{"id":56281,"date":"2023-05-30T10:43:01","date_gmt":"2023-05-30T02:43:01","guid":{"rendered":"http:\/\/www.upgrademag.com\/web\/?p=56281"},"modified":"2023-05-30T10:43:03","modified_gmt":"2023-05-30T02:43:03","slug":"goldenjackal-apt-spying-on-diplomatic-entities-in-middle-east-and-south-asia","status":"publish","type":"post","link":"http:\/\/www.upgrademag.com\/web\/2023\/05\/30\/goldenjackal-apt-spying-on-diplomatic-entities-in-middle-east-and-south-asia\/","title":{"rendered":"GoldenJackal APT spying on diplomatic entities in Middle East and South Asia"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><strong>Kaspersky discovered a new APT group. Dubbed GoldenJackal, it has been active since 2019, but has no public profile and has remained largely unknown. As the investigation shows, the group usually targets government and diplomatic entities in the Middle East and South Asia.\u00a0<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Kaspersky began monitoring the group in mid-2020 and observed a consistent of activities, which portray a capable and moderately stealthy actor. The main feature of this group is a specific toolset intended to control the machines of their victims, spread across systems using removable drives, and smuggle certain files from them, suggesting that the actor\u2019s primary motivation is espionage.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">As Kaspersky\u2019s investigation shows, the actor used fake Skype installers and malicious Word documents as initial vectors for their attacks. The fake Skype installer was an executable file that was approximately 400 MB in size. It was a dropper containing two resources: the JackalControl Trojan and a legitimate Skype for business standalone installer. The first usage of this tool was tracked back to 2020. Another infection vector was a malicious document that uses the remote template injection technique to download a malicious HTML page, which exploits the Follina vulnerability.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The document was named \u201cGallery of Officers Who Have Received National and Foreign Awards.docx\u201d and appears as a legitimate circular requesting the information about officers decorated by Pakistan\u2019s government. The first description of the Follina vulnerability was published on May 29, 2022 and this document appears to have been modified on June 1, two days after publication, and was first detected on June 2.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The document was configured to load an external object from a legitimate and compromised website. Once the external object is downloaded, the executable file is launched, which contains a JackalControl Trojan malware.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">JackalControl is the main trojan and it allows the attackers to control the target machine remotely through a set of predefined and supported commands. Over the years the attackers have distributed different variants of this malware: some include code to maintain persistence, others were configured to run without infecting the system. The machine usually gets infected by other components, such as a batch script.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The second important tool usually deployed by the GoldenJackal group is a JackalSteal. This tool can be used to monitor removable USB drives, remote shares, and all logical drives in the targeted system. The malware can work as a standard process or as a service. It cannot maintain persistence, so it must be installed by another component.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Finally, GoldenJackal uses a number of additional tools, such as JackalWorm, JackalPerInfo and JackalScreenWatcher. They are deployed in specific cases that were witnessed by Kaspersky researchers. This toolset is aimed at controlling victim\u2019s machines, stealing their credentials, taking screen captures of the desktop and so on \u2013 with espionage as an ultimate objective.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cGoldenJackal is an interesting APT actor that tries to keep a low profile \u2013 despite first kicking off its operation back in June 2019, it managed to stay under the radar. Possessing an advanced malware toolset, it has been quite prolific in its attacks on government and diplomatic entities in the Middle East and Southern Asia. Since some of the malware implants are still in the developing stages, it is crucial for cybersecurity teams to watch out for any possible attacks that might be performed by the actor. We hope that our analysis will help prevent GoldenJackal\u2019s activity,\u201d comments Giampaolo Dedola, senior security researcher at Kaspersky\u2019s Global Research and Analysis Team (GReAT).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In order to avoid falling victim to a targeted attack by a known or unknown threat actor, Kaspersky researchers recommend implementing the following measures:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Provide your SOC team with access to the latest threat intelligence (TI). <a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/www.kaspersky.com\/enterprise-security\/threat-intelligence\">The Kaspersky Threat Intelligence Portal<\/a> is a single point of access for the company\u2019s TI, providing cyberattack data and insights gathered by Kaspersky spanning over 20 years.&nbsp;<\/li>\n\n\n\n<li>Upskill your cybersecurity team to tackle the latest targeted threats with&nbsp;<a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/xtraining.kaspersky.com\/?utm_source=pr-media&amp;utm_medium=partner&amp;utm_campaign=gl_xtr-gen-pr_je0066&amp;utm_content=sm-post&amp;utm_term=gl_pr-media_organic_66jpzgkgnjbgdrn&amp;redef=1&amp;THRU&amp;reseller=gl_xtr-gen-pr_acq_ona_smm__onl_b2b_pr-media_post_______\">Kaspersky online training<\/a>&nbsp;developed by GReAT experts<\/li>\n\n\n\n<li>For endpoint level detection, investigation, and the timely remediation of incidents, implement EDR solutions such as&nbsp;<a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/www.kaspersky.com\/enterprise-security\/endpoint-detection-response-edr\">Kaspersky Endpoint Detection and Response<\/a><\/li>\n\n\n\n<li>In addition to adopting essential endpoint protection, implement a corporate-grade security solution that detects advanced threats on the network level at an early stage, such as&nbsp;<a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/www.kaspersky.com\/enterprise-security\/anti-targeted-attack-platform\">Kaspersky Anti Targeted Attack Platform<\/a><\/li>\n\n\n\n<li>As many targeted attacks start with phishing or other social engineering techniques, introduce security awareness training and teach practical skills to your team \u2013 for example, through the&nbsp;<a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/www.kaspersky.com\/small-to-medium-business-security\/security-awareness-platform\">Kaspersky Automated Security Awareness Platform<\/a><\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Kaspersky began monitoring the group in mid-2020 and observed a consistent of activities, which portray a capable and moderately stealthy actor. The main feature of this group is a specific toolset intended to control the machines of their victims, spread across systems using removable drives, and smuggle certain files from them, suggesting that the actor\u2019s primary motivation is espionage.<\/p>\n","protected":false},"author":6,"featured_media":56297,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[19],"tags":[286,101,54,2103],"class_list":["post-56281","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-headlines","tag-it-security","tag-kaspersky","tag-security","tag-security-breach"],"_links":{"self":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/56281","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/comments?post=56281"}],"version-history":[{"count":0,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/56281\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media\/56297"}],"wp:attachment":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media?parent=56281"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/categories?post=56281"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/tags?post=56281"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}