Wednesday, December 18, 2024
HomeCyber Security NewsRussian APT29 Used 30+ C&C Servers Uncovered Linked to "WellMess" Malware

Russian APT29 Used 30+ C&C Servers Uncovered Linked to “WellMess” Malware

Published on

SIEM as a Service

Researchers from RISKIQ uncovered more than 30 commands & control server infrastructure actively serving malware known as “WellMess/WellMail”.

These C2 servers belong to Russian APT29 group hackers, and the gang was identified nearly a year back by the UK, US, and Canadian governments issued a joint advisory.

APT29(YTTRIUM, THE DUKES, COZY BEAR) group explicitly believed to be associated with Russia’s Foreign Intelligence Services (SVR) and the malware previously used in espionage campaigns targeting COVID-19 research in the UK, US, and Canada.

- Advertisement - SIEM as a Service

Identified command & control servers are actively serving WellMess malware against highly targeted victims.

“The activity uncovered was notable given the context in which it appeared, coming on the heels of a public reproach of Russian hacking by President Joe Biden in a recent summit with President Vladimir Putin.” RISKIQ said.

‘WellMess’ is a custom malware used to target the number of victims globally, and the group is mainly using the recently published exploits to gain initial footholds.

A Tweets Leads to the Way

Researchers’ investigation begins with the Tweet that contains an indicator about the command and control server and the signed certificate.

Further analysis leads to uncovering several additional IP addresses and  Certificates, also revealed that the C2 server associated with the APT29 and WellMess.

The identified C2 infrastructure is actively used by APT 29, Also found new IP addresses residing in the same networks.

“Building on that discovery, RiskIQ’s Team Atlas was then able to leverage RiskIQ’s Internet Intelligence Graph to link the following SSL Certificates and IP addresses to APT29 C2 infrastructure with high confidence.”

When researchers examined the banners returned from HTTP requests made to the servers, they were able to found an entirely separate group of malicious certificates and IP addresses.

You can explore the full list of these IOCs Here.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity and hacking news updates.

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

New VIPKeyLogger Via Weaponized Office Documenrs Steals Login Credentials

The VIPKeyLogger infostealer, exhibiting similarities to the Snake Keylogger, is actively circulating through phishing...

INTERPOL Urges to End ‘Pig Butchering’ & Replaces With “Romance Baiting”

INTERPOL has called for the term "romance baiting" to replace "pig butchering," a phrase...

New I2PRAT Malware Using encrypted peer-to-peer communication to Evade Detections

Cybersecurity experts are sounding the alarm over a new strain of malware dubbed "I2PRAT,"...

Earth Koshchei Employs RDP Relay, Rogue RDP server in Server Attacks

 A new cyber campaign by the advanced persistent threat (APT) group Earth Koshchei has...

API Security Webinar

72 Hours to Audit-Ready API Security

APIs present a unique challenge in this landscape, as risk assessment and mitigation are often hindered by incomplete API inventories and insufficient documentation.

Join Vivek Gopalan, VP of Products at Indusface, in this insightful webinar as he unveils a practical framework for discovering, assessing, and addressing open API vulnerabilities within just 72 hours.

Discussion points

API Discovery: Techniques to identify and map your public APIs comprehensively.
Vulnerability Scanning: Best practices for API vulnerability analysis and penetration testing.
Clean Reporting: Steps to generate a clean, audit-ready vulnerability report within 72 hours.

More like this

New VIPKeyLogger Via Weaponized Office Documenrs Steals Login Credentials

The VIPKeyLogger infostealer, exhibiting similarities to the Snake Keylogger, is actively circulating through phishing...

INTERPOL Urges to End ‘Pig Butchering’ & Replaces With “Romance Baiting”

INTERPOL has called for the term "romance baiting" to replace "pig butchering," a phrase...

New I2PRAT Malware Using encrypted peer-to-peer communication to Evade Detections

Cybersecurity experts are sounding the alarm over a new strain of malware dubbed "I2PRAT,"...