An advanced persistent threat (APT) group, MuddyWater, that has ties with Iran’s Ministry of Intelligence and Security (MOIS) was linked to campaigns against government and private organizations in Turkey.
According to cybersecurity researchers from Cisco Talos, MuddyWater, also known as Mercury or Static Kitten, that has been active since at least 2017 has been tied to attacks against organizations in the US, Israel, Europe, and the Middle East in the past.
Earlier this year, US Cyber Command linked the APT to the Iranian government, saying that MuddyWater is one of many groups “conducting Iranian intelligence activities.”
US Cyber Command stated that MuddyWater is a subordinate element within the MOIS. According to the Congressional Research Service, the MOIS conducts domestic surveillance to identify regime opponents. It also surveils anti-regime activists abroad through its network of agents placed in Iran’s embassies.
Talos researchers Asheer Malhotra and Vitor Ventura stated that the latest MuddyWater campaign is utilizing malicious PDFs and Microsoft Office documents as an initial attack vector.
Phishing emails containing these malicious attachments are spoofed to appear to be from the Turkish Health and Interior Ministries. Targets included the Scientific and Technological Research Council of Turkey (Tubitak).
The malicious documents contained embedded VBA macros designed to trigger a PowerShell script, leading to the execution of a downloader for executing arbitrary code, the creation of a registry key for persistence, and the use of Living Off the Land Binaries (LOLBins) to hijack the machine.
After being inside a target system, MuddyWater focuses on three aims: conducting cyberespionage for state interests; stealing intellectual property with a high economic value, and deploying ransomware to deliberately disrupt a victim organization’s operators or to destroy evidence of their intrusions.
The researchers were not able to secure the final payload in this campaign due to verification checks on the operator’s command-and-control (C2) server.
The APT has also adopted canary tokens to keep track of their intrusions. Canary tokens are digital “canaries” that warn that a file has been opened and are usually used by defenders to detect and monitor potential breaches.
An advisory issued by Trakya and the Turkey National Cyber Incident Response Center (USOM) warns of an APT-level attack listed IPs and an email address that were also uncovered in the Talos analysis of this campaign.
Image Credits : Arab News














Comments