HomeSecurityNoisyBear hackers target the energy sector

NoisyBear hackers target the energy sector

A hacking group called NoisyBear has emerged as a significant threat to Kazakhstan's energy sector, using advanced tactics to infiltrate critical infrastructure through malicious ZIP files and PowerShell-based attack chains.

hackers NoisyBear

This group has organized targeted campaigns against KazMunaiGas (KMG), the country's national oil and gas company, using phishing emails that mimic legitimate internal communications regarding payroll programs and policy updates.

The attack methodology demonstrates remarkable social engineering, with threat actors compromising legitimate business email accounts within KazMunaiGas to lend authenticity to their malicious communications. These emails contain ZIP attachments that appear to be urgent HR documents, creating a false sense of legitimacy that encourages employee interaction.

See also: GhostRedirector hackers compromise Windows Servers with malicious IIS Module

The complexity of the campaign extends beyond simple phishing, incorporating multi-stage payload delivery systems. They leverage trusted binaries and PowerShell execution environments to remain hidden throughout the infection process.

Seqrite researchers detected the activities of this threat group in April 2025, with active campaigns intensifying throughout May 2025. Researchers noted that NoisyBear's operational patterns suggest a Russian origin (Russian comments within the malicious code , use of sanctioned hosting services, and targeting patterns consistent with Russia's geopolitical interests).

Analysis of the group’s infrastructure reveals connections to Aeza Group LLC, a sanctioned hosting provider. The malware’s impact extends beyond simple data theft, incorporating advanced persistence mechanisms and defense evasion techniques that allow for prolonged network access.

See also: Stealerium malware targets educational institutions

NoisyBear hackers target the energy sector

Victims face potential exposure of sensitive corporate communications, strategic planning documents, and operational data critical to Kazakhstan’s energy infrastructure. The campaign’s focus on energy sector entities raises concerns about potential disruptions to critical national infrastructure and economic stability.

NoisyBear: Infection Mechanism and Technical Analysis

As we mentioned above, the NoisyBear infection chain starts with malicious ZIP containing three crucial elements: a decoy document bearing the official KazMunaiGas logo, a README.txt file providing execution instructions, and a weaponized LNK file named “График зарплат.lnk” (Salary Schedule.lnk).

The malicious shortcut file uses PowerShell as the Living Off The Land Binary (LOLBIN) to perform advanced download operations.

When executed, the LNK file launches a PowerShell command that retrieves a malicious batch script named “123.bat” from the remote server “77.239.125.41:8443”.

See also: XWorm: New Infection and Detection Evasion Techniques

The downloaded script is strategically placed in the C:\Users\Public directory, a location chosen for its accessibility and reduced security. The batch script acts as a secondary loader, downloading PowerShell scripts that the researchers have dubbed “DOWNSHELL”. These loaders demonstrate advanced techniques for bypassing the Anti-Malware Scan Interface (AMSI), using reflection to manipulate the System.Management.Automation.AmsiUtils class.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The malware sets the “amsiInitiFailed” flag  to convince PowerShell that AMSI initialization failed, effectively disabling real-time scanning capabilities for subsequent malicious operations. The final payload includes process injection techniques targeting explorer.exe, using classic CreateRemoteThread injection methods. Finally, the malware uses OpenProcess, VirtualAllocEx, WriteProcessMemory, and CreateRemoteThread API calls to inject Meterpreter reverse shell capabilities, establishing persistent backdoor access for data extraction and remote command execution.

NoisyBear hackers target the energy sector

The NoisyBear case highlights how cyberwarfare is becoming a tool for geopolitical influence. The fact that the energy sector is being targeted shows that hackers are not simply seeking financial gain but are seeking to damage critical infrastructure with wider implications. The use of sophisticated persistent access techniques highlights the security gap that still exists even in strategic organizations, confirming that resilience to such threats must be treated as a national priority.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS