Security researchers from ESET have discovered the Roaming Tiger hacking campaign, in which bad actors target Russian businesses.
'Roaming Tiger' is the name of a cyber espionage campaign targeting high-profile organizations in Russia and countries of the former Soviet Union, including Belarus, Kazakhstan, Kyrgyzstan, Tajikistan, Ukraine and Uzbekistan.
The Roaming Tiger campaign was discovered by ESET experts in 2014, while researcher Anton Cherepanov presented the findings of his research at the ZeroNights security conference held in 2014.
According to experts, the threat actors behind the Roaming Tiger campaign rely on RTF exploits and the PlugX RAT, while analysis of the command and control (C&C) infrastructure also suggests the participation of Chinese hackers.
Over the summer, Palo Alto Networks experts discovered another hacking campaign that bears several similarities to Roaming Tiger. The attacks target organizations and businesses in the same countries, but instead of PlugX, the hackers used a new tool called BBSRAT.
The threat actors mostly used spear phishing emails with a malicious Word document attached.

The Word document was designed to exploit an old Microsoft Office vulnerability (CVE-2012-0158) in order to distribute the BBSRAT malware.
This flaw was also exploited during attacks observed by ESET experts last year. Surprisingly, BBSRAT used the same C&C architecture as the Roaming Tiger campaign.
Summarizing the characteristics of the Roaming tiger campaign, we have:
- High profile victims in Russia
- Exploiting RTF vulnerabilities (CVE-2012-0158 and CVE-2014-1761)
- Win32/Korplug (aka PlugX RAT) • Win32/Farfli.BEK (aka Gh0st RAT)
