The Shuckworm spy group (aka Gamaredon, Armageddon), believed to be associated with the Russian Federal Security Service (FSB), has been observed stepping up its cyber attacks against Ukraine.
A new Shuckworm campaign spotted by the Symantec Threat Hunter Team focused on obtaining military and security intelligence to aid potential aggressors.
In particular, it was intended to access sensitive information such as reports on Ukrainian military personnel, enemy engagements, airstrikes, arsenal inventories, and military training activities.
For more information on the group’s tactics, see Ukrainian Cyber Agency Reports Surge in Cyberattacks in Second Quarter.
Initial access was obtained via phishing emails containing malicious attachments of various file types. Shuckworm then deployed additional backdoors and tools to the victim’s machine.
Symantec also observed the attackers using a new PowerShell script to spread the custom backdoor malware Pterodo via USB drives.
“Many organizations forget the threat that USB devices pose to their organizations,” warns Erich Kron, security awareness advocate for KnowBe4.
“USB storage is portable in nature and is often used to share files and other information between individuals, making it an excellent vehicle for distributing malware within a network.”
Overall, the new campaign showed a high level of persistence, with some infestations lasting as long as three months.
To avoid detection, Shuckworm constantly updated its toolset. Symantec discovered up to 25 new variants of the group’s scripts observed each month from January to April 2023.
Additionally, they used legitimate services such as Telegram and its microblogging platform Telegraph to make their command and control infrastructure difficult to track.
“To protect themselves from such attacks, organizations should seriously consider whether the risk of using USB devices is worth it, and ensure that antivirus software is in place whenever these portable devices are connected to a computer. We need to make sure it scans,” Kron added.
“Additionally, with email phishing once again becoming a major attack vector, organizations must educate and train their users to spot and report phishing attempts.”