Experts Uncover Year-Long Cyber Attack on IT Firm Utilizing Custom Malware RDStealer

June 20, 2023Ravi Lakshmanan

Malware RDStealer

A highly targeted cyberattack against an East Asian IT company involved the deployment of custom malware written in Golang. RDS Tealer.

In a technical report shared with The Hacker News, Bitdefender security researcher Victor Vrabie said, “This operation has been active for over a year, with the ultimate goal of compromising credentials and exfiltrating data. I was there,” he said.

Evidence collected by a Romanian cybersecurity firm indicates that the campaign was launched in early 2022. The target was an unspecified IT company in East Asia.

In its early stages, the operation relied on out-of-the-box remote access Trojans such as AsyncRAT and Cobalt Strike, but in late 2021 and early 2022, it will move to bespoke malware to thwart detection. bottom.

The main evasion tactic concerns the use of Microsoft Windows folders, which are likely to be excluded from scanning by security software (such as System32 and Program Files), to store the backdoor payload.

cyber security

One of the subfolders in question is “C:\Program Files\Dell\CommandUpdate”. This is the directory for the genuine Dell application named Dell Command | update.

Bitdefender states that all machines infected in the course of this incident were made by Dell, suggesting that the attackers deliberately chose this folder to camouflage their malicious activity.

This reasoning is supported by the fact that the attackers have registered command-and-control (C2) domains such as ‘dell-a’.[.]NTP updates[.]com” aims to blend into the target environment.

This intrusion set is characterized by the use of a server-side backdoor called RDStealer. This backdoor specializes in continuously collecting clipboard contents and keystroke data from the host.

But what makes it stand out is the ability to “monitor incoming RDP”. [Remote Desktop Protocol] If client drive mapping is enabled, a connection could be established and the remote machine compromised. ”

Therefore, when a new RDP client connection is detected, commands are issued by RDStealer to extract sensitive data such as browsing history, credentials, and private keys from apps like mRemoteNG, KeePass, and Google Chrome.

“This highlights the fact that attackers are actively seeking credentials and saved connections to other systems,” Bitdefender’s Marin Zugec said in a second analysis.

upcoming webinars

🔐 Mastering API Security: Understanding Your True Attack Surface

Discover untapped vulnerabilities in your API ecosystem and take proactive steps towards ironclad security. Join us for an insightful webinar!

join the session

In addition, connecting RDP clients were infected with another Golang-based custom malware known as Logutil, which used DLL sideloading techniques to maintain a persistent foothold on the victim network and facilitate command execution. increase.

Little is known about this threat actor other than the fact that it has been active since at least 2020.

“Cybercriminals are continuously innovating and exploring new techniques to make their malicious activities more credible and stealthy,” Zugek said.

“This attack is a testament to the increasing sophistication of modern cyberattacks, but also the ability of threat actors to exploit newfound sophistication to exploit older, widely-adopted technologies. It also emphasizes the facts.”

Did you enjoy this article? Follow us twitter You can read more exclusive content we post on LinkedIn.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *