CommonMagic Malware Implants Linked to New CloudWizard Framework

The CommonMagic malware implant is associated with a previously unknown advanced persistent threat campaign related to the Russian-Ukrainian conflict and relies on a new modular framework.

The framework, dubbed “CloudWizard,” was discovered by Kaspersky security researchers and described in an advisory published today.

Leonid Bezvershenko, Georgy Kucherin, and Igor Kuznetsov emphasized that a section of CloudWizard code is identical to CommonMagic. This is because they employ the same encryption library, follow a similar file naming format, and share the victim’s location.

Read more about Russia’s cyber attack strategy in Ukraine: Russian cyber attack shows ‘unprecedented’ speed and agility

The same active threat actor is also believed to be involved in malicious campaigns known as Operation Groundbait and Operation BugDrop.

The researchers said CloudWizard victims were not limited to the Donetsk, Lugansk and Crimea regions of Ukraine, but also included central and western regions. Targets included individuals, diplomatic agencies, and research institutions.

CloudWizard provides 9 modules that collectively provide various hacking functions such as file collecting, keylogging, screenshot capturing, microphone input recording, password theft, etc. It can also exfiltrate Gmail cookies from the browser database, access and exfiltrate activity logs, contact lists and all email messages associated with the targeted account.

“The threat actors behind these operations have demonstrated over 15 years of continuous enhancement of their toolset, targeting of organizations of interest, and ongoing cyber espionage efforts. ,” Kucherin commented on the findings.

“Geopolitical factors remain a key motivation for APT attacks, and given the prevailing tensions in the conflict regions of Russia and Ukraine, we expect this actor to continue operating for the foreseeable future. .”

Kaspersky’s report comes months after the Russian government announced that authorities would no longer be able to use a messaging app developed and operated by a foreign company allegedly to minimize the possibility of classified information reaching Ukraine’s allies. Announced.

Source link

Leave a Reply

Your email address will not be published. Required fields are marked *