Thursday, February 27, 2025
Homecyber securityTarrask Malware Uses Unpatched Zero-day Vulnerabilities to Evade Defense Techniques

Tarrask Malware Uses Unpatched Zero-day Vulnerabilities to Evade Defense Techniques

Published on

SIEM as a Service

Follow Us on Google News

The Chinese-backed Hafnium hacking group has been found to use a new type of malware that Microsoft discovered a few days ago. 

This malware has been used to create and hide scheduled tasks on compromised Windows systems in order to maintain persistence on those systems, and is dubbed “Tarrask.”

There has been a historical pattern of attacks by the Hafnium threat group targeting American companies in the following sectors:- 

  • Defense industry
  • Think tanks
  • Researchers

Microsoft has also listed it as one of the state-sponsored groups that were linked last year to a massive global attack. In this global attack, the threat actors have exploited the ProxyLogon zero-day flaw affecting every version of Microsoft Exchange supported.

Maintaining Persistence via Scheduled Tasks

In order to perform automated tasks on a chosen computer for legitimate administrative purposes, Windows Task Scheduler is a service that enables users to schedule tasks to run on their computer.

In this particular case, it is common to use this service by threat actors to maintain their persistence as long as they remain within a Windows environment.

If you use the Task Scheduler GUI or the schtasks command-line utility to create a scheduled task, the Tarrask malware will generate several artifacts from the process.

Here below we have mentioned the registry keys that are created upon the creation of a new task:-

  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\TASK_NAME
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{GUID}

It is possible that the Hafnium operators could have deleted all on-disk artifacts like:-

  • Registry keys
  • XML file

Since all these deleted artifacts were also added to the system folder to remove any trace of their malicious activity, it would have seemingly removed persistence across restarts since it had been added to the system folder.

Recommendation

In the Windows operating system, the services like Job or task schedulers serving for many years. This attack illustrates the fact that the threat actor HAFNIUM has a deep understanding of the Windows subsystem and makes use of that underpinning to carry out the attack successfully.

They do so to do the following things on the compromised systems:-

  • Mask activities on targeted endpoints
  • Maintain persistence
  • Hide in plain sight

So, here below we have mentioned all the possible mitigations provided by the Microsoft Detection and Response Team (DART) in collaboration with the Microsoft Threat Intelligence Center (MSTIC):-

  • Enumerate your Windows environment registry hives.
  • Enable logging “TaskOperational” within Microsoft-Windows-TaskScheduler/Operational to modify your audit policy to identify Scheduled Tasks actions.
  • Always apply the recommended Microsoft audit policy settings.
  • Enable and centralize the Task Scheduler logs: “Event ID 4698 within the Security.evtx log” and “Microsoft-Windows-TaskScheduler/Operational.evtx log”
  • Make sure to monitor all the uncommon behaviors of your outbound communications.
  • On regular basis re-establish outbound communications with C&C infrastructure.

You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity and hacking news updates.

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Lotus Blossom Hacker Group Uses Dropbox, Twitter, and Zimbra for C2 Communications

The Lotus Blossom hacker group, also known as Spring Dragon, Billbug, or Thrip, has...

Squidoor: Multi-Vector Malware Exploiting Outlook API, DNS & ICMP Tunneling for C2

A newly identified malware, dubbed "Squidoor," has emerged as a sophisticated threat targeting government,...

Unpatched Vulnerabilities Attract Cybercriminals as EDR Visibility Remains Limited

Cyber adversaries have evolved into highly organized and professional entities, mirroring the operational efficiency...

Threat Actors Attack Job Seekers of Fortune 500 Companies to Steal Personal Details

In Q3 2024, Cofense Intelligence uncovered a targeted spear-phishing campaign aimed at employees working...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

Lotus Blossom Hacker Group Uses Dropbox, Twitter, and Zimbra for C2 Communications

The Lotus Blossom hacker group, also known as Spring Dragon, Billbug, or Thrip, has...

Squidoor: Multi-Vector Malware Exploiting Outlook API, DNS & ICMP Tunneling for C2

A newly identified malware, dubbed "Squidoor," has emerged as a sophisticated threat targeting government,...

Unpatched Vulnerabilities Attract Cybercriminals as EDR Visibility Remains Limited

Cyber adversaries have evolved into highly organized and professional entities, mirroring the operational efficiency...