The North Korean state-sponsored hacking group ScarCruft has been linked to a cyberattack on the IT infrastructure and email server for NPO Mashinostroyeniya, a major Russian missile engineering organization.
NPO Mashinostroyeniya is a Russian designer and manufacturer of orbital vehicles, spacecraft, and tactical defense and attack missiles used by the Russian and Indian armies.
Cyber security firm SentinelLabs reported that ScarCruft is responsible for the hack of NPO Mashinostroyeniya’s email server and IT systems, where the threat actors planted a Windows backdoor named ‘OpenCarrot’ for remote access to the network.
ScarCruft (APT37) is a cyber-espionage group known to surveil and steal data from organizations as part of their cyber campaigns.
The breach was discovered by the security analysts after analyzing an email leak from NPO Mashinostroyeniya that contained highly confidential communications, including a report from IT staff warning of a potential cybersecurity incident in mid-May 2022.
According to the leaked emails, IT staff at NPO Mashinostroyeniya discussed suspicious network communication between processes running on internal devices and external servers.
This led to the company finding a malicious DLL installed on internal systems, causing them to engage with their antivirus firm to determine how they had become infected.
After analyzing the IP addresses and other indicators of compromise (IOCs) found in the emails, SentinelLabs determined that the Russian organization was infected with the ‘OpenCarrot’ Windows backdoor which is a feature-rich backdoor malware previously linked to the Lazarus Group.
When legitimate users on the compromised devices become active, OpenCarrot automatically enters a sleep state and checks every 15 seconds for the insertion of new USB drives that can be laced and used for lateral movement.
However, it is not clear if this was a joint operation between ScarCruft and Lazarus. The analysts are still determining the intrusion method.
Simultaneously, SentinelLabs saw evidence of suspicious traffic originating from the victim’s Linux email server, which was beaconing outbound to ScarCruft infrastructure.
SentinelLabs suggests that the involvement of two state-supported hacking groups could indicate a deliberate strategy by the North Korean state that controls both.
Image Credit : Hackread















Comments