For several years, Kaspersky Lab has been closely monitoring more than 60 advanced threat actors responsible for digital attacks around the world.
The company's experts have seen almost everything, with attacks becoming increasingly complex, as even states have become involved in these activities and have tried to “equip themselves» with the most advanced tools.
However, only now have KasperskyLab experts been able to confirm that they have discovered a threat actor that surpasses anything known in terms of complexity and technical expertise. In fact, this actor has been active for almost two decades! It is the Equation.
According to researchers at Kaspersky Lab, this group is unique in almost every aspect of its activities. It uses particularly complex and expensive tools in their development, with the purpose of «infect» the victims, to retrieve data and to hide its activity in an extremely professional way, leveraging classic espionage techniques, so as to deliver malicious payloads to the victims.
To «infect» its victims, this group uses a powerful «arsenal» with «implants» (Trojans), including the following (based on names assigned by Kaspersky Lab): Equation Laser, Equation Drug, Double Fantasy, Triple Fantasy, Fanny and Gray Fish. Undoubtedly, there will be other active «implants» besides the aforementioned.
What makes the Equation Group unique?
Absolute persistence and concealment
The Global Research and Analysis Team of Kaspersky Lab managed to recover two units, which allow the reprogramming of hard‑drive firmware from more than 12 popular manufacturers. This is perhaps the most powerful tool in the «arsenal» of the Equation Group and the first known malicious software capable of «infecting» hard drives.
“A particular risk is that once a hard drive is ‘infected’ with this malicious payload, it is impossible to scan its firmware. To put it simply: on most hard drives there are functions to write to the firmware area, but there are no functions to read it back. This means that we are almost blind and have no ability to detect hard drives that have been ‘infected’ with this malware,” warns Costin Raiu, Director of Kaspersky Lab’s Global Research and Analysis Team.
Data recovery capability from isolated networks
The worm «Fanny» stands out from all attacks carried out by the Equation Group. Its main purpose was to map networks with «air gap». In other words, to understand the topology of networks that are not accessible and to execute commands on these isolated systems. For this purpose, a unique «command and control» mechanism is used, which is based on USB and allowed the attackers to transfer data to and from the networks with «air gap».
Specifically, a non «infected» USB stick with hidden storage space was used to collect basic system information from a computer that was not connected to the Internet, as well as to send them to the C&C mechanism when this USB was connected to a computer that had been infected by the worm «Fanny» and was connected to the Internet. If the attackers wanted to execute commands on networks with «air gap», they could store the commands in the USB's hidden storage space. As soon as the USB was connected to the computer with «air gap», the «Fanny» recognized the commands and executed them.
Classic espionage methods for delivering malicious software
The attackers used generic methods to «infect» their targets, not only via the internet but also in the physical world. For this reason, they used a hijacking technique, stealing data and replacing it with the corresponding Trojan versions. One such example concerned targeting participants at a scientific conference in Houston. When they returned home, some participants received a copy of the conference materials on a CD-ROM, which was then used to install the Trojan «Double Fantasy» on the target's device. The exact method by which the CDs were made available is unknown.
Infamous friends: Stuxnet and Flame
There are serious indications that the Equation Group has interacted with other powerful groups, such as the operators of Stuxnet and Flame. Generally, this particular group appears to have been in a position of superiority compared to other entities. The Equation Group had access to zero‑day threats before they were even used by Stuxnet and Flame. To some extent, they shared exploits with others.
For example, in 2008 the «Fanny» used two zero-day threats that were introduced into Stuxnet in June 2009 and March 2010. One of Stuxnet's zero-days was actually a module of Flame, which exploited the same vulnerabilities and was extracted “directly from the Flame platform and incorporated into Stuxnet.
Strong and geographically distributed infrastructure
The Equation Group uses a massive C&C infrastructure that includes more than 300 domains and over 100 servers. The servers are hosted in many countries, such as the USA, the United Kingdom, Italy, Germany, the Netherlands, Panama, Costa Rica, Malaysia, Colombia and the Czech Republic. Kaspersky Lab today uses «sinkholing» for more than 20 of the 300 C&C servers.
Thousands of high‑profile victims worldwide
Since 2001, the Equation Group has «infected» thousands or perhaps even tens of thousands of victims in more than 30 countries. The victims are found in the following sectors: Government and diplomatic organizations, Telecommunications, Aeronautics, Energy, Nuclear research, Oil and Natural Gas, Military Organizations and Nanotechnology. It also turned against Islamist activists, scientists, Mass Media, transportation companies, financial institutions and companies that develop encryption technologies.
Localization
Kaspersky Lab observed seven exploits used by the Equation Group in the eponymous malware. At least four of these were used as zero-day threats. Additionally, the use of unknown exploits, possibly zero-day, targeting Firefox 17 was observed, in the same way they are used in the Tor browser.
During the «infection» stage, the team has the ability to use ten exploits in a chain. However, Kaspersky Lab experts observed that no more than three are used. If the first is not successful, they try another, and then the third. If all three exploits fail, they do not «infect» the system.
Kaspersky Lab's products detected a number of attack attempts against users. Many of these attacks were not successful, thanks to the Automatic Exploit Prevention technology, which detects and blocks the exploitation of unknown vulnerabilities. The worm «Fanny» was likely created in July 2008, and was first detected and added to the blacklist of Kaspersky Lab's automatic systems in December 2008.
Source: secnews.gr



