Thursday, April 18, 2024

New Research Reveals APT Groups Targeting Security Researchers

As per the research conducted by SentinelOne, a new risk has been identified, which affects the information security researchers as well as the infosec community.

Threat actors targeting the infosec community was not something new, as there were several instances where infosec individuals were targeted.

Many security researchers rely on security research tools like Ghidra, IDA Pro, and others to research various other exploits and develop Proof-of-Concepts. 

Those security researchers have been targeted in a spear-phishing campaign recently reported by Google Threat Analytics Group (TAG) in 2022.

Attacks on Security Researchers

As many security researchers could not afford security tool costs, they rely on torrents for pirated software, providing the same functionality as a paid tool for free.

Such tools were targeted by threat actors and leveraged for data exfiltration and post-exploitation techniques.

One such research from ESET in 2021 stated that some malicious actors targeted the IDA Pro torrents and injected a malicious code that downloads an additional DLL from a server in the name of IDA helper for following on post-exploitation.

Another report from Leiden University stated that around 10% of the proof-of-concept GitHub repositories have the capability to exfiltrate data from the targeted environment.

Many of the GitHub projects by Security researchers had established contact with malicious accounts.

SentinelOne also mentioned that “The ability to use a given reverse engineering or digital forensics tool to achieve living off the land types of attacks can be found.“ and “software such as Ghidra enables a threat actor to target members of the security community.”

Identifying Living off the Land

Living off the Land is an attack scenario in which threat actors use fileless malware and rely on legitimate software and services on the victim’s system for further attack cases. One such case study was conducted with the software Ghidra (released by the NSA).

An attacker can modify a .java jar file in Ghidra’s repository which contains the same class name as Ghidra within the /.Ghidra/patch directory to override the functionality.

This path releases the necessary security adversary for the security researchers, which is now under the threat actor’s control.

Once this control is gained, the threat actor can drop the stage-two payload on the system since that is the default functionality of Ghidra.

If a directory named /.ghidra does not exist during the first time installation of Ghidra, it will show a user-agreement policy that the threat actor can exploit to conduct a phishing campaign. 

Ghidra Attack Scenario (Source: SentinelOne)

A complete report on this research has been published by SentinelOne, including a case study, exploitation, and Protection against these kinds of attack scenarios.


Latest articles

Xiid SealedTunnel: Unfazed by Yet Another Critical Firewall Vulnerability (CVE-2024-3400)

In the wake of the recent disclosure of a critical vulnerability (CVE-2024-3400) affecting a...

Cerber Linux Ransomware Exploits Atlassian Servers to Take Full Control

Security researchers at Cado Security Labs have uncovered a new variant of the Cerber...

FGVulDet – New Vulnerability Detector to Analyze Source Code

Detecting source code vulnerabilities aims to protect software systems from attacks by identifying inherent...

North Korean Hackers Abuse DMARC To Legitimize Their Emails

DMARC is targeted by hackers as this serves to act as a preventative measure...

L00KUPRU Ransomware Attackers discovered in the wild

A new variant of the Xorist ransomware, dubbed L00KUPRU, has been discovered in the...

Oracle Releases Biggest Security Update in 2024 – 372 Vulnerabilities Are Fixed – Update Now!

Oracle has released its April 2024 Critical Patch Update (CPU), addressing 372 security vulnerabilities...

Outlook Login Panel Themed Phishing Attack Evaded All Antivirus Detections

Cybersecurity researchers have uncovered a new phishing attack that has bypassed all antivirus detections.The...
Eswar is a Cyber security content editor with a passion for creating captivating and informative content. With years of experience under his belt in Cyber Security, he is covering Cyber Security News, technology and other news.


Mastering WAAP/WAF ROI Analysis

As the importance of compliance and safeguarding critical websites and APIs grows, Web Application and API Protection (WAAP) solutions play an integral role.
Key takeaways include:

  • Pricing models
  • Cost Estimation
  • ROI Calculation

Related Articles