{"id":36229,"date":"2019-08-26T11:14:08","date_gmt":"2019-08-26T03:14:08","guid":{"rendered":"http:\/\/www.upgrademag.com\/web\/?p=36229"},"modified":"2019-08-26T11:14:10","modified_gmt":"2019-08-26T03:14:10","slug":"cloud-atlas-apt-upgrades-its-arsenal-with-polymorphic-malware","status":"publish","type":"post","link":"http:\/\/www.upgrademag.com\/web\/2019\/08\/26\/cloud-atlas-apt-upgrades-its-arsenal-with-polymorphic-malware\/","title":{"rendered":"Cloud Atlas APT upgrades its arsenal with polymorphic malware"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><strong>Cloud Atlas, an advanced persistent threat (APT), also known as Inception, has updated its attack arsenal with new tools which allow it to avoid detection through standard Indicators of Compromise. This updated infection chain has been spotted in the wild in different organizations in Eastern Europe, Central Asia and Russia.<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Cloud Atlas is a threat actor that has a long history of cyber-espionage operations targeting industries, government agencies and other entities. It was first identified <a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/securelist.com\/cloud-atlas-redoctober-apt-is-back-in-style\/68083\/\">in 2014<\/a> and has been active ever since. Recently, Kaspersky researchers have seen Cloud Atlas targeting the international economics and aerospace industries as well as governmental and religious organizations in Portugal, Romania, Turkey, Ukraine, Russia, Turkmenistan, Afghanistan and Kyrgyzstan among other countries. Upon successful infiltration, Cloud Atlas would:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>collect information about the system to which it has gained access<\/li><li>log passwords<\/li><li>exfiltrate recent .txt .pdf. xls .doc files to a command and control server.<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">While Cloud Atlas hasn\u2019t dramatically changed its tactics, since 2018, recent waves of attacks research has discovered it has started to implement a novel way of infecting its victims and conducts lateral movement through their network.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img decoding=\"async\" src=\"https:\/\/ecp.yusercontent.com\/mail?url=https%3A%2F%2Flh3.googleusercontent.com%2FcSoLBYsWgT9y7-inCRP52kINWMkQpilHD8Qumcb26v3Uh00NDbZ7rzcwnbCQiyocyWeZY6S9UjN7w-ww2JnbftiCEl9oiePUMJHhCTZKd7T8ycXLd7Vc4rVsfcYU0-8KVsDhVPEB&amp;t=1566458244&amp;ymreqid=27f3344f-c727-c29c-1c0e-8c012001ed00&amp;sig=q.HrrYMeE2qOi2uE24tdQg--~C\" alt=\"https:\/\/lh3.googleusercontent.com\/r1xROVxQRGtTPVHPGCm503lKx7ZIBJCxA_57QJ-vcf7POK1SIVisEl-zcs_Jm5qlp5q1PbsBuTtRGSJh-7VntGxIUiYspkhFsEjenjVCktqp_2TC4XGPG6DIDtJaYlky8juGUqEp\"\/><\/figure><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Fig.1: The infection chain that was used by Cloud Atlas before April 2019.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Previously, Cloud Atlas would first send a spear-phishing email with a malicious attachment to a target. In the case of a successful exploitation, PowerShower \u2013 the attached malware, used for initial reconnaissance and to download additional malicious modules \u2013 would then be executed to allow cyberattackers to proceed with an operation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The newly updated chain of infection postpones the execution of PowerShower until a later stage; instead, after the initial infection, a malicious HTML app is now downloaded and executed on the target machine. This application will then collect initial information about the attacked computer, and download and execute VBShower \u2013 another malicious module. VBShower then erases evidence of the presence of malware in the system and consults with its masters through command and control servers, to decide on further actions. Depending on the command received, this malware will then download and execute either PowerShower or another well-known Cloud Atlas\u2019 second stage backdoor.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img decoding=\"async\" src=\"https:\/\/ecp.yusercontent.com\/mail?url=https%3A%2F%2Flh3.googleusercontent.com%2FKYQYBSmBK-TwkbWuO2yytmORHKVciikZhpC5E07I4fzYYvii_rUx8snQSl_sPlTOpXvYfGZePkgyPvIgQdMzQle46IDNzse0dT5u4fHUIzF70FrtLcoXWu-E2JceKxDtAATPxTa3&amp;t=1566458244&amp;ymreqid=27f3344f-c727-c29c-1c0e-8c012001ed00&amp;sig=z5sQSfl5goRlr6P2KYsYhg--~C\" alt=\"https:\/\/lh4.googleusercontent.com\/p8N7gv_3PJqNy19O6ylS6h1fvh-q3gGQ809ZR1dm_d3kcuYir49uyEbQjaXUY6LLZn-j_XwLmD6-dZj9TJpZtNY67FtKC9UdkzSPJuJcr5_EhUKTmt8ok2qZ01Jfp9TUd94nWY7Y\"\/><\/figure><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Fig 2. The updated Cloud Atlas infection chain<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">While this new infection chain is in general much more complicated than the previous model, its main differentiator is the fact that a malicious HTML application and the VBShower module are polymorphic. This means that the code in both modules will be new and unique in each case of infection. According to Kaspersky experts, this updated version is carried out in order to make the malware invisible to security solutions relying on familiar Indicators of Compromise.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cIt has become good practice in the security community to share the Indicators of Compromise (IoC) of malicious operations we find through research. This practice allows us to respond to ongoing international cyber-espionage operations quite swiftly, preventing any further damage they could cause. However, as we predicted <a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/securelist.com\/kaspersky-security-bulletin-predictions-for-2017\/76660\/\">as early as 2016<\/a>, IoC have become obsolete as a reliable tool to spot a targeted attack in your network, \u201c said Felix Aime, security researcher, Kaspersky Global Research and Analysis Team.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u00a0&#8220;This first emerged with ProjectSauron, which would create a unique set of IoC for each of its victims and continued with the trend of using open source tools in espionage operations instead of unique ones. This is now continuing with this recent example of polymorphic malware. This doesn\u2019t mean that actors are becoming harder to catch, but that security skills and the defenders toolkit needs to evolve along with the toolkit and skills of the malicious actors they are tracking,\u201d Aime added.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Kaspersky recommends that organizations use anti-targeted attack solutions enhanced with Indicators of Attack (IoA) that focus on the tactics, techniques or actions that malefactors may take when preparing for an attack. IoAs track the techniques deployed, no matter what specific tools are used. The latest versions of Kaspersky Endpoint Detection and Response, and Kaspersky Anti Targeted Attack both feature a new database of IoAs, maintained and updated by Kaspersky\u2019s own expert threat hunters.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Other recommendations for organizations from Kaspersky:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Educate your staff on digital hygiene and explain how they can recognize and avoid potentially malicious emails or links. Consider introducing dedicated <a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/www.kaspersky.com\/enterprise-security\/security-awareness\">awareness<\/a> training for employees<\/li><li>Use an endpoint security solution fitted with anti-spam and anti-phishing components, as well as application control functionality with a default deny mode to block the execution of unauthorized applications \u2014 such as <a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/www.kaspersky.com\/enterprise-security\/endpoint\">Kaspersky Endpoint Security for Business<\/a><\/li><li>For endpoint level detection, investigation and timely remediation of incidents, implement an EDR solution such as <a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/www.kaspersky.com\/enterprise-security\/endpoint-detection-response-edr\">Kaspersky Endpoint Detection and Response<\/a>, to catch even unknown banking malware<\/li><li>Implement a corporate-grade security solution that detects advanced threats on the network at an early stage, such as <a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/www.kaspersky.com\/enterprise-security\/anti-targeted-attack-platform\">Kaspersky Anti Targeted Attack Platform<\/a><\/li><li>Integrate <a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/www.kaspersky.com\/enterprise-security\/threat-intelligence\">threat intelligence<\/a> into your Security Information and Event Management (SIEM) services &nbsp;and security controls, in order to access the most relevant and up-to-date threat data.<\/li><\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Cloud Atlas is a threat actor that has a long history of cyber-espionage operations targeting industries, government agencies and other entities. It was first identified in 2014 and has been active ever since.<\/p>\n","protected":false},"author":6,"featured_media":35630,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[19],"tags":[6845,101,54],"class_list":["post-36229","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-headlines","tag-cloud-atlas","tag-kaspersky","tag-security"],"_links":{"self":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/36229","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/comments?post=36229"}],"version-history":[{"count":0,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/36229\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media\/35630"}],"wp:attachment":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media?parent=36229"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/categories?post=36229"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/tags?post=36229"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}