Russia’s Shuckworm cyber group launching ongoing attacks on Ukraine

Malware downloading data logging and other espionage tools aimed at Ukrainian organizations.

Anonymous hacker working on a laptop, flags of Ukraine and Russia
Image: Adobe Stock

The Russia-linked cyber group Shuckworm is continuing to target Ukrainian organizations with infostealing malware. According to Symantec’s Threat Hunter Team, part of Broadcom Software, much of the current activity is an extension of attacks that were reported by the Computer Emergency Response Team of Ukraine (CERT-UA) in July.

Shuckworm (aka, Gamaredon, Armageddon) is a eight-year-old cyber crime group that focuses almost exclusively on Ukraine, Symantec said.

“Shuckworm is generally considered to be an espionage operation … ,” said Brigid Gorman, senior intelligence analyst on the Symantec’s Threat Hunter Team. “Fear of exposure does not appear to deter Shuckworm from continuing its activities.”

The infostealer payload is capable of recording audio using the system’s microphone, take screenshots, log keystrokes and download and execute .exe and .dll files.

Infection Vector

Symantec said Shuckworm used self-extracting 7-Zip files, which were downloaded via email. The binaries in the 7-Zip files subsequently downloaded mshta.exe, an XML file, which was likely masquerading as a HTML application, from the domain a0698649[.]xsph[.]ru. It has been publicly documented since May 2022 that subdomains of xsph[.]ru are associated with Shuckworm activity.

This domain was used in a phishing attack spoofing the Security Service of Ukraine with “Intelligence Bulletin” in the subject line, according to CERT-UA.

SEE: Password breach: Why pop culture and passwords don’t mix (free PDF) (TechRepublic)

Attack Chain

Running mshta.exe executed a PowerShell stealer. Symantec logged three versions of the same PowerShell stealer on one system.

“It’s possible the attackers may have deployed multiple versions of the stealer, which were all very similar, as an attempt to evade detection,” Symantec said in a blog post detailing the attacks.

Two VBS downloaders with the words “juice” and “justice” in their file names also were seen on victim machines. These filenames are associated with Backdoor.Pterodo, a well-known Shuckworm script capable of calling PowerShells, uploading screenshots and also executing code downloaded from a command-and-control server, Symantec said.

Shuckworm also is deploying the Giddome backdoor, another well-known espionage tool. Some of these Giddome variants may have originated from VCD, H264, or ASC files. Similar to .ISO files, VCD files are images of a CD or DVD recognized by Windows as an actual disc.

The legitimate remote desktop protocol tools Ammyy Admin and AnyDesk were also leveraged by the attackers for remote access—a common tactic used by cyber gangs, Symantec said.

To protect your organization from Shuckworm, Gorman said to:

  • Adopt a defense-in-depth strategy using multiple detection, protection and hardening technologies
  • Monitor the use of dual-use tools inside the network
  • Use the latest version of PowerShell with logging enabled
  • Audit and control IT administrative account usage
  • Use one-time credentials for IT admins
  • Create profiles of usage for IT admins and their tools since many of these tools are used by attackers to move laterally through a network
  • Implement multi-factor authentication
  • Scan their systems for the indicators of compromise

Source link

istanbul escort aksaray escort arnavutköy escort ataköy escort avcılar escort avcılar türbanlı escort avrupa yakası escort bağcılar escort bahçelievler escort bahçeşehir escort bakırköy escort başakşehir escort bayrampaşa escort beşiktaş escort beykent escort beylikdüzü escort beylikdüzü türbanlı escort beyoğlu escort büyükçekmece escort cevizlibağ escort çapa escort çatalca escort esenler escort esenyurt escort esenyurt türbanlı escort etiler escort eyüp escort fatih escort fındıkzade escort florya escort gaziosmanpaşa escort güneşli escort güngören escort halkalı escort ikitelli escort istanbul escort kağıthane escort kayaşehir escort küçükçekmece escort mecidiyeköy escort merter escort nişantaşı escort sarıyer escort sefaköy escort silivri escort sultangazi escort suriyeli escort şirinevler escort şişli escort taksim escort topkapı escort yenibosna escort zeytinburnu escort porno 1080p porno izle 4k porno izle 720p porno izle abella danger alman alman porno alman porno izle aloha tube porno amatör amatör porno amatör porno izle anal anal porno anal porno izle arap porno asa akira porno asyalı porno bangbros porno bangbros porno izle banyoda sikis başörtülü porno beeg porno izle beyaz tenli porno izle biseksuel porno izle bisexsuel porno brandi love porno brazzers brazzers porno izle canli porno canli porno izle çinli porno çinli porno izle ensest porno ensest porno izle ensest seks erotik porno erotik porno izle esmer porno esmer porno izle etek altı fake agent fake taxi fake taxi porno fantazi pornoları fantezi porno izle fetiş porno fetiş porno izle fetish fransız porno fransız porno izle full hd hg porno izle gangbang porno genç kız porno izle genç kız sikişi genç teen porno izle gizli çekim porno gizli çekim pornosu grup pornosu grup porno grup porno izle hd pornolar hd porno hd porno izle hemşire porno hemşire pornosu hizmetçi porno hizmetçi porno izle ingiliz porno japon pornoları japon porno kızlık bozma kızlık bozma porno izle konulu porno konulu porno izle koreli porno köylü pornoları kumral porno kumral porno izle latin pornoları latin porno latin porno izle lezbiyen pornoları lezbiyen porno lezbiyen porno izle lisa ann porno liseli pornoları liseli porno liseli porno izle manken porno manken porno izle masaj porno izle masturbasyon porno izle masturbasyon pornoları mature porno mia khalifa porno mia malkova porno milf porno izle mobil porno mobil porno izle öğrenci porno izle öğretmen porno izle okul porno izle olgun kadın pornosu olgun porno oral porno oral porno izle oral seks porna izle pornhub pornhub porno izle porno film izle porno indir porno izle porno resimler porno star porntube porno izle redtube redtube pornoları riley reid porno rokettube rus pornoları rus porno rus porno izle sakso blowjob porno izle sarışın pornoları sarışın porno sarışın porno izle sarışın pornoları sekreter porno shemale sikiş sikiş sikiş izle şişman porno siyahi pornoları suriyeli pornoları swinger porno tecavüz porno teen porn türbanlı pornoları türbanlı porno türk pornoları türk porno türk porno izle türkçe altyazılı porno türkçe altyazılı porno izle xhamster pornoları xhamster porno xhamster porno izle xnxx xnxx porno xnxx porno izle xvideos xvideos porno izle yaşlı porno yeşilçam porno izle youjizz youporn youporn porno izle zenci porno güvenilir bahis siteleri bahis siteleri casino deneme bonusu casino siteleri deneme bonusu para yatırma bonusu bahis siteleri casino siteleribahis sitesi para yatırma