Athens, July 7, 2014
Kaspersky Lab researchers have discovered that legacy Miniduke implants from 2013 are still being used in active cyber campaigns against government agencies and other entities. In addition, Miniduke’s new platform, called BotGenStudio, can now be used not only by cybercriminals launching Advanced Persistent Threat (APT) attacks, but also by law enforcement agencies and traditional criminals.
Last year, in the wake of the announcement made by Kaspersky Lab and its partner, CrySyS Lab, the perpetrators of the Miniduke APT stopped their campaign, or at least reduced its intensity. However, in early 2014, Miniduke attacks became fully active again. This time, Kaspersky Lab experts have noticed changes in the attackers’ modus operandi and the tools they use.
After the 2013 revelation, the perpetrators behind Miniduke began using another custom backdoor, which has the ability to intercept various types of information. The malware “tweaks” popular applications designed to run “deep” in systems, including file information, icons, and even file size.
Unique features
The main “new” Miniduke backdoor (also known as TinyBaron or CosmicDuke) is created using a customizable framework called BotGenStudio, which has the flexibility to enable or disable features when the bot is ready. The malware is able to steal a wide range of information. The backdoor also has many other capabilities, such as the following functions: keylogger, collection of general network information, capture of screenshots, recording of keystrokes, extraction of information from Microsoft and Windows Address Book, interception of passwords for Skype, extraction of information from Google Chrome, Google Talk, Opera, TheBat!, Firefox and Thunderbird, as well as interception of confidential information from protected storage systems, as well as extraction of certificates/private keys, etc.
The malware makes various network connections to extract data, including FTP uploads and three different variations of HTTP communication mechanisms. The storage of extracted data is another interesting feature of MiniDuke. When a file is uploaded to the Command & Control server, it is split into small pieces (about 3Kb), which are compressed, encrypted, and placed in a container before the upload is complete. If the file is large enough, it can be placed in several different containers that are uploaded independently. All these layers of additional processing ensure that very few researchers will be able to access the original data.
Each MiniDuke victim is assigned a unique ID, which allows specific updates to be pushed to each victim individually. For self-protection, the malware uses a custom obfuscated loader that has a high impact on CPU resources before executing the payload. In this way, the perpetrators prevented anti-malware solutions from analyzing the implant and detecting malicious operation via simulator. This also complicates the analysis of the malware.
C & C Servers – dual purpose
During the analysis, KasperskyLab experts managed to obtain a copy of one of the CosmicDuke command and control servers (C&C). It appears that it was used not only for communication between those behind CosmicDuke and the infected computers, but also for other activities of the group members, including hacking into other servers on the Internet, with the aim of collecting any information or media that could lead to potential targets. For this purpose, the C&C server was equipped with a number of available hacking tools to search for vulnerabilities in websites using different engines in order to attack them.
The victims
Interestingly, while the older Miniduke implants were primarily used against government targets, the new CosmicDuke implants have a different typology of victims. In addition to government organizations, they also target diplomatic missions, the energy sector, telecommunications, military equipment suppliers, and individuals involved in the trafficking and sale of illegal and controlled substances.
KasperskyLab experts analyzed both CosmicDuke and Miniduke servers. From the latter, KasperskyLab experts were able to extract a list of victims and the countries they corresponded to, and thus the experts discovered that users of the legacy Miniduke servers were interested in targets in Australia, Belgium, France, Germany, Hungary, the Netherlands, Spain, Ukraine, and the USA. Victims in at least three of these countries fall into the category of “government targets.”.
One of the CosmicDukeservers analyzed had a long list of victims (139 unique IP addresses), starting in April 2012. In terms of geographical distribution, the ten countries where the most victims were found are Georgia, Russia, the USA, Great Britain, Kazakhstan, Belarus, Cyprus, Ukraine and Lithuania. The attackers also showed a slight interest in expanding their activities and scanned IP addresses and servers in Azerbaijan, Greece and Ukraine.
Trading platform
The most unusual victims discovered were individuals who appeared to be involved in the trafficking and sale of controlled and illegal substances, such as steroids and hormones. These victims were only observed in Russia.
“It’s a bit unexpected – normally, when we hear about APT attacks, we tend to think that these are state-sponsored cyber espionage campaigns. But we see two explanations for this. One possibility is that the BotGenStudio malware platform used in Miniduke is also available as one of the so-called ‘legitimate spyware tools’, such as HackingTeam’s RCS, which is widely used by law enforcement agencies. Another possibility is that the platform is simply available in the underworld and is being bought by various pharmaceutical competitors to spy on each other,” commented Vitaly Kamluk, Principal Security Researcher at Kaspersky Lab’s Global Research & Analysis Team.
Localization
Kaspersky Lab products detect the CosmicDuke backdoor, under the codenames Backdoor.Win32.CosmicDuke.gen and Backdoor.Win32.Generic.
For more information, read KasperskyLab's blog on Securelist.com.
About Kaspersky Lab
Kaspersky Lab is the world's largest privately held computer security company. The company is among the top four security providers in the world*. Throughout its 16-year history, Kaspersky Lab has been pioneering security innovations, providing cost-effective solutions to protect consumers, small and medium-sized businesses and large enterprises. Today, Kaspersky Lab operates in 200 countries and regions around the world, providing online security to over 300 million users. For more information, visit: www.kaspersky.com .
- Based on IDC’s “Worldwide Endpoint Security Revenue by Vendor” ranking for 2012. Ranking included in IDC’s “Worldwide Endpoint Security 2013–2017 Forecast and 2012 Vendor Shares” report (IDC #235930, August 2013). The report included a ranking of software vendors based on revenue from sales of computer security solutions in 2012.
Kaspersky Contact
Konstantinos Memos
Advocate/ Burson-Marsteller
210 6931000
kmemmos@advocate-bm.gr

