CERT-UA Uncovers Gamaredon’s Rapid Data Exfiltration Tactics Following Initial Compromise

July 17, 2023THNMoreCyber ​​Attack / Data Safety

Data withdrawal

A Russian-linked threat actor known as Gamaredon has been observed conducting data exfiltration operations within an hour of the initial compromise.

“As the main compromise vector, most often emails and messages in messengers (Telegram, WhatsApp, Signal) are used with previously compromised accounts,” said the Ukrainian computer emergency response team ( CERT-UA) says: said in a group analysis published last week.

Gamaredon, also known as Aqua Blizzard, Armageddon, Shuckworm, or UAC-0010, is a state-sponsored attacker linked to SBU headquarters in the Autonomous Republic of Crimea, which was annexed by Russia in 2014. The group infected thousands of government computers.

It is also one of many Russian hacking groups that have maintained an active presence since the start of the Russo-Ukrainian War in February 2022, using phishing campaigns to deliver PowerShell backdoors such as GammaSteel. and perform reconnaissance and execute additional commands.

The message usually contains an archive with HTM or HTA files that, when opened, launches a series of attacks.

Data withdrawal

According to CERT-UA, GammaSteel matches a specific set of extensions (.doc, .docx, .xls, .xlsx, .rtf, .odt, .txt, .jpg, .jpeg, .pdf, .) used to extract files that ps1, .rar, .zip, .7z, and .mdb – within 30-50 minutes.

The group has also been observed to utilize USB infection techniques for propagation, constantly evolving its tactics. If he runs with a compromised host for a week, there could be between 80 and 120 malicious files, officials say.

upcoming webinars

Shielding Against Insider Threats: Mastering SaaS Security Posture Management

Worried about insider threats? We’ve got you covered! Join us for this webinar to explore practical strategies and proactive security secrets using SaaS Security Posture Management.

join today

Threat actors also used AnyDesk software for interactive remote access, PowerShell scripts for session hijacking to bypass two-factor authentication (2FA), and Telegram and Telegram to obtain command and control (C2) server information. It’s also important that you’re using Telegraph.

CERT-UA said, “Attackers take individualized measures to ensure network infrastructure resilience and to avoid detection at the network level.” “Over the course of a day, the intermediate control node’s IP address could change her three to six times, or more. This shows, among other things, that the process is well automated. .”

Did you enjoy this article? Follow us twitter You can read more exclusive content we post on LinkedIn.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *