Skip to content

Blog

New Iranian Campaign Tailored to US Companies Utilizes an Updated Toolset

APT34 is running a new campaign against Westat employees and the US organizations that hire Westat, using a malicious employee satisfaction survey spreadsheet as the initial vector. We analyze TONEDEAF 2.0, a heavily reworked version of the group's backdoor with a new C2 protocol, dynamic API resolution, string decoding and a decoy GUI window, alongside a stripped-down 64-bit VALUEVAULT 2.0 credential stealer. Both were fully undetected.

Read more →

January 30, 2020

Linux Rekoobe Operating with New, Undetected Malware Samples

Introduction Our research team has identified new versions of an old Linux malware known as Rekoobe, a minimalistic trojan with a complex CNC authentication protocol originally targeting SPARC and Intel x86, x86-64 systems back in 2015. The new malware samples have lower detection rates than their predecessors. We believe this malware ceased its operation in 2016 after it was reported, however, based on our findings we can estimate the operators behind Rekoobe have resumed their operations utilizing a newer version of the malware.

Read more →

January 20, 2020

ChinaZ Updates Toolkit by Introducing New, Undetected Malware

Introduction ChinaZ is a Chinese cybercrime group and the author of several DDoS malware. We have profiled this group in a previous article discussing connections between ChinaZ and other Chinese threat actors. Recently, we have discovered new tools being utilized by ChinaZ which have low detection rates in comparison to the group’s other, more common malware. VirusTotal detection rate of one of the discovered samples

Read more →

December 13, 2019

ACBackdoor: Analysis of a New Multiplatform Backdoor

Introduction We have discovered an undetected Linux backdoor which does not have any known connections to other threat groups. VirusTotal detection rate of ACBackdoor Linux variant In addition, we have found Windows variants of the same malware. As is common with most Windows variants, this variant has a higher detection rate than its Linux counterpart. VirusTotal detection rate of ACBackdoor Windows variant

Read more →

November 18, 2019

PureLocker: New Ransomware-as-a-Service Being Used in Targeted Attacks Against Servers

Analysis by Intezer and IBM X-Force points its origins to a Malware-as-a-Service (MaaS) provider utilized by the Cobalt Gang and FIN6 attack groups This is a mutual research between Intezer and IBM’s X-Force IRIS team We have found a new and undetected ransomware threat that is being used for targeted attacks against production servers of enterprises. Using code reuse analysis, we discovered this threat is closely related to the “more_eggs” backdoor malware, which is sold on the dark web by a veteran MaaS provider and has been used by the Cobalt Gang, FIN6, and other threat groups.

Read more →

November 12, 2019

Mapping the Connections Inside Russia’s APT Ecosystem

This research is a joint effort conducted by Omri Ben-Bassat from Intezer and Itay Cohen from Check Point Research. Prologue пролог If the names Turla, Sofacy, and APT29 strike fear into your heart, you are not alone. These are known to be some of the most advanced, sophisticated and notorious APT groups out there, and not in vain. These Russian-attributed actors are part of a larger picture in which Russia is one of the strongest powers in cyber warfare today. Their advanced tools, unique approaches, and solid infrastructures suggest enormous and complicated operations that involve different military and government entities inside Russia.

Read more →

September 24, 2019

Russian Cybercrime Group FullofDeep Behind QNAPCrypt Ransomware Campaigns

We identified a new QNAPCrypt ransomware sample operated by the same threat actors behind the 15 campaigns we shut down in July. It shares the function naming convention, the AES CFB encryption, and the geolocation filtering that skips Belarus, Russia and Ukraine. The ransom note drops the bitcoin wallet in favour of a protonmail address, which together with the strings identifies the operators as FullofDeep, a Russian cybercrime group focused on ransomware.

Read more →

September 20, 2019

MoP – "Master of Puppets" – Advanced malware tracking framework revealed at BlackHat Arsenal 2019

At BlackHat Arsenal 2019 Intezer’s researcher, Omri Ben-Bassat, revealed open-source tool called MoP (“Master of Puppets”) which is a framework for reverse engineers who wish to create and operate trackers for new malware found in the wild for research purposes. To make it simple – MoP framework takes care of all the generic malware tracker stuff so the reverse engineer is left with pure reverse engineering work, You only need to implement a simple plugin on top of MoP which describes the malware’s network protocol.

Read more →

August 14, 2019

Watching the WatchBog: New BlueKeep Scanner and Linux Exploits

A new version of the WatchBog cryptomining botnet has compromised an estimated 4,500 Linux machines since early June. It adds exploits for Jira, Exim and Solr published only days earlier, and a BlueKeep RDP scanner that suggests the operators are building a list of vulnerable Windows hosts to attack later or sell on. The spreader is a Cython-compiled Python binary and was undetected by all vendors. A design flaw let us MITM its C2 traffic during analysis.

Read more →

July 24, 2019

EvilGnome: Rare Malware Spying on Linux Desktop Users

EvilGnome is a fully undetected Linux backdoor implant that targets desktop users rather than servers. It disguises itself as a Gnome shell extension, ships as a makeself self-extracting archive, and persists via crontab. Its five "Shooter" modules capture desktop screenshots, record microphone audio, steal documents, and fetch further modules from the C2 over RC5-encrypted traffic. Hosting and infrastructure evidence connects it to the Russian Gamaredon Group.

Read more →

July 17, 2019