{"id":35899,"date":"2019-07-23T08:10:06","date_gmt":"2019-07-23T00:10:06","guid":{"rendered":"http:\/\/www.upgrademag.com\/web\/?p=35899"},"modified":"2019-07-23T08:10:08","modified_gmt":"2019-07-23T00:10:08","slug":"hacking-group-hides-malware-in-anti-internet-censorship-software","status":"publish","type":"post","link":"http:\/\/www.upgrademag.com\/web\/2019\/07\/23\/hacking-group-hides-malware-in-anti-internet-censorship-software\/","title":{"rendered":"Hacking group hides malware in anti-internet censorship software"},"content":{"rendered":"<p>Kaspersky researchers have discovered that the Russian-speaking threat actor Turla has revamped its toolset &#8212; wrapping its famous JavaScript KopiLuwak malware in a new dropper called Topinambour, creating two similar versions in other languages, and distributing its malware through infected installation packs for software that circumvents internet censorship, among others. Researchers believe these measures are designed to minimize detection and precision target victims. Topinambour was spotted in an operation against government entities at the start of 2019.<\/p>\n<p>Kaspersky defines a dropper as a program that secretly installs malicious programs, built into their code, on a computer. Typically, a program dropped onto the victim\u2019s computer is saved and launched without any notification (or a fake notification may be displayed). A dropper is used to secretly install other malware or to help known malicious programs to evade detection (not all anti-malware programs are capable of scanning all components inside a dropper).<\/p>\n<p>Turla is a high profile Russian-speaking threat actor with a known interest in cyberespionage against government and diplomatic related targets. It has a reputation for being innovative and for its signature KopiLuwak malware, first observed in late <a href=\"https:\/\/securelist.com\/kopiluwak-a-new-javascript-payload-from-turla\/77429\/\">2016<\/a>. In 2019, Kaspersky researchers uncovered new tools and techniques introduced by the threat actor that increase stealth and help to minimize detection.<\/p>\n<p>Topinambour (named after the vegetable that is also known as a Jerusalem artichoke) is a new .NET file that is being used by Turla to distribute and drop its JavaScript KopiLuwak through infected installation packages for legitimate software programs like VPNs for circumventing internet censorship.<\/p>\n<p>KopiLuwak is designed for cyberespionage and Turla\u2019s latest infection process includes techniques that help the malware to avoid detection.\u00a0 For example, the command and control infrastructure has IPs that appear to mimic ordinary LAN addresses. Further, the malware is almost completely \u2018fileless\u2019 \u2013 the final stage of infection, an encrypted Trojan for remote administration, is embedded into the computer\u2019s registry for the malware to access when ready.<\/p>\n<p>The two KopiLuwak analogues: the .NET RocketMan Trojan and the PowerShell MiamiBeach Trojan are also designed for cyberespionage.\u00a0 Researchers believe that these versions are deployed against targets with security software installed that is able to detect KopiLuwak. Upon successful installation, all three versions can:<\/p>\n<ul>\n<li>Fingerprint targets, to understand what kind of computer has been infected<\/li>\n<li>Gather information on system and network adapters<\/li>\n<li>Steal files<\/li>\n<li>Download and execute additional malware<\/li>\n<li>MiamiBeach is also able to take screenshots<\/li>\n<\/ul>\n<p>\u201cIn 2019, Turla emerged with a revamped toolset, introducing a number of new features possibly to minimize detection by security solutions and researchers. These include reducing the malware\u2019s digital footprint, and the creation of two different but similar versions of the well-known KopiLuwak malware. The abuse of installation packs for VPN software that can circumvent internet censorship suggests the attackers have clearly defined cyberespionage targets for these tools, \u201d said\u00a0 Kurt Baumgartner, principal security researcher at Kaspersky.<\/p>\n<p>\u201cThe continued evolution of Turla\u2019s arsenal is a good reminder of the need for threat intelligence and security software that can protect against the latest tools and techniques used by APTs.\u00a0 For example, endpoint protection and checking file hashes after downloading installation software would help to protect against threats like Topinambour,\u201d \u00a0Baumgartner added.<\/p>\n<p><b>To reduce the risk of falling victim to sophisticated cyberespionage operations, Kaspersky recommends taking the following measures:<\/b><\/p>\n<ul>\n<li>Implement <a href=\"https:\/\/www.kaspersky.com\/enterprise-security\/security-awareness\">security awareness training<\/a> for staff explaining how to recognize and avoid potentially malicious applications or files. For example, employees should not download and launch any apps or programs from untrusted or unknown sources.<\/li>\n<li>For endpoint level detection, investigation and timely remediation of incidents, implement EDR solutions such as <a href=\"https:\/\/www.kaspersky.com\/enterprise-security\/endpoint-detection-response-edr\">Kaspersky Endpoint Detection and Response<\/a>.<\/li>\n<li>In addition to adopting essential endpoint protection, implement a corporate-grade security solution that detects advanced threats on the network level at an early stage, such as <a href=\"https:\/\/www.kaspersky.com\/enterprise-security\/anti-targeted-attack-platform\">Kaspersky Anti Targeted Attack Platform<\/a>.<\/li>\n<\/ul>\n<ul>\n<li>Provide your SOC team with access to the latest <a href=\"https:\/\/www.kaspersky.com\/enterprise-security\/threat-intelligence\">Threat Intelligence<\/a>, to keep up to date with the new and emerging tools, techniques and tactics used by threat actors.<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Kaspersky researchers have discovered that the Russian-speaking threat actor Turla has revamped its toolset &#8212; wrapping its famous JavaScript KopiLuwak malware in a new dropper called Topinambour, creating two similar versions in other languages, and distributing its malware through infected installation packs for software that circumvents internet censorship, among others. Researchers believe these measures are [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":30091,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[19],"tags":[495,3800,117,103],"class_list":["post-35899","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-headlines","tag-cybersecurity-and-cybercrime","tag-hacking","tag-kaspersky-lab","tag-malware"],"_links":{"self":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/35899","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/comments?post=35899"}],"version-history":[{"count":0,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/35899\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media\/30091"}],"wp:attachment":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media?parent=35899"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/categories?post=35899"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/tags?post=35899"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}