Iranian Government-Backed Hackers Targeting U.S. Energy and Transit Systems

April 19, 2023Rabbi LakshmananCyber ​​Threat / SCADA

US energy and transportation system

Iranian government-backed actor known as mint sand storm Associated with attacks targeting critical infrastructure in the United States from late 2021 to mid-2022.

“This Mint Sandstorm subgroup is technically and operationally mature, capable of developing bespoke tools, rapidly weaponizing N-day vulnerabilities, and agile in its operational focus. , and appears to be consistent with Iran’s national priorities,” the Microsoft Threat Intelligence team said. analysis.

Targeted entities consist of seaports, energy companies, transportation systems, and major U.S. utilities and gas companies. The activity is suspected to be in retaliation for attacks targeting shipping, rail, and gas station payment systems from May 2020 to late 2021.

It is worth noting here that Iran subsequently accused Israel and the US of masterminding attacks on gas stations to create unrest in the country.

Mint Sandstorm is the new name assigned to a threat actor previously tracked by Microsoft under the name Phosphorus, also known as APT35, Charming Kitten, ITG18, TA453, and Yellow Garuda.

The nomenclature change is part of Microsoft’s move from chemical-element-inspired monikers to a new weather-themed nomenclature taxonomy for threat actors, partly due to the “threat’s complexity, scale, and due to an increase in “quantity”.

Unlike MuddyWater (aka Mercury or Mango Sandstorm), which is known to operate on behalf of Iran’s Ministry of Intelligence and Security (MOIS), Mint Sandstorm is said to be associated with the Islamic Revolutionary Guard Corps (IRGC). I’m here.

The attacks detailed by Redmond demonstrate the ability of attackers to constantly refine their tactics as part of highly targeted phishing campaigns to gain access to target environments.

This includes quickly converting published proofs of concept (PoCs) related to flaws in internet-facing applications (such as CVE-2022-47966 and CVE-2022-47986) into playbooks for initial access and persistence. includes hiring to

A successful compromise deploys a custom PowerShell script. This script is used to activate one of two attack chains. The first attack relies on an additional her PowerShell script to connect to a remote server and steal the Active Directory database.

upcoming webinars

Master the Art of Dark Web Intelligence Gathering

Learn the art of extracting threat intelligence from the dark web – join us for this expert-led webinar!

Save my seat!

Another sequence uses Impacket to connect to an actor-controlled server and deploy custom implants called Drokbk and Soldier. The latter is a multi-stage .NET backdoor with the ability to download and run tools and uninstall itself.

Drokbk was detailed by the Secureworks Counter Threat Unit (CTU) in December 2022 and is attributed to a threat actor known as Nemesis Kitten (aka Cobalt Mirage, TunnelVision, or UNC2448), a subcluster of Mint Sandstorm. It has been with.

Microsoft also launched a low-volume phishing campaign that culminated in the use of a third custom and modular backdoor called CharmPower, a PowerShell-based malware capable of reading files, gathering host information, and exfiltrating data. Called the threat actor for enforcement.

“The capabilities observed in intrusions attributed to this Mint Sandstorm subgroup allow operators to hide C2 communications, remain on compromised systems, and deploy a variety of post-compromise tools with varying capabilities. It’s a concern,” the tech giant added.

Did you find this article interesting?Please follow us twitter and LinkedIn to read more exclusive content we post.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *