Skip to main content

Turla Campaigns Leverage New Backdoors

Turla, a advanced persistent threat (APT) group also known as Waterbug, has recently carried out three campaigns using custom malware, modified versions of publicly available hacking and legitimate administration tools.

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Turla, a advanced persistent threat (APT) group also known as Waterbug, has recently carried out three campaigns using custom malware, modified versions of publicly available hacking and legitimate administration tools.


Affected platforms

The following platforms are known to be affected:

Threat details

The first campaign involved a newly observed backdoor named Neptun installed on Microsoft Exchange servers. Neptun is designed to passively listen for commands from the attacker, making the malware more difficult to detect. Once installed, Neptun is able to download additional tools, upload stolen files, and execute shell commands.

The second campaign used a backdoor named PhotoBased.dll. This backdoor stores its command and control configuration in the registry for Windows Media Player and modifies the Microsoft Sysinternals registry to prevent pop-ups when running the PsExec tool. Once the backdoor is installed an attacker can use it to upload and download files, execute shell commands, and update its configuration. The attacker also installed another backdoor that runs a command shell via the named pipe cmd_pipe. Both backdoors allow the attacker to execute commands to gain full control of the users system.

In the third campaign, Turla used a backdoor, named securlsa.chk. This backdoor receives commands through the remote procedure call (RPC) protocol. Using the backdoor the attacker can execute commands using cmd.exe and read or write arbitrary files. This RPC backdoor also included source code derived from the tool PowerShellRunner, which allows a user to run PowerShell scripts without executing powershell.exe. This allows the attacker to potentially bypass detection aimed at identifying malicious PowerShell usage.


Remediation steps

Type Step

To prevent and detect an infection, ensure that:

  • A robust program of education and awareness training is delivered to users to ensure they don’t open attachments or follow links within unsolicited emails.
  • All operating systems, anti-virus and other security products are kept up-to-date.
  • Regular anti-virus and security scans are performed on your organisation’s estate.
  • All day-to-day computer activities such as email and internet are performed using non-administrative accounts.
  • Strong password policies are in place.
  • Network, proxy and firewall logs should be monitored for suspicious activity.
  • User accounts accessed from affected devices should be reset on a clean computer.
  • Your organisation adopts a holistic all-round approach to Cyber Security as advocated by the 10 Steps to Cyber Security.

Last edited: 14 February 2020 2:44 pm