North Korean hackers target security researchers with a new backdoor

Stock image of a young woman wearing glasses surrounded by computer monitors in a dark office. In front of her is a see-through display showing a world map and some data.

Getty Images

Threat actors with ties to the North Korean government are targeting security researchers in hacking campaigns using new techniques and malware in hopes of gaining a foothold within the companies the targets work for, researchers say. says.

Researchers at security firm Mandiant said Thursday that they first discovered the campaign last June while tracking a phishing campaign targeting US-based tech customers. Hackers in this campaign attempted to infect targets with his family of three new malware, which Mandiant named Touchmove, Sideshow, and Touchshift. Hackers in these attacks also demonstrated new capabilities to counter endpoint detection tools while operating within targeted cloud environments.

“Mandiant suspects UNC2970 specifically targeted security researchers in this operation,” Mandiant researchers wrote.

Shortly after discovering the campaign, Mandiant responded to multiple intrusions of UNC2970 into US and European media organizations. UNC2970 used job-themed spear phishing to lure targets into trying to trick them into installing new malware.

Traditionally, UNC2970 has targeted organizations with job-themed spear-phishing emails. More recently, the group has turned to using a fake LinkedIn account of her claiming to be a recruiter. Accounts are carefully crafted to mimic the identities of legitimate individuals to trick targets and increase their chances of success. Ultimately, the attacker attempts to move the conversation to her WhatsApp, from where she uses her WhatsApp or email to deliver a backdoor that Mandiant invokes on her Plankwalk and other malware families.

Plankwalk and other used malware are primarily delivered via embedded macros in Microsoft Word documents. When the document is opened and macros are allowed to run, the target machine downloads and executes a malicious payload from the command and control server. One of the documents used looks like this:

Mandiant

The attacker’s command and control servers were primarily compromised WordPress sites, another technique known from UNC2970. The infection process involves sending the target an archive file containing a specifically malicious version of his TightVNC remote desktop application. In a post, Mandiant researchers further explain this process.

A ZIP file distributed by UNC2970 contained what victims believed was a skills assessment test for job applications. The ZIP actually contained an ISO file of him, a Trojanized version of his TightVNC that Mandiant tracks as her LIDSHIFT. The victim was instructed to run the TightVNC application. This application, along with other files, is aptly named for the company the victim was supposed to be evaluated for.

In addition to functioning as a regular TightVNC viewer, LIDSHIFT contained several hidden features. The first was that when run by the user, the malware would beacon back to a hardcoded C2. The only interaction this required from the user was launching the program. This lack of interaction is unlike what MSTIC observed in a recent blog post. His first C2 beacon from LIDSHIFT contains the victim’s initial username and hostname.

The second function of LIDSHIFT is to reflectively insert encrypted DLLs into memory. The injected DLL is a trojanized Notepad++ plugin that acts as a downloader that Mandiant tracks as his LIDSHOT. LIDSHOT is injected as soon as the victim opens a dropdown within her TightVNC Viewer application. LIDSHOT has her two main functions: enumerating systems and downloading and executing shellcode from C2.

The attack continues by installing the Plankwalk backdoor. This can install various additional tools, such as his InTune for Microsoft endpoint application. You can use InTune to deliver configurations to endpoints registered with your organization’s Azure Active Directory service. UNC2970 appears to be using legitimate applications to evade endpoint protection.

“The malware tools identified highlight the continued malware development and deployment of new tools by UNC2970,” Mandiant researchers wrote. “While the group has previously targeted the defense, media and technology industries, its targeting of security researchers suggests a shift in strategy or expansion of its activities.”

While UNC2970 may be the first time a security researcher has been targeted, other North Korean actors have been involved in this activity since at least 2021.

Targets can reduce their chances of being infected in these campaigns by using:

  • multi-factor authentication
  • Cloud-only account to access Azure Active Directory
  • A separate account for sending email, web browsing, and similar activities, and a dedicated administrator account for sensitive administrative functions.

Organizations should also consider other protections such as macro blocking, privileged identity management, conditional access policies, and the use of security restrictions in Azure AD. We also recommend asking multiple administrators to approve her InTune transactions. A full list of mitigations is included in his Mandiant post linked above.

Source link

Leave a Reply

Your email address will not be published. Required fields are marked *