air-gapped systems

Kaspersky said that the hackers primarily targeted Russian government services, their contractors and industrial enterprises.

The Awaken Likho group, also known as Core Werewolf and PseudoGamaredon, was first documented by BI.ZONE in June 2023. At that time, attacks against the defense sector and critical infrastructure were detected. The group is believed to have been active since at least August 2021.

Attackers often start with spear-phishing attacks that distribute malicious executable files disguised as Microsoft Word or PDF. Typically, they contain a double extension, such as “doc.exe”, “.docx.exe” or “.pdf.exe”, but users only see the .docx and .pdf parts of the extension.

See also: Ukrainian hackers behind the attack on Russian VGTRK?

However, opening these files triggers the installation of UltraVNC, allowing the Awaken Likho team to gain full control of the compromised hosts.

The latest attack discovered by Kaspersky is also based on an SFX archive file created using 7-Zip, which, when opened, triggers the execution of a file called “MicrosoftStores.exe.” This then decompresses an AutoIt script to ultimately execute the open-source MeshAgent remote management.

Russian government services

"These actions allow the APT group to persist in the system: the attackers create a scheduled task that executes a script, which, in turn, launches MeshAgent to establish a connection to the MeshCentral," Kaspersky said.

The group has also been linked to an attack on a Russian military base in Armenia as well as a breach at a Russian research institute involved in weapons development.

See also: Microsoft and DOJ targeted the infrastructure of Russian hackers ColdRiver

The attacks of this Awaken Likho serve as a reminder of the constantly evolving cyberwar landscape and the potential impacts it can have on both government entities and private organizations.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

As technology continues to advance, so must our defenses against these sophisticated threats. It is vital for governments and industries to work together to strengthen cybersecurity measures.

Source: thehackernews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS