Skip to main content

New JavaScript Malware Dubbed KopiLuwak

The cyber espionage group ‘Turla’ has been using a new piece of JavaScript malware to profile victims.
Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

The cyber espionage group ‘Turla’ has been using a new piece of JavaScript malware to profile victims.

Affected platforms

The following platforms are known to be affected:

Threat details

The malware KopiLuwak is distributed through malicious spam emails and has been targeting governments of EU countries, media companies and EU related institutions.

The macro used in this campaign has modifications compared to previous versions. There is an XOR encryption routine that is used to decode the initial JavaScript and uses a marker string to find the embedded payload in the document. The malware is able to maintain persistence across reboots by adding an entry into the registry. Multiple layers of JavaScript have been implemented within the code to specifically avoid detection.

The C2 servers that are used are legitimate websites that have been compromised and used for communications. Each of the infected hosts is assigned a custom User Agent (UA) String that is used to make POST requests to the C2 server. The UA String consists of the system name and the user name which are then passed through a routine that produces a unique ID consisting of 16 digits, with a string appended to the end.


Remediation steps

Type Step
  • Monitor network and proxy logs for indications of compromise.
  • Never open attachments or links from untrusted sources.
  • Make sure that malware definitions are kept up-to-date.

Last edited: 17 February 2020 11:36 am