Tuesday, November 5, 2024
HomeComputer SecurityLYCEUM APT Hackers Attack Critical Infrastructures Over a Year using Several Hacking...

LYCEUM APT Hackers Attack Critical Infrastructures Over a Year using Several Hacking Tools

Published on

Malware protection

A new threat group dubbed LYCEUM spotted attacking critical infrastructure organizations including oil, gas and possibly telecommunications using several hacking tools.

The threat group found to be active at least from April 2018 and they target South African regions, starting from May 2019 the group launches campaigns against oil and gas organizations in the Middle East.

Earlier Dragos identified an activity group HEXANE targeting oil and gas companies in the Middle East, followed to that now Secureworks published a report on LYCEUM activities.

- Advertisement - SIEM as a Service

LYCEUM Threat Group Toolkit

LYCEUM uses simple attack techniques to attack Critical Infrastructure organizations. The attack starts with credentials obtained through password spraying or brute-force attacks.

Once they gain access to the accounts they use targeted spear-phishing emails to the targeted executives such as human resources (HR) staff and IT personnel.

The Emails originates from Internal Email address and they use “security best practice” themed documents to trick the users.

Phishing Decoys used

The Email contains malicious Excel attachment that delivers DanBot malware, which is focused on stealing various sensitive information from victims.

Tools used

Following are the tools used by LYCEUM threat group.

DanBot – First stage which provides remote access capability, a communication mechanism and ability to execute arbitrary commands.

DanDrop – Malicious macro used to drop DanBot payload

kl.ps1 – Customized keylogger to capture keystrokes.

Decrypt-RDCMan.ps1 – PoshC2 penetration testing framework used to decrypt stored passwords.

Get-LAPSP.ps1 – Powershell script that is capable of stealing information from Active Directory via LDAP.

“LYCEUM registered infrastructure using the PublicDomainRegistry.com, Web4Africa and Hosting Concepts B.V. registrars. New domains appear to be registered for individual campaigns,” according to a report published by SecureWorks.

The threat actor group actively targets energy organizations in the Middle East, in the future, they expand their attack sector.

“Aside from deploying novel malware, LYCEUM’s activity demonstrates capabilities CTU researchers have observed from other threat groups and reinforces the value of a few key controls. Password spraying, DNS tunneling, social engineering, and abuse of security testing frameworks are common tactics, particularly from threat groups operating in the Middle East.”

Indicators of compromise

Domains
bsolutions-cloude.com
cybersecnet.co.za
cybersecnet.org
excsrvcdn.com
online-analytic.com
web-traffic.info
web-statistics.info
dnscachecloud.com
dnscloudservice.com
opendnscloud.com
IP's
164.132.181.82
198.50.152.162
158.69.187.171
104.149.37.44
62.113.196.37
75.87.185.45
144.217.149.61
62.113.207.181
144.217.156.94
SHA
10d0d53f5e5f34c424431492fa4ee95eb
2fa4fe6327455384cf508c586dd2851
a8f68c928f82edd8a28c0fd25e207929a7dbce23
9df776b9933fbf95e3d462e04729d074

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity and Hacking New updates.

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Google Patched 40 Security Vulnerabilities Along With Two Zero-Days

Google has released a batch of security updates addressing 40 vulnerabilities, two of which...

Threat Actor IntelBroker Claims Leak of Nokia’s Source Code

The threat actor known as IntelBroker, in collaboration with EnergyWeaponUser, has claimed responsibility for...

Evasive Panda Attacking Cloud Services To Steal Data Using New Toolkit

The Evasive Panda group deployed a new C# framework named CloudScout to target a...

Massive Midnight Blizzard Phishing Attack Using Weaponized RDP Files

Researchers warn of ongoing spear-phishing attacks by Russian threat actor Midnight Blizzard targeting individuals...

Free Webinar

Protect Websites & APIs from Malware Attack

Malware targeting customer-facing websites and API applications poses significant risks, including compliance violations, defacements, and even blacklisting.

Join us for an insightful webinar featuring Vivek Gopalan, VP of Products at Indusface, as he shares effective strategies for safeguarding websites and APIs against malware.

Discussion points

Scan DOM, internal links, and JavaScript libraries for hidden malware.
Detect website defacements in real time.
Protect your brand by monitoring for potential blacklisting.
Prevent malware from infiltrating your server and cloud infrastructure.

More like this

Google Patched 40 Security Vulnerabilities Along With Two Zero-Days

Google has released a batch of security updates addressing 40 vulnerabilities, two of which...

Threat Actor IntelBroker Claims Leak of Nokia’s Source Code

The threat actor known as IntelBroker, in collaboration with EnergyWeaponUser, has claimed responsibility for...

Evasive Panda Attacking Cloud Services To Steal Data Using New Toolkit

The Evasive Panda group deployed a new C# framework named CloudScout to target a...