惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

The GitHub Blog
The GitHub Blog
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Microsoft Security Blog
Microsoft Security Blog
J
Java Code Geeks
S
SegmentFault 最新的问题
Apple Machine Learning Research
Apple Machine Learning Research
N
Netflix TechBlog - Medium
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
博客园_首页
宝玉的分享
宝玉的分享
Google DeepMind News
Google DeepMind News
B
Blog RSS Feed
Hugging Face - Blog
Hugging Face - Blog
量子位
Blog — PlanetScale
Blog — PlanetScale
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
阮一峰的网络日志
阮一峰的网络日志
D
Docker
罗磊的独立博客
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
云风的 BLOG
云风的 BLOG
IT之家
IT之家
MyScale Blog
MyScale Blog
Microsoft Azure Blog
Microsoft Azure Blog

Industroyer Archives - Security Affairs

Russia-linked BlackEnergy backed new cyber attacks on Ukraine’s state bodies Exaramel Malware Links Industroyer ICS malware and NotPetya wiper Experts spotted Industroyer ICS Malware and linked it to Ukraine Power Outage
GreyEnergy cyberespionage group targets Poland and Ukraine
Pierluigi Paganini · 2018-10-19 · via Industroyer Archives - Security Affairs

Security researchers from ESET published a detailed analysis of a recently discovered cyber espionage group tracked as GreyEnergy.

Security experts from ESET published a detailed analysis of a recently discovered threat actor tracked as GreyEnergy, its activity emerged in concurrence with BlackEnergy operations.

ESET researchers have spotted a new strain of malware tracked as Exaramel that links the not Petya wiper to the Industroyer ICS malware.

Experts from ESET speculate the BlackEnergy threat actor evolved into two separate APT groups, namely TeleBots and GreyEnergy.

“Following this attack, the BlackEnergy group evolved into at least two subgroups:
TeleBots and GreyEnergy. ”  reads the report.

“The main goal of the TeleBots group is to perform cybersabotage attacks on Ukraine, which are achieved through computer network attack (CNA) operations.”

GreyEnergy conducted reconnaissance and cyber espionage activities in Ukraine and Poland, it focused its activities on energy and transportation industries, and other high-value targets.

The APT group leverage the GreyEnergy malware, a malicious code that implements a modular architecture to extend its capabilities by adding the appropriate modules.

“Like many complex threats, the GreyEnergy malware has a modular architecture. The functionality of the malware can be easily extended with additional modules. A GreyEnergy module is a DLL file that gets executed by calling the function with the first ordinal. Each module, including the main GreyEnergy module, accepts text commands with various parameters.” continues the analysis.

The list of available modules includes components for file extraction, screenshot capturing, keylogging, password, and credential stealing, and of course a backdoor.

Experts pointed out that they haven’t found modules that specifically target Industrial Control Systems software or devices. ESET pointed out that GreyEnergy operators have been strategically targeting ICS control workstations running SCADA software and servers.

In one case, hackers used a disk-wiping component to disrupt operating processes on the target systems.

GreyEnergy attackers in one case also used a valid digital certificate, likely stolen from Taiwanese company Advantech, to sign a sample.

“One of the most intriguing details discovered during our research is that one of the GreyEnergy samples we found was signed with a valid digital certificate that had likely been stolen from a Taiwanese company that produces ICS equipment. In this respect, the GreyEnergy group has literally followed in Stuxnet’s footsteps.” states ESET.

Attackers spread the malware by carryout both spear phishing campaigns and compromised self-hosted web services, in this latter case attackers hack into public-facing web services running on a server that is connected to an internal network. In this was attackers will attempt to compromise the server and make lateral movements in the internal network.

GreyEnergy also used other backdoors, mostly PHP backdoors, and malware implementing several layers of obfuscation and encryption to hide the malicious code.

The spear-phishing messages first drop a lightweight first-stage backdoor tracked as GreyEnergy mini (aka FELIXROOT) to gather information on the target network and gather admin credentials using tools such as Nmap and Mimikatz.

The stolen credentials are used to deploy the main GreyEnergy malware into the target network with administrator privileges.

The malware is written in C and compiled using Visual Studio, it is deployed two ways:

  • in-memory-only mode without implementing persistence;
  • Service DLL persistence;

ESET experts also discovered a worm dubbed Moonraker Petya that is similar to NotPetya, they speculate it is a predecessor of the infamous wiper.

GreyEnergy

Moonraker Petya has limited spreading capabilities and like NotPetya it is able to make machines unbootable, the malware was used against a small number of organizations.

Moonraker Petya may be the result of a collaboration between TeleBots and GreyEnergy APT groups.

“GreyEnergy is an important part of the arsenal of one of the most dangerous APT groups that has been terrorizing Ukraine for the past several years. We consider it to be the successor of the BlackEnergy toolkit. The main reasons for this conclusion are the similar malware design, specific choice of targeted victims, and modus operandi,” ESET concludes.

[adrotate banner=”9″] [adrotate banner=”12″]

Pierluigi Paganini

(Security Affairs – GreyEnergy, APT)

[adrotate banner=”5″]

[adrotate banner=”13″]