HomeSecurityCrouching Yeti: Espionage with 2,800 targets in Greece & Europe

Crouching Yeti: Espionage with 2,800 targets in Greece & Europe

crouching yetiCrouching Yeti: An active espionage campaign with more than 2,800 targets worldwide. Crouching Yeti also targeted targets in Greece and wider Southeastern Europe

Kaspersky Lab has published new analysis of the malware and Command & Control server infrastructure associated with the Crouching Yeti, as documented by experts from the company’s Global Research and Analysis Team. The campaign was launched in 2010 and is still active today, targeting new victims every day. It is also known as Energetic Bear.

Nicolas Brulez, Principal Security Researcher at Kaspersky Lab, said: “This campaign was originally named Energetic Bear by Crowd Strike, in keeping with its nomenclature. The “Bear” refers to the likely origin of the campaign, as Crowd Strike believes it originated in Russia. Kaspersky Lab is still investigating all available evidence. However, at this time, there are no strong indications in either direction. Our analysis also shows that the global targeting of the attackers extends beyond energy producers, where the campaign initially appeared to be focused. Based on this data, we decided to give the campaign a new name. Yeti resembles a bear, but its origin is mysterious.”.

Crouching Yeti is involved in several APT (Advanced Persistent Threat) campaigns. According to Kaspersky Lab research, the victims cover a wide range of businesses and organizations. Most of the identified victims come from the following sectors: industry/mechanical equipment, manufacturing, pharmaceuticals, construction, education, and IT.

In total, the number of victims identified exceeds 2,800 worldwide, of which Kaspersky Lab researchers were able to identify 101 companies/organizations. Based on the relevant list, Crouching Yeti seems to focus on strategic targets. However, it also seems that the attackers are also interested in other, not so “obvious”, targets. Kaspersky Lab experts believe that the latter may be “collateral victims”. However, it may also make sense to view Crouching Yeti not only as a highly targeted campaign focused on a very specific area of ​​interest, but also as a broad surveillance campaign with interest in various sectors. The companies and organizations attacked are mainly located in the USA, Spain and Japan.

In addition to the above countries, Crouching Yeti was also active in Greece. Specifically for our country, Kaspersky Lab's research identified that the campaign affected the network of a public academic research and technology organization, as well as the branch of a multinational courier company. Crouching Yeti also targeted different types of targets in the wider region of Southeastern Europe. Among others, its victims include a high-speed computer network administrator in Turkey, while in Croatia, an academic/research network and a Physics institute were affected.

Given the nature of the victims that have been identified, the main impact for them is the leakage of highly sensitive information, such as trade secrets, know-how, etc.

Industrial espionage: Malicious tools with multiple add-ons

Crouching Yeti is not a particularly sophisticated campaign. For example, the attackers did not use zero-day vulnerabilities, but programs that were developed for already known vulnerabilities. However, this did not prevent the campaign from remaining unnoticed for several years.

Kaspersky Lab researchers have found evidence of five types of malicious tools used by attackers to extract valuable information from compromised systems:

  • The Havex trojan
  • The Sysmain trojan
  • The ClientX backdoor
  • Karaganybackdoor and related stealers
  • Side moves and second-level tools

The Havex Trojan was the most widely used tool. In total, Kaspersky Lab researchers discovered 27 different versions of this malware and several additional modules, including tools aimed at collecting data from industrial control systems. Kaspersky Lab products detect and neutralize all variants of the malware used in this campaign.

To manage and control the campaign, Havex and the other malicious tools used connect to a large network of compromised websites. These websites "host" victim information and execute commands to infected systems, in combination with additional malicious modules.

The list of these additional modules includes tools for intercepting Outlook passwords and contacts, for taking screenshots, as well as tools for searching and stealing certain types of files, such as: text documents, spreadsheets, databases, PDF files, virtual disks, password-protected files, pgp security keys, etc.

Currently, the Havex Trojan is known to have two highly specialized modules, aimed at gathering data from specific industrial IT environments and transmitting it to the attacker. The OPC scanner module is designed to collect extremely detailed information about OPC servers running on a local network. Such servers are typically used where multiple industrial automation systems operate. The second module is a network scanning tool, which searches for all computers connected to ports associated with OPC/SCADA software. This tool attempts to connect to such hosts in order to determine the possible OPC/SCADA system in operation. It then transmits all the collected data to the command & control servers.

Mysterious origin

Kaspersky Lab researchers observed several meta-features that could indicate the national origin of the criminals behind the campaign. Specifically, they performed a timestamp analysis of 154 files and concluded that most samples were collected between 06:00 and 16:00 UTC (Coordinated Universal Time). These times could correspond to any country in Europe, including Eastern Europe.

The company's experts also analyzed the agent's language. The strings in the malware under analysis are in English (written by non-native speakers). Unlike several previous researchers of this campaign, Kaspersky Lab experts were unable to conclude that this agent is of Russian origin. In almost 200 malicious executable files and their associated operational content, there is no Cyrillic content (or any corresponding transliteration), in contrast to the recorded findings for campaigns such as RedOctober, Miniduke, Cosmic duke, Snake and TeamSpy. Also, language-related data points to people speaking French and Swedish.

Kaspersky Lab experts are continuing their investigation into this campaign, while also working with law enforcement and industry partners. You can find the full text of the research available on Securelist.com.

Source: secnews.gr

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS