Arid Viper Hacking Group Using Upgraded Malware in Middle East Cyber Attacks

April 4, 2023Rabbi LakshmananCyber ​​Threat/Malware

malware

threat actor known as dry viper has been observed using an updated variant of its malware toolkit in attacks targeting Palestinian entities since September 2022.

Symantec tracks the group under the insect-themed name Mantis, and says the attackers “go to great lengths to maintain a persistent presence on targeted networks.” .

The hacking group, also known as APT-C-23 and Desert Falcon, has been involved in attacks targeting Palestine and the Middle East since at least 2014.

Mantis has used homegrown malware tools such as ViperRat, FrozenCell (aka VolatileVenom), and Micropsia to execute and conceal campaigns on Windows, Android, and iOS platforms.

According to a report published by Kaspersky in February 2015, the threat actor is believed to be native Arabic-speaking and based in Palestine, Egypt, and Turkey. Previous public reports have linked the group to Hamas’ cyber warfare arm.

In April 2022, a high-profile Israeli national employed by sensitive defense, law enforcement, and emergency services organizations was identified as being targeted by a new Windows backdoor called BarbWire.

The group’s series of attacks typically uses spear-phishing emails and fake social credentials to lure targets into installing malware on their devices.

The latest attacks detailed by Symantec use updated versions of custom Micropsia and Arid Gopher implants to compromise targets before engaging in credential theft and exfiltration of stolen data.

An executable coded in the Go programming language, Arid Gopher is a variant of Micropsia malware first documented by Deep Instinct in March 2022.

Along with the ability to launch secondary payloads (such as Arid Gopher), Micropsia records keystrokes, takes screenshots, stores Microsoft Office files inside RAR archives, and extracts them using custom-built Python-based tools. It’s designed to.

THN webinars

Become an Incident Response Pro!

Unlocking the Secrets of Bulletproof Incident Response – Master the 6-step process with Asaf Perlman, IR Lead at Cynet!

Don’t miss it – secure your seat!

“Arid Gopher, like its predecessor Micropsia, is an information-stealing malware whose purpose is to establish a foothold, gather sensitive system information, and send it back to the C2 (command and control) network.” Deep Instinct says: time.

Evidence gathered by Symantec indicates that Mantis installed three different versions of Micropsia and Arid Gopher on three sets of workstations between December 18, 2022 and January 12, 2023 as a method of maintaining access. Moved to expand.

Arid Gopher has undergone regular updates and complete code rewrites, with attackers “aggressively changing logic between variants” as an evasion mechanism.

“Mantis appears to be a staunch adversary, spending time and effort generously to maximize its chances of success. It is evidenced by the decision to segment it into multiple separate strands to reduce the likelihood that the entire operation will be detected.”Symantec concluded.

Did you find this article interesting?Please follow us twitter and LinkedIn to read more exclusive content we post.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *