Il formato per i documenti di testo si conferma come uno dei vettori di attacco preferiti dai pirati informatici. Come funziona la tecnica di attacco.
Non si tratta di una novità assoluta, ma l’RTF Template Injection rappresenta una strategia che i gruppi di hacker di stato legati a Russia, Cina e India stanno utilizzando con un certo successo per aggirare i sistemi di protezione delle loro vittime.
Come spiegano in un report pubblicato su Internet i ricercatori di Proofpoint, lo stratagemma utilizzato dai pirati è quello di usare le funzionalità dei modelli RTF per elaborare il contenuto del file e “trasformarlo” in una URL che avvia il download di un malware.
Non è la prima volta che i file in formato RTF finiscono sotto i riflettori a causa della “malleabilità” dei contenuti e della possibilità che i pirati informatici li utilizzino come vettore di attacco. Secondo gli autori del report, però, questa tecnica sarebbe più semplice da sfruttare rispetto ad altre garantendo, allo stesso tempo, una maggiore efficacia.
In particolare, l’uso di file RTF avrebbe preso piede a partire dalla primavera 2021, quando alcuni gruppi APT (Advanced Persistent Threat) come il team DoNot, che sarebbe stato il primo a utilizzarlo.
In seguito (l’ultimo caso è datato ottobre 2021) lo stratagemma sarebbe stato utilizzato dal gruppo Gamaredon, legato ai servizi segreti di Mosca.
Il caso che gli analisti hanno approfondito maggiormente, però, è quello degli attacchi condotti ai danni di organizzazioni malesi da parte di TA423, che ha consentito di mettere in evidenza anche le tecniche di ingegneria sociale sfruttate di pirati per aggirare i controlli di Word nei confronti dei documenti che contengono componenti attivi come quelli usati nella RTF Template Injection.
Nel dettaglio, il documento è stato “arricchito” da un messaggio apparentemente visualizzato dal software di videoscrittura (ma in realtà integrato nel documento) che invita a consentire l’esecuzione delle macro per superare un problema di compatibilità. Qualcosa di sicuramente già visto, che però mantiene un’indubbia efficacia.
Una ricerca di Trend Micro analizza l’ecosistema per la compravendita di accessi a network e dispositivi gestito dal cyber crimine.
Il livello di professionalizzazione nel cyber crimine continua a crescere e uno degli indizi più evidenti di questa continua evoluzione viene messo in evidenza da Trend Micro, che in una ricerca pubblicata su Internet analizza il mercato del cosiddetto Access as a Service, cioè la compravendita degli accessi a network aziendali.
Il nuovo modello di business, in crescita su forum e siti Internet frequentati dai cyber criminali, ricorda quello di semplici market: al loro interno, gli “access broker” offrono la possibilità di acquistare le credenziali o l’acceso diretto a una specifica rete.
Dallo studio, emerge come la classica ricostruzione di una violazione informatica, che normalmente viene riassunta con lo schema attacco-intrusione, è in realtà più complessa.
Si tratta di una classica filiera, composta dai pirati informatici che ottengono l’accesso al dispositivo compromesso, gli access broker che agiscono come intermediari e i “clienti finali”, che possono sfruttare l’accesso per colpire le organizzazioni compromesse, di solito con attacchi ransomware.
Da un punto di vista pratico, spiegano gli autori, ciò che viene fornito può essere il semplice accesso a una web shell, che permette di eseguire comandi in una rete compromessa. Più spesso, però, vengono forniti un set di credenziali e un server VPN per la connessione.
I prezzi possono variare notevolmente, per esempio in base al tipo di accesso (a una singola macchina o a un’intera rete) o al fatturato annuo dell’azienda compromessa. Un accesso RDP può valere un minimo di 10 dollari, ma il prezzo medio per le credenziali di amministratore in un’azienda è di circa 8.500. Tuttavia, i prezzi possono arrivare anche fino a 100.000 dollari.
Nello studio, gli analisti di Trend Micro hanno messo sotto la lente di ingrandimento più di 900 fonti, registrando il fatto che la maggior parte degli accessi messi in vendita sono relativi a organizzazioni europee (43%) e nordamericane (24%).
Il settore più colpito è quello didattico, in particolar modo nel Regno Unito. Il 71% degli accessi in vendita, infatti, rientra in questa categoria. A livello globale, invece, il dato è molto più basso: appena il 36%.
Google Play apps downloaded 300,000 times stole bank credentials
Researchers said they’ve discovered a batch of apps downloaded from Google Play more than 300,000 times before the apps were revealed to be banking trojans that surreptitiously siphoned user passwords and two-factor authentication codes, logged keystrokes, and took screenshots.
The apps—posing as QR scanners, PDF scanners, and cryptocurrency wallets—belonged to four separate Android malware families that were distributed over four months. They used several tricks to sidestep restrictions that Google has devised in an attempt to rein in the unending distribution of fraudulent apps in its official marketplace. Those limitations include restricting the use of accessibility services for sight-impaired users to prevent the automatic installation of apps without user consent.
Small footprint
“What makes these Google Play distribution campaigns very difficult to detect from an automation (sandbox) and machine learning perspective is that dropper apps all have a very small malicious footprint,” researchers from mobile security company ThreatFabric wrote in a post. “This small footprint is a (direct) consequence of the permission restrictions enforced by Google Play.”
Instead, the campaigns typically delivered a benign app at first. After the app was installed, users received messages instructing them to download updates that installed additional features. The apps often required updates to be downloaded from third-party sources, but by then, many users had come to trust them. Most of the apps initially had zero detections by malware checkers available on VirusTotal.
ThreatFabric
The apps also flew under the radar by using other mechanisms. In many cases, the malware operators manually installed malicious updates only after checking the geographic location of the infected phone or by updating phones incrementally.
“This incredible attention dedicated to evading unwanted attention renders automated malware detection less reliable,” the ThreatFabric post explained. “This consideration is confirmed by the very low overall VirusTotal score of the 9 number of droppers we have investigated in this blogpost.”
The malware family responsible for the largest number of infections is known as Anatsa. This “rather advanced Android banking trojan” offers a variety of capabilities, including remote access and automatic transfer systems, which automatically empty victims’ accounts and send the contents to accounts belonging to the malware operators.
The researchers wrote:
The process of infection with Anatsa looks like this: upon the start of installation from Google Play, the user is forced to update the app in order to continue using the app. In this moment, [the] Anatsa payload is downloaded from the C2 server(s) and installed on the device of the unsuspecting victim.
Actors behind it took care of making their apps look legitimate and useful. There are large numbers of positive reviews for the apps. The number of installations and presence of reviews may convince Android users to install the app. Moreover, these apps indeed possess the claimed functionality; after installation, they do operate normally and further convince [the] victim [of] their legitimacy.
Despite the overwhelming number of installations, not every device that has these droppers installed will receive Anatsa, as the actors made efforts to target only regions of their interest.
ThreatFabric
Three other malware families found by the researchers included Alien, Hydra, and Ermac. One of the droppers used to download and install malicious payloads was known as Gymdrop. It used filter rules based on the model of the infected device to prevent the targeting of researcher devices.
New workout exercises
“If all conditions are met, the payload will be downloaded and installed,” the post stated. “This dropper also does not request Accessibility Service privileges; it just requests permission to install packages, spiced with the promise to install new workout exercises—to entice the user to grant this permission. When installed, the payload is launched. Our threat intelligence shows that at the moment, this dropper is used to distribute [the] Alien banking trojan.”
The researchers listed 12 Android apps that participated in the fraud. The apps are:
Asked for comment, a Google spokesman pointed to this post from April detailing the company’s methods for detecting malicious apps submitted to Play.
Over the past decade, malicious apps have plagued Google Play on a regular basis. As was the case this time, Google is quick to remove the fraudulent apps once it has been notified of them, but the company has been chronically unable to find thousands of apps that have infiltrated the bazaar and infected thousands or even millions of users.
It’s not always easy to spot these scams. Reading user comments can help, but not always, since crooks often seed their submissions with fake reviews. Steering clear of obscure apps with small user bases can also help, but that tactic would have been ineffective in this case. Users should also think carefully before downloading apps or app updates from third-party markets.
The best advice for staying safe from malicious Android apps is to be extremely sparing in installing them. And if you haven’t used an app for a while, uninstalling it is a good idea.
https://arstechnica.com/?p=1816768
Ecco Chinotto, il nuovo spyware degli hacker nordcoreani APT37
Modulare, personalizzabile e multipiattaforma: viene utilizzato per spiare attivisti politici e giornalisti in operazioni di lungo termine.
Difficile capire quale sia l’origine del nome, ma al di là del sorriso che può strappare ai lettori italiani, con Chinotto c’è poco da scherzare.
Come spiegano i ricercatori di Kaspersky in un corposo report pubblicato su Internet, il trojan è utilizzato dal gruppo APT37 (ScarCruft) legato al governo della Corea del Nord.
Si tratterebbe di un “impianto”, come vengono definiti in gergo, in grado di infettare qualsiasi tipo di dispositivo e con un elevato livello di personalizzazione che consentirebbe ai pirati informatici di rendere più difficile la sua individuazione.
Lo schema di infezione descritto dagli analisti di Kaspersky ricalca quelli conosciuti nell’ambiente degli spyware di stato: il vettore iniziale, infatti, è normalmente un messaggio di spear phishing veicolato tramite email o i social network.
La catena di attacco, però, è decisamente complessa. Il primo livello di compromissione è infatti rappresentato da una semplice PowerShell che viene installata utilizzando un documento di Word contenente una macro che, come prima azione, modifica le impostazioni del registro di sistema di Windows per fare in modo che Word accetti qualsiasi comando senza visualizzare alcun avviso all’utente.
Il messaggio non viene mandato “a freddo”, ma sarebbe preceduto da messaggi e conversazioni tramite i social network, nel corso dei quali i pirati utilizzerebbero account compromessi che la vittima considera affidabili. Il documento è contenuto in un archivio in formato RAR protetto da password.
La seconda fase dell’infezione, di cui però i ricercatori non sono ancora riusciti a ottenere tutti i dettagli, prevede l’installazione di un payload scaricato da Internet che porta, probabilmente, alla creazione della backdoor individuata dagli analisti.
Nella ricostruzione dell’attacco, che nello specifico sarebbe iniziato a marzo, gli autori del report elencano una serie di indizi che indurrebbero a pensare che gli operatori di APT37 abbiano cercato di installare (senza successo) diversi malware fino al mese di agosto, quando hanno infine utilizzato Chinotto.
Si tratta di un eseguibile per Windows, il cui codice è pesantemente offuscato attraverso l’inserimento di dati “spazzatura” e le cui caratteristiche consentono ai pirati di esfiltrare informazioni, catturare screenshot della macchina infetta e aggiungere nuove funzionalità al malware.
Esiste però anche una versione Android di Chinotto, che viene distribuita attraverso smishing (phishing via SMS) e che permetterebbe sia l’esfiltrazione di file e informazioni dal dispositivo, sia la registrazione delle telefonate della vittima.
Lo schema complessivo, secondo i ricercatori di Kaspersky, prevederebbe l’uso delle informazioni sottratte per contattare altri bersagli e sfruttare gli account compromessi come “testa di ponte” per portare altri attacchi di spear phishing.
Insomma: Chinotto verrebbe utilizzato in un’ampia campagna di spionaggio che i servizi segreti nordcoreani starebbero portando avanti con tempi estremamente lunghi, in cui l’impianto finale verrebbe installato anche a mesi di distanza dalla prima infezione.
Il RAT è pensato per rubare le credenziali delle carte di credito sui siti Web di e-commerce attraverso uno skimmer installato sulle pagine.
Commercio elettronico nel mirino dei pirati informatici e, questa volta, il bersaglio è rappresentato dai sistemi Linux. °Il codice di CronRAT, infatti, sfrutta una vulnerabilità del sistema di pianificazione del sistema operativo Open Source, chiamato appunto cron.
Nel dettaglio, i cyber criminali utilizzano delle impostazioni che fanno riferimento a date inesistenti (come il 31 di febbraio) per installare un programma Bash in grado di comunicare con un server esterno passando completamente inosservato.
Come si legge nel report pubblicato su Internet dai ricercatori di Sansec, il malware viene memorizzato come una task di cron con un valore invalido (52 23 31 2 3) che permette però al codice di acquisire persistenza sull macchina compromessa.
Il suo obiettivo è quello di aprire un canale di comunicazione con un server esterno su protocollo TCP attraverso la porta 443, impostando come prima cosa una password per le comunicazioni e un comando che ne avvia l’autodistruzione.
La tecnica utilizzata, definita “esotica” dai ricercatori, si fonda sulla possibilità di inviare dati sfruttando un semplice file.
Secondo quanto riferiscono gli autori del report, CronRAT è stato identificato su un elevato numero di siti Internet dedicati al commercio elettronico.
La scelta temporale non sarebbe casuale: con il Black Friday, infatti, il traffico per lo shopping online è destinato a crescere esponenzialmente e la strategia dei cyber criminali, orientata al furto di dati di carte di credito usate nei pagamenti per gli acquisti, punterebbe a massimizzare la quantità di dati rubati.
La tecnica sfrutta alcune vulnerabilità della piattaforma Microsoft per colpire i dipendenti attraverso un subdolo schema di ingegneria sociale.
L’efficacia di un attacco informatico non dipende solo dal tipo di exploit o di malware utilizzato. In buona parte, il successo è legato alla capacità dei cyber criminali di indurre le loro vittime a fare quel “fatidico click” che porta all’infezione del loro dispositivo.
Nel caso del gruppo TR, documentato in un report pubblicato su Internet dai ricercatori di Trend Micro, questo obiettivo viene raggiunto attraverso un creativo uso di due exploit per Microsoft Exchange Server.
I cyber criminali di TR sono specializzati nella diffusione via email di numerosi malware e, in questi ultimi mesi, stanno utilizzando intensivamente Squirrelwaffle.
Si tratta di un loader, cioè di un impianto che viene utilizzato dai pirati per “mettere un piede” nella rete che vogliono colpire e distribuire ulteriori malware.
I vettori di attacco utilizzato dai pirati, come spiegato in una ricerca di Cisco Talos, sono solitamente documenti allegati a messaggi email o link malevoli incorporati nel messaggio di posta stesso.
La novità evidenziata da Trend Micro, però, è il fatto che i pirati informatici stiano utilizzando le vulnerabilità di Exchange Server (ProxyLogon e ProxyShell) per veicolare le email in modo da ottenere un vantaggio strategico nell’attacco.
La tattica utilizzata, in pratica, prevede l’uso di Exchange per inviare i messaggi malevoli dall’interno della rete, facendo in modo che appaiano come risposte a un messaggio inviato precedentemente dalla vittima.
Inserendosi in un thread esistente, i cyber criminali sperano di indurre i destinatari dei messaggi ad abbassare le difese e a superare la normale diffidenza che orami qualsiasi persona ha nei confronti di allegati e link che provengono da sconosciuti.
Un trucchetto che ha ottime probabilità di funzionare e che rende ancora più urgente la necessità di correggere le vulnerabilità (CVE-2021-26855, CVE-2021-34473 e CVE-2021-34523) che ne consentono l’utilizzo.
New ‘SharkBot’ Android Banking Malware Hitting U.S., UK and Italy Targets
A new Android banking trojan has been found, targeting international banks from the United Kingdom and Italy (including in the U.S.). and five different cryptocurrency services. Twenty-two instances have been discovered, but more are expected.
The malware, first detected at the end of October 2021, appears to be new and still being developed. It was discovered by Cleafy, a Milan, Italy-based online fraud detection and prevention firm. Cleafy calls it ‘SharkBot’, named after the frequency of the word ‘sharked’ in its binaries.
SharkBot is not found in Google’s official marketplace. This means it must be sideloaded by delivering the APK to the device and ensuring it is manually loaded. In a technical analysis of the malware, Cleafy notes that it poses as a legitimate application using common names and icons.
If the deception succeeds and the malware is installed, it immediately attempts to enable Android’s Accessibility Services by delivering fake pop-ups to the victim – such as ‘Allow Media Player to have full control of your device’. If this is successful, SharkBot has all the permissions it needs.
Once accepted the malware can enable keylogging (to steal typed credentials), intercept SMS messages (to circumvent MFA), deliver overlay attacks (to steal login credentials and credit card information) and remotely control the device because permissions were granted via the fake pop-up. “Basically,” comments Corey Nachreiner, CSO at WatchGuard Technologies, “the malicious Accessibility Services can read anything a user can read and can recreate any action a user can on the device.”
Notably, SharkBot also attempts a relatively novel technique known as an Automatic Transfer Systems (ATS) attack. “This technique has been seen recently from other banking trojans, such as Gustuff,” explains Cleafy. “ATS is an advanced attack technique (fairly new on Android) which enables attackers to auto-fill fields in legitimate mobile banking apps and initiate money transfers from the compromised devices.”
The ATS functionality is contained in a module downloaded separately from the C2. “Given its modular architecture,” comments Cleafy, “we don’t exclude the existence of botnets with other configurations and targets.”
The assumption is that ATS is used by SharkBot to bypass the behavioral detection measures used by many financial institutions. If ATS is used on what is a trusted device, a ‘new device enrollment’ phase is not necessary, SMS-based MFA can be bypassed, and behavioral biometrics are not effective.
Although relatively few instances of SharkBot have been discovered in the wild, Cleafy suspects that the threat will grow. This is partly because it is new, and apparently still being developed.
“The implications of becoming infected with SharkBot could be severe, so it’s important,” says Nachreiner, “to avoid being infected altogether.” This is not yet easy. The malware is new and not well detected by existing detection means. Apart from the DGA for its C2s, it also uses anti-analysis techniques including obfuscated strings and emulator detection.
The best solution is to avoid side-loading religiously. Without 100% certainty in the authenticity of the application and the validity of its source, simply do not install it.
Kevin Townsend is a Senior Contributor at SecurityWeek. He has been writing about high tech issues since before the birth of Microsoft. For the last 15 years he has specialized in information security; and has had many thousands of articles published in dozens of different magazines – from The Times and the Financial Times to current and long-gone computer magazines.
Nuovo modus operandi dei gruppi APT legati all’Iran: l’estorsione punta a raccogliere fondi e danneggiare i bersagli colpiti dai pirati informatici.
È tempo di aggiornare la mappa delle minacce informatiche. Un invito valido anche per il settore APT (Advanced Persistent Threat) che, normalmente, siamo abituati ad associare a campagne di spionaggio.
Stando a quanto riporta Microsoft, infatti, anche i cosiddetti “hacker di stato” stanno cambiando strategie e strumenti di attacco. Una metamorfosi che starebbe interessando, in particolare, i gruppi legati al governo dell’Iran.
Stando a quanto si legge su un report pubblicato online dai ricercatori Microsoft, infatti, i gruppi APT che fanno riferimento a Teheran hanno cominciato a utilizzare lo schema ransomware per colpire i loro obiettivi.
Come si legge nel report pubblicato su Internet dai ricercatori, infatti, il gruppo Phosphorus (conosciuto anche come APT35) ha recentemente iniziato a utilizzare tecniche estorsive nei suoi attacchi.
Phosphorus, fino a qualche tempo fa, si dedicava esclusivamente ad attacchi che miravano al cyber spionaggio. A partire dalla seconda metà del 2021, però il gruppo ha cambiato strategia.
Secondo quanto riportano gli analisti, il gruppo ha cominciato a sfruttare una serie di vulnerabilità sui server Exchange con lo scopo di introdursi nelle reti delle organizzazioni prese di mira e individuare i dispositivi in cui erano conservati dati sensibili per avviarne la crittazione con dei ransomware.
Un comportamento decisamente “anomalo” rispetto ai precedenti. In Medioriente, infatti, gli esperti di cyber security hanno in passato registrato un estensivo uso di wiper (malware che cancellano direttamente i dati conservati sui sistemi piuttosto che crittografarli -ndr) come strumenti di attacco.
Perché passare dallo spionaggio e sabotaggio al ransomware? Un’ipotesi è che l’uso di schemi estorsivi offra il vantaggio (non disprezzabile per i pirati) di incassare qualche dollaro per la loro attività.
L’uso di un ransomware, però, può anche essere considerata una sorta di “false flag”. Utilizzare uno strumento normalmente usato da “normali” cyber criminali può infatti contribuire a depistare gli esperti e rendere più difficile l’attribuzione degli attacchi.
Da quando il furto di dati è diventato prassi comune anche negli attacchi ransomware, infatti, la codifica dei dati e la richiesta di un riscatto possono essere una perfetta copertura per le azioni di intelligence portate avanti attraverso i cyber attacchi.
Malware downloaded from PyPI 41,000 times was surprisingly stealthy
PyPI—the open source repository that both large and small organizations use to download code libraries—was hosting 11 malicious packages that were downloaded more than 41,000 times in one of the latest reported such incidents threatening the software supply chain.
JFrog, a security firm that monitors PyPI and other repositories for malware, said the packages are notable for the lengths its developers took to camouflage their malicious code from network detection. Those lengths include a novel mechanism that uses what’s known as a reverse shell to proxy communications with control servers through the Fastly content distribution network. Another technique is DNS tunneling, something that JFrog said it had never seen before in malicious software uploaded to PyPI.
A powerful vector
“Package managers are a growing and powerful vector for the unintentional installation of malicious code, and as we discovered with these 11 new PyPI packages, attackers are getting more sophisticated in their approach, Shachar Menashe, senior director of JFrog research, wrote in an email. “The advanced evasion techniques used in these malware packages, such as novel exfiltration or even DNS tunneling (the first we’ve seen in packages uploaded to PyPI) signal a disturbing trend that attackers are becoming stealthier in their attacks on open source software.”
The researchers said that PyPI quickly removed all malicious packages once JFrog reported them.
Use of open source repositories to push malware dates back to at least 2016, when a college student uploaded malicious packages to PyPI, RubyGems, and npm. He gave the packages names that were similar to widely used packages already submitted by other users.
Over a span of several months, his imposter code was executed more than 45,000 times on more than 17,000 separate domains, and more than half the time, his code was given all-powerful administrative rights. Two of the affected domains ended in .mil, an indication that people inside the US military may have run his script.
In July, JFrog found malicious PyPI packages, downloaded more than 30,000 times, that carried out a range of nefarious activities, including stealing credit card data and injecting malicious code on infected machines.
Earlier this year, a researcher developed a new type of supply chain attack that can have serious consequences. The so-called “dependency confusion attacks” work by uploading malicious packages to public code repositories and giving them names that are identical to legitimate packages stored in the internal repository of Microsoft, Apple, or another large software developer. Developers’ software-management apps often favor external code libraries over internal ones, so they download and use the malicious package rather than the trusted one.
From attacker to victim via Fastly
Now, these types of attacks are getting harder to detect. The biggest advance in subterfuge the researchers found was in two packages, one called “importantpackage” (or alternatively “important-package”) and the other called “10Cent10” (or “10Cent11”). The packages use the Fastly CDN to disguise communications between the infected machine and a control server.
The malicious code hiding in the packages causes an HTTPS request to be sent to pypi.python.org in a way that’s indistinguishable from a legitimate request to PyPI. The requests eventually are rerouted by Fastly as an HTTP request to the control server psec.forward.io.global.prod.fastly.net. The server then sends replies through the same setup, allowing for two-way communication. Fastly makes it easy for people to register their domains with the service. In many cases, registration can even be done anonymously.
JFrog researchers Andrey Polkovnychenko and Menashe explained:
The PyPI infrastructure is hosted on the Fastly CDN. This hosting uses the Varnish transparent HTTP proxy to cache the communication between clients and the backend. The traffic first goes into a TLS terminator for decryption, so the Varnish proxy can inspect the contents of the HTTP packet. The proxy analyzes the HTTP headers from the user’s request and redirects the request to the corresponding backend according to the Host header. The process then repeats itself in the reverse direction, allowing the malware to imitate duplex communication with PyPI.
As a result, the command-and-control (C2) session is encrypted and signed with a legitimate server certificate, making it indistinguishable from communicating with legitimate PyPI resources.
DNS tunneling, the other advanced evasion technique the researchers found, works using a DNS channel—normally reserved for mapping domain names to IP addresses—to send communications between an infected computer and a control server. DNS tunneling isn’t new, but the researchers said it’s the first time they have seen the technique used in malware uploaded to PyPI.
The growing sophistication of the malicious code being sneaked into PyPI, and presumably other repositories, is an indication that its use in spreading malware is likely to continue. Developers who rely on public repositories should take extra care to ensure there are no typos or stray letters in the package name they’re downloading.
https://arstechnica.com/?p=1814211
Supply Chain Security Fears Escalate as Iranian APTs Caught Hitting IT Services Sector
Fears of software supply chain attacks escalated again this week with a new warning from Microsoft that it has caught Iranian threat actors breaking into IT services shops in India and Israel and using that access to hit the real targets.
Two of Redmond’s premier threat hunting units — the Microsoft Threat Intelligence Center (MSTIC) and Microsoft Digital Security Unit (DSU) — are sounding the alarm for a series of intrusions at companies that sell business management and integration software to millions of global organizations.
Once inside the IT services organizations, Microsoft said the Iranian hackers are “extending their attacks to compromise downstream customers,” much like the SolarWinds supply chain mega-hack that snagged thousands of corporate victims globally.
Microsoft warned of a significant surge in these attacks — more than 1,600 notifications to over 40 IT companies in response to Iranian targeting, compared to 48 notifications in 2020 — and warned that downstream attacks are targeting organizations in the defense, energy, and legal sectors
“As India and other nations rise as major IT services hubs, more nation state actors follow the supply chain to target these providers’ public and private sector customers around the world matching nation state interests,” Microsoft said in a report calling attention to the surge in these Iran-linked attacks.
In July 2021 this year, Microsoft said it caught a threat actor based in Iran that compromised a single Israel-based IT company that provides business management software. Microsoft said the hacking group then used access to that IT company to extend their attacks and compromise downstream customers in the defense, energy, and legal sectors in Israel.
A few months later, Redmond’s threat hunting teams caught a separate Iranian group hacking into email accounts at a Bahrain-based IT integration company that works on IT integration with Bahrain government clients.
Microsoft surmises that the downstream Bahrain government clients “were likely the ultimate target” and warned that the group has also compromised various accounts at a partially government-owned organization in the Middle East that provide information and communications technology to the defense and transportation sectors.
The hacking group maintained persistence at the Bahrain IT integration organization from September through at least October.
Microsoft said credential theft from the original compromises of IT services companies are used in the downstream attacks. [The Iranian attackers] dumped credentials from the on-premises network of an IT provider based in Israel in early July. Over the next two months, the group compromised at least a dozen other organizations, several of which have strong public relations with the compromised IT company,” Microsoft explained.
The company said at least four of those victims were compromised using the acquired credentials and access from the IT company in the July and August attacks.
Redmond’s telemetry has picked up a major surge in these and other Iranian groups targeting IT companies based in India beginning in mid-August. From mid-August to late September, Microsoft said it issued 1,788 nation state notifications (NSNs) across Iranian actors to enterprise customers in India, roughly 80% of which were to IT companies.
Over the three previous years, Microsoft barely issued 10 such notifications in response to Iranian hacking activity and because there are no obvious geo-political reasons for the India targeting, the company believes the Indian IT shops are being used “for indirect access to subsidiaries and clients outside India.”
Ryan Naraine is Editor-at-Large at SecurityWeek and host of the popular Security Conversations podcast series. He is a journalist and cybersecurity strategist with more than 20 years experience covering IT security and technology trends.
Ryan has built security engagement programs at major global brands, including Intel Corp., Bishop Fox and Kaspersky GReAT. He is a co-founder of Threatpost and the global SAS conference series. Ryan’s career as a journalist includes bylines at major technology publications including Ziff Davis eWEEK, CBS Interactive’s ZDNet, PCMag and PC World.
Ryan is a director of the Security Tinkerers non-profit, and a regular speaker at security conferences around the world. Follow Ryan on Twitter @ryanaraine.