The Desert Falcons, a digital espionage group targeting numerous organizations and high-profile individuals from Middle Eastern countries, were revealed during Kaspersky Lab’s Security Analyst Summit in Mexico. Analysts consider the group to be the first known Arab group of “digital mercenaries” to have developed and carried out comprehensive digital espionage.
The list of victims targeted includes military and government organizations, and in particular, executives tasked with combating money laundering. The attack targeted executives from the health and economic sectors, leading media outlets, research and educational institutions, energy and utility providers, activists and political leaders, personal security companies, and other targets holding important geopolitical information.
The operation has been active for at least two years. The Desert Falcons group began to develop and consolidate its operations in 2011. However, the beginning of the group's main activity and malware infections is placed in 2013. The peak of their activity is recorded in early 2015.
The vast majority of targets are located in Egypt, Palestine, Israel and Jordan.
In addition to the Middle Eastern countries, which were the initial targets, the Desert Falcons group is also active outside of this region. In total, its members have managed to attack more than 3,000 victims, in more than 50 countries worldwide, having stolen over a million files.
The attackers use self-developed malicious tools to launch attacks on Windows computers and Android devices.
Kaspersky Lab experts have many reasons to believe that the native language of the Desert Falcons group members is Arabic.
Although the perpetrator of the attack appears to be operating in countries such as Egypt, Palestine, Israel and Jordan, many victims were also found in Qatar, Saudi Arabia, the United Arab Emirates, Algeria, Lebanon, Norway, Turkey, Sweden, France, the United States, Russia and other countries
The primary method used by the Desert Falcons group to deliver malicious payloads was spearphishing via email, social media messages, and chat messages. The phishing messages contained malicious files (or links to malicious files) that mimicked legitimate documents or applications.
The Desert Falcons group uses various techniques to lure its victims into executing malicious files. One of the most prominent techniques used by the group is the so-called “Right-to-Left Override”. This technique exploits a special Unicode character to reverse the order of characters in a file name, hiding a dangerous extension in the middle of the name and placing a fake, seemingly harmless file extension near the end of the file name. Using this technique, malicious files (.exe, .scr) look like a harmless document or PDF file, while even careful users with good technical knowledge can be fooled and “run” these files. For example, a file with the extension “.fdp.scr” would appear as “.rcs.pdf”.
After successfully infecting the victim, Desert Falcons members use one of two different backdoors, either their main Trojan or the DHS Backdoor, which appear to have been developed from scratch and are in constant development. Kaspersky Lab experts have identified over 100 malware samples used by this group for attacks.
The malicious tools used have full Backdoor functionality. Thus, they can take screenshots, intercept keystrokes, upload or download files, collect information about all Word and Excel files on a victim's hard drive or connected USB devices, intercept passwords stored in the system registry (Internet Explorer and Live Messenger), and make audio recordings. Kaspersky Lab experts also managed to detect traces of the activity of a malware, which appears to be a backdoor for Android, with call and SMS logging capabilities.
Source: protothema.gr

