HomeSecurityNew Enhanced BlackEnergy Crimeware Targets Linux Systems and Cisco Routers

New Enhanced BlackEnergy Crimeware Targets Linux Systems and Cisco Routers

cyber security

Kaspersky Lab security researchers have uncovered new capabilities in the BlackEnergy crimeware , which now has the ability to infiltrate routers and Linux and Windows systems via Cisco network devices.

The Global Research & Analysis Team published a report on Monday detailing some of the new “relatively unknown” plug-in capabilities developed for BlackEnergy to attack Cisco and target ARM and MIPS platforms.

The malware was upgraded with custom  plugins including Ciscoapi.tcl which targets The Borg kit and according to the researchers, the upgraded version contained various wrappers to Cisco EXECcommands as well as a message about Kaspersky, which says “F*uck U, Kaspersky!!! U never get a fresh B1ack En3rgy. So, thanks C1sco 1td for built-in backd00rs & 0-days”.

[alert variation=”alert-info”]The BlackEnergy malware was originally created and used by cybercriminals in Distributed Denial-of-Service (DdoS) attacks and was later augmented with several custom plugins used to exfiltrate banking information.[/alert]

Most recently, the BlackEnergy malware was detected in the alleged attack targeting NATO, Ukrainian and Polish government agencies, as well as several sensitive European industries over the past year.

Now, the malware has been enhanced and has capabilities to scan ports, steal passwords, collect system information, steal digital certificates, remotely connect to the desktop, and delete data or destroy a hard drive.

In the event that the victim detects BlackEnergy on their system, the attacker activates the “dstr,” plugin, which erases data from hard drives and replaces it with random data, and can attack a second victim using the VPN credentials collected from the first victim.

However, experts are unsure of the purpose of some plugins, including one that gathers information about connected USB drives, and another that collects data about the BIOS (Basic Input/Output System), motherboard, and processor of the infected systems.

“We are fairly confident that our list of [BlackEnergy] tools is not complete,” the researchers wrote. “For example, we have not yet obtained the plugin for accessing the router, but we are confident that it exists. There are also indications that a plugin exists for decrypting the victim’s files.”.

Many anonymous companies in various countries were targeted by the latest version of the BlackEnergy malware, including victims in Russia, Germany, Belgium, Turkey, Libya, Vietnam, and many other countries.

Another crimeware group, the Sandworm group, is reported to have used BlackEnergy exclusively during 2014, including their ownplugins and scripts.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS