Sunday, July 21, 2024

MuddyWater Hacker Group Utilize Legitimate File-Sharing Service to Distribute Malware

In recent surveillance, a campaign has been witnessed by security researchers, the campaign is targeting companies in the Middle East and nearby regions. According to the news report, the security analysts at Trend Micro have lately identified a campaign that is continuously targeting different organizations.

The cybersecurity expert of the Trend Micro research team has Dubbed “Earth Vetala” the recently detected campaign. However, the latest finding extends on earlier research that was reprinted by Anomali last month.

During the research, the experts found proof of malicious activity that has aimed at UAE and Kuwait government agencies by utilizing the ScreenConnect remote management tool.

Remote Admin Tools Used

According to the experts, the campaign uses the following authorized remote admin tools:

  • ScreenConnect
  • RemoteUtilities

What was discovered?

After investigating the whole campaign the cybersecurity analyst has discovered many details, and that’s why here we have listed the key points below:-

  • The campaign is currently taking all the credentials from browsers like Chrome, Chromium, Firefox, Opera, Internet Explorer, and Outlook.
  • The campaign has been utilizing a spear-phishing email or attached documents with embedded links to an authorized file-sharing service.
  • The main motive of the campaign is to disseminate all the malicious packages that generally carry remote tools (ScreenConnect and RemoteUtilities) to manage all the enterprise systems remotely.

Technical Analysis

The analysts have detected a spearphishing email supposedly from a government agency throughout the research. However, these email tries to induce the beneficiaries to click the URL and download all the malicious file.

Along with the spearphishing email, the fake documents’ content continuously strives to convince the victim to click on another ill-disposed URL and download a malicious .ZIP file.

During the research, they have also detected several ZIP files that are used to administer the RemoteUtilities remote administration software in the method, along with all of those administering the same RemoteUtilities sample.

Tactics, Techniques, and Procedures

  • The campaign has been appropriating the post-exploitation tools that involve password/process-dumping tools, reverse-tunneling tools, and custom backdoors.
  • The threat actors have been perceived as instating conversations along with additional C2 infrastructure to perform the obfuscated PowerShell scripts.

Earth Vetala Footprint and target sectors

Earth Vetala conducted a very extensive aggressive campaign that is targeting multiple countries, and the researchers have identified that it is operating in the following countries:-

  • Bahrain
  • Israel
  • Azerbaijan
  • Saudi Arabia
  • United Arab Emirates

Sectors that are being targeted by Earth Vwtala are:-

  • Government Agencies
  • Academia
  • Tourism

After investigating the whole campaign, the security experts came to know that, the MuddyWater group can create a lot of harm in the future.

MuddyWater group has been long recognized for utilizing spearphishing to attack its victims. That’s why the analysts have suggested to stay observant and use anti-spam, and anti-phishing explications to stay protected from all these types of threats.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity, and hacking news updates.


Latest articles

Hackers Claiming Dettol Data Breach: 453,646 users Impacted

A significant data breach has been reported by a threat actor known as 'Hana,'...

CrowdStrike Update Triggers Widespread Windows BSOD Crashes

A recent update from cybersecurity firm CrowdStrike has caused significant disruptions for Windows users,...

Operation Spincaster Disrupts Approval Phishing Technique that Drains Victim’s Wallets

Chainalysis has launched Operation Spincaster, an initiative to disrupt approval phishing scams that have...

Octo Tempest Know for Attacking VMWare ESXi Servers Added RansomHub & Qilin to Its Arsenal

Threat actors often attack VMware ESXi servers since they accommodate many virtual machines, which...

TAG-100 Actors Using Open-Source Tools To Attack Gov & Private Orgs

Hackers exploit open-source tools to execute attacks because they are readily available, well-documented, and...

macOS Users Beware Of Weaponized Meeting App From North Korean Hackers

Meeting apps are often targeted and turned into weapons by hackers as they are...

Hackers Exploiting Legitimate RMM Tools With BugSleep Malware

Since October 2023, MuddyWater, which is an Iranian threat group linked to MOIS, has...
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Free Webinar

Low Rate DDoS Attack

9 of 10 sites on the AppTrana network have faced a DDoS attack in the last 30 days.
Some DDoS attacks could readily be blocked by rate-limiting, IP reputation checks and other basic mitigation methods.
More than 50% of the DDoS attacks are employing botnets to send slow DDoS attacks where millions of IPs are being employed to send one or two requests per minute..
Key takeaways include:

  • The mechanics of a low-DDoS attack
  • Fundamentals of behavioural AI and rate-limiting
  • Surgical mitigation actions to minimize false positives
  • Role of managed services in DDoS monitoring

Related Articles