Turla Campaigns Leverage New Backdoors
Turla, a advanced persistent threat (APT) group also known as Waterbug, has recently carried out three campaigns using custom malware, modified versions of publicly available hacking and legitimate administration tools.
Summary
Turla, a advanced persistent threat (APT) group also known as Waterbug, has recently carried out three campaigns using custom malware, modified versions of publicly available hacking and legitimate administration tools.
Affected platforms
The following platforms are known to be affected:
Threat details
The first campaign involved a newly observed backdoor named Neptun installed on Microsoft Exchange servers. Neptun is designed to passively listen for commands from the attacker, making the malware more difficult to detect. Once installed, Neptun is able to download additional tools, upload stolen files, and execute shell commands.
The second campaign used a backdoor named PhotoBased.dll. This backdoor stores its command and control configuration in the registry for Windows Media Player and modifies the Microsoft Sysinternals registry to prevent pop-ups when running the PsExec tool. Once the backdoor is installed an attacker can use it to upload and download files, execute shell commands, and update its configuration. The attacker also installed another backdoor that runs a command shell via the named pipe cmd_pipe. Both backdoors allow the attacker to execute commands to gain full control of the users system.
In the third campaign, Turla used a backdoor, named securlsa.chk. This backdoor receives commands through the remote procedure call (RPC) protocol. Using the backdoor the attacker can execute commands using cmd.exe and read or write arbitrary files. This RPC backdoor also included source code derived from the tool PowerShellRunner, which allows a user to run PowerShell scripts without executing powershell.exe. This allows the attacker to potentially bypass detection aimed at identifying malicious PowerShell usage.
Remediation steps
| Type | Step |
|---|---|
|
To prevent and detect an infection, ensure that:
|
Last edited: 14 February 2020 2:44 pm