|By PR Newswire||
|August 11, 2014 11:29 AM EDT||
LONDON, August 11, 2014 /PRNewswire/ --
The "Epic" operation serves as the first phase in a multi-stage infection of the Turla campaign
Turla, also known as Snake or Uroburos is one of the most sophisticated ongoing cyber-espionage campaigns. When the first research on Turla/Snake/Uroburos was published, it didn't answer one major question: how do victims become infected?
The latest Kaspersky Lab research on this operation reveals that Epic is the initial stage of the Turla victim infection mechanism.
Turla big picture:
- Epic Turla / Tavdig: The early-stage infection mechanism.
- Cobra Carbon system/ Pfinet (+others): Intermediary upgrades and communication plugins.
- Snake / Uroburos: High-grade malware platform that includes a rootkit and virtual file systems.
The "Epic" project has been used since at least 2012, with the highest volume of activity observed in January-February 2014. Most recently, Kaspersky Lab detected this attack against one of its users on August 5, 2014.
Targets of "Epic" belong to the following categories: government entities (Ministry of Interior, Ministry of Trade and Commerce, Ministry of Foreign/External affairs, intelligence agencies), embassies, military, research and education organisations and pharmaceutical companies.
Most of the victims are located in the Middle East and Europe, however, we observed victims in other regions, including in the USA. In total, Kaspersky Lab experts counted several hundred victim IPs distributed in more than 45 countries, with France at the top of the list.
Distribution of the top 20 affected countries by victim IP
Kaspersky Lab researchers discovered that the Epic Turla attackers use zero-day exploits, social engineering and watering hole technique attacks to infect victims.
In the past, they used at least two zero-day exploits: one for Escalation of Privileges (EoP) in Windows XP and Windows Server 2003 (CVE-2013-5065.) which allows the Epic backdoor to achieve administrator privileges on the system and run unrestricted; and an exploit in Adobe Reader (CVE-2013-3346) that is used in malicious e-mail attachments.
Whenever an unsuspecting user opens a maliciously-crafted PDF file on a vulnerable system, the machine will automatically become infected, allowing the attacker to gain immediate and full control over the target system.
The attackers use both direct spear-phishing e-mails and watering hole attacks to infect victims. The attacks detected in this operation fall into several different categories depending on the initial infection vector used in compromising the victim:
● Spear-phishing e-mails with Adobe PDF exploits (CVE-2013-3346 + CVE-2013-5065.)
● Social engineering to trick the user into running malware installers with ".SCR" extension, sometimes packed with RAR
● Watering hole attacks using Java exploits (CVE-2012-1723), Adobe Flash exploits (unknown) or Internet Explorer 6, 7, 8 exploits (unknown)
● Watering hole attacks that rely on social engineering to trick the user into running fake "Flash Player" malware installers
Watering holes are websites commonly visited by potential victims. These websites are compromised in advance by the attackers and are injected to serve malicious code. Depending on the visitor's IP address (for instance, a government organisation's IP), the attackers serve Java or browser exploits, signed fake Adobe Flash Player software or a fake version of Microsoft Security Essentials. In total, we have observed more than 100 injected websites. The choice of the websites reflects specific interest of attackers. For example, many of the infected Spanish websites belong to local governments.
Once the user is infected, the Epic backdoor immediately connects to the command-and-control (C&C) server to send a pack with the victim's system information. The backdoor is also known as "WorldCupSec", "TadjMakhal", "Wipbot" or "Tadvig".
Once a system is compromised, the attackers receive a brief summary of information from the victim, and based on that, they deliver pre-configured batch files containing a series of commands for execution. In addition to these, the attackers upload custom lateral movement tools. These include a specific keylogger tool, a RAR archiver and standard utilities like a DNS query tool from Microsoft.
Turla's first stage:
During the analysis, Kaspersky Lab researchers observed the attackers using the Epic malware to deploy a more sophisticated backdoor known as the "Cobra/Carbon system", also named "Pfinet" by some anti-virus products. After some time, the attackers went further and used the Epic implant to update the "Carbon" configuration file with a different set of C&C servers. The unique knowledge to operate these two backdoors indicates a clear and direct connection between each other.
"The configuration updates for the 'Carbon system' malware are interesting, because this is another project from the Turla actor. This indicates that we are dealing with a multi-stage infection that begins with Epic Turla. The Epic Turla is used to gain a foothold and validate the high profile victim. If the victim is interesting, it gets upgraded to the full Turla Carbon system" explains Costin Raiu, Director of the Global Research and Analysis Team at Kaspersky Lab.
The attackers behind Turla are clearly not native English speakers. They commonly misspell words and expressions, such as:
- Password it´s wrong!
- File is not exists
- File is exists for edit
There are other indications which provide a hint at the origin of the attackers. For instance, some of the backdoors have been compiled on a system with Russian language. Additionally, the internal name of one of the Epic backdoors is "Zagruzchik.dll", which means "bootloader" or "load program" in Russian.
Finally, the Epic mothership control panel sets the code page to 1251, which is used for Cyrillic characters.
Links with other threat actors:
Interestingly, possible connections with different cyber-espionage campaigns have been observed. In February 2014, Kaspersky Lab experts observed that the threat actor known as Miniduke were using the same web-shells to manage infected web servers as the Epic team did.
To learn more about the "Epic Turla" operation, please read the blog post available at Securelist.com.
About Kaspersky Lab
Kaspersky Lab is the world's largest privately held vendor of endpoint protection solutions. The company is ranked among the world's top four vendors of security solutions for endpoint users*. Throughout its more than 16-year history Kaspersky Lab has remained an innovator in IT security and provides effective digital security solutions for large enterprises, SMBs and consumers. Kaspersky Lab, with its holding company registered in the United Kingdom, currently operates in almost 200 countries and territories across the globe, providing protection for over 300 million users worldwide. Learn more at http://www.kaspersky.com.
* The company was rated fourth in the IDC rating Worldwide Endpoint Security Revenue by Vendor, 2012. The rating was published in the IDC report "Worldwide Endpoint Security 2013-2017 Forecast and 2012 Vendor Shares (IDC #242618, August 2013). The report ranked software vendors according to earnings from sales of endpoint security solutions in 2012.
1650 Arlington Business Park
RG7 4SA, Reading
Kaspersky Lab UK
2 Kingdom Street
W2 6BD, London
SOURCE Kaspersky Lab
The 5th International DevOps Summit, co-located with 17th International Cloud Expo – being held November 3-5, 2015, at the Santa Clara Convention Center in Santa Clara, CA – announces that its Call for Papers is open. Born out of proven success in agile development, cloud computing, and process automation, DevOps is a macro trend you cannot afford to miss. From showcase success stories from early adopters and web-scale businesses, DevOps is expanding to organizations of all sizes, including the ...
Jul. 7, 2015 12:15 PM EDT Reads: 1,938
Jul. 7, 2015 12:15 PM EDT Reads: 2,394
SYS-CON Media announced today that CloudBees, the Jenkins Enterprise company, has launched ad campaigns on SYS-CON's DevOps Journal. CloudBees' campaigns focus on the business value of Continuous Delivery and how it has been recognized as a game changer for IT and is now a top priority for organizations, and the best ways to optimize Jenkins to ensure your continuous integration environment is optimally configured.
Jul. 7, 2015 12:15 PM EDT Reads: 1,325
Jul. 7, 2015 12:00 PM EDT Reads: 1,586
The Internet of Things is not only adding billions of sensors and billions of terabytes to the Internet. It is also forcing a fundamental change in the way we envision Information Technology. For the first time, more data is being created by devices at the edge of the Internet rather than from centralized systems. What does this mean for today's IT professional? In this Power Panel at @ThingsExpo, moderated by Conference Chair Roger Strukhoff, panelists addressed this very serious issue of pro...
Jul. 7, 2015 12:00 PM EDT Reads: 1,954
SYS-CON Events announced today that kintone has been named “Bronze Sponsor” of SYS-CON's 17th International Cloud Expo®, which will take place on November 3–5, 2015, at the Santa Clara Convention Center in Santa Clara, CA. kintone promotes cloud-based workgroup productivity, transparency and profitability with a seamless collaboration space, build your own business application (BYOA) platform, and workflow automation system.
Jul. 7, 2015 12:00 PM EDT Reads: 2,201
The most often asked question post-DevOps introduction is: “How do I get started?” There’s plenty of information on why DevOps is valid and important, but many managers still struggle with simple basics for how to initiate a DevOps program in their business. They struggle with issues related to current organizational inertia, the lack of experience on Continuous Integration/Delivery, understanding where DevOps will affect revenue and budget, etc. In their session at DevOps Summit, JP Morgenthal...
Jul. 7, 2015 12:00 PM EDT Reads: 1,630
Buzzword alert: Microservices and IoT at a DevOps conference? What could possibly go wrong? In this Power Panel at DevOps Summit, moderated by Jason Bloomberg, the leading expert on architecting agility for the enterprise and president of Intellyx, panelists peeled away the buzz and discuss the important architectural principles behind implementing IoT solutions for the enterprise. As remote IoT devices and sensors become increasingly intelligent, they become part of our distributed cloud envir...
Jul. 7, 2015 11:45 AM EDT Reads: 2,741
Jul. 7, 2015 11:30 AM EDT Reads: 1,901
Jul. 7, 2015 11:15 AM EDT Reads: 1,830
Jul. 7, 2015 11:15 AM EDT Reads: 1,735
Jul. 7, 2015 11:15 AM EDT Reads: 380
Jul. 7, 2015 11:00 AM EDT Reads: 2,199
Jul. 7, 2015 11:00 AM EDT Reads: 2,091
Jul. 7, 2015 11:00 AM EDT Reads: 1,799