Cyber Hacking News

Russian hackers target governments by compromising embassy emails

0

A new phishing campaign was discovered by security analysts in which Russian hackers known as APT29 (aka Cozy Bear or Nobelium) targets diplomats and government entities.

The APT29 which has been active since 2014 is a state-sponsored actor that focuses on cyberespionage.

According to the analysts at Mandiant, a new campaign was spotted in which the hacker group is targeting diplomats and various government agencies through multiple phishing campaigns.

The messages pretend to contain important policy updates and originate from legitimate email addresses belonging to embassies.
In this campaign, Atlassian Trello, and other legitimate cloud service platforms were abused for command and control (C2) communication.

The spear-phishing campaign which started in January 2022 continued through March 2022 made use of various topics and depended on multiple sender addresses.

All the phishing emails originated from a legitimate compromised email address belonging to a diplomat which makes the recipients trust the emails.

It was found that the initially compromised addresses were listed as contact points on embassy websites.

The email used the HTML smuggling technique to deliver an IMG or ISO file to the recipient. This is a usual technique used by the APT29 in the past. The ISO archive contains a Windows shortcut file (LNK) that executed an embedded malicious DLL file when clicked.

The LNK file pretends to be a document file with the real extension hidden and a fake icon. The DLL execution results in the delivery of the BEATDROP downloader, which runs in memory after creating a suspended thread to inject itself into, and connects to Trello for C2 communication.

Later APT29 replaced BEATDROP with a new C++ BEACON loader based on Cobalt Strike that had higher-level capabilities such as keylogging, taking screenshot, a proxy server mode, account credentials exfiltration, enumeration, and port scanning.

Both loaders deployed BOOMIC, which Microsoft tracks as VaporRage, discovered and analyzed in May 2021. BOOMIC establishes persistence by modifying the Windows registry and then downloads various obfuscated shellcode payloads and runs them in memory.

Mandiant found various legitimate compromised websites serving as BOOMIC’s C2, which helps avoid URL blocklisting problems.

After establishing a presence in an environment, APT29 escalates privileges in less than 12 hours, using various techniques like writing files that contain Kerberos tickets. Then, they perform extensive network reconnaissance to identify valid pivoting points and gather more passwords, and finally, move laterally by dropping more Cobalt Strike beacons and then BOOMIC on adjacent systems.

The APT29 group however remains a top-level espionage threat for high-interest targets.

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

U.S. DoD tricked into paying millions to phishing actor

Previous article

Chinese cyber-espionage group targets Asian telecom sector

Next article

You may also like

Comments

Leave a reply

Your email address will not be published. Required fields are marked *