National Cyber Warfare Foundation (NCWF)

CHRYSENE


0 user ratings
2024-07-26 20:03:49
blscott

 - archive -- 
mso-border-bottom-alt:solid windowtext .75pt;padding:0in 0in 1.0pt 0in\">

solid windowtext .75pt;padding:0in;mso-padding-alt:0in 0in 1.0pt 0in\">Adversaries
abusing ICS (based on Dragos Inc adversary list). This threat actor targets
organizations involved in oil, gas, and electricity production, primarily in
the Gulf region, for espionage purposes. According to one cybersecurity
company, the threat actor compromises a target machine and passes it off to another
threat actor for further exploitation.





Chrysene is a codename used
by Dragos to identify an Iran-linked cyber espionage
group active since mid-2017, widely assessed as a subset or variant of the
broader OilRig / APT 34 / Helix Kitten / Cobalt
Gypsy threat actor network. 




  • Target
    Focus:
    The group specifically targets organizations in
    the electricity generation, oil, and gas sectors, primarily
    in North America, Western Europe, Israel, and Iraq. 

  • Tactics:
    Chrysene employs IT penetration and espionage rather than direct
    industrial control system (ICS) sabotage, using custom malware with
    enhancements over related groups like OilRig and Greenbug. 

  • Attribution:
    While Dragos distinguishes Chrysene as a distinct activity group, it is
    closely associated with Iranian state interests and shares significant
    tooling overlap with other Iranian APTs. 



Operational Evolution and Role



Chrysene functions primarily
as an initial access broker within the Iranian cyber espionage
ecosystem.  Rather than conducting long-term exploitation themselves,
they specialize in compromising target networks and subsequently handing
off access to other threat actors for further exploitation.
This
\"handoff\" model was evident in their lineage from the groups
responsible for the 2012 Shamoon attacks against Saudi
Aramco. 



While historically linked
to OilRig (APT34) and Greenbug, Chrysene has evolved into a
distinct entity with more advanced technical capabilities. They utilize custom
64-bit malware and unique Command and Control (C2) infrastructure designed to
evade standard antivirus detection. Their operations have expanded from the
Arabian Gulf to include targets in North America, Western Europe,
Israel, Iraq, and Pakistan.



Tactics, Techniques, and Procedures (TTPs)



Chrysene’s methodology focuses
on IT penetration to facilitate ICS reconnaissance.  They
do not currently possess confirmed capabilities to directly manipulate
industrial control systems for destructive effect; instead, they gather the
intelligence necessary for future disruptive operations. 




  • Infection
    Vectors
    : The group employs watering hole attacks,
    compromising legitimate websites unrelated to industrial controls to
    infect visitors.  They also leverage spear-phishing and the
    exploitation of public-facing applications.

  • Malware
    Arsenal
    : Their toolkit includes modular backdoors such
    as QUADAGENT, Helminth, and POWRUNER.  These
    tools allow for DNS tunneling, file exfiltration, and lateral movement
    within Windows-based environments often found in engineering workstations.

  • Evasion:
    A key differentiator from predecessor groups is their use of 64-bit
    malware
    and updated toolsets to bypass legacy security
    filters.  In 2019, activity clusters associated with Chrysene
    were also observed under the moniker Hexane, indicating a
    continued strategy of refreshing tools to avoid attribution. 



Strategic Targets and Intent



The group’s strategic focus
remains fixed on the energy sector, specifically targeting:




  1. Electricity
    Generation
    : Mapping control loops and identifying operational
    leverage points.

  2. Oil
    and Gas
    : Compromising petrochemical facilities and
    upstream/downstream infrastructure. 

  3. Telecommunications:
    Occasionally targeted to support broader espionage goals in the Middle
    East and Southwest Asia. 



Recent
intelligence suggests that while Chrysene focuses on espionage, the data
they collect supports the broader Iranian objective of developing pre-positioning
capabilities
for potential future disruption of critical
infrastructure.  
Their activity serves as the \"eyes and
ears\" phase of a larger operational cycle, feeding information to groups
capable of executing destructive payloads. 



OilRig is a threat group
with suspected Iranian origins
that has targeted Middle Eastern and
international victims since at least 2014. The group has targeted a variety of
industries, including financial, government, energy, chemical, and
telecommunications, and has largely focused its operations within the Middle East.
It appears the group carries out supply chain attacks, leveraging the trust
relationship between organizations to attack their primary targets.
FireEye
assesses that the group works on behalf of the Iranian government based on
infrastructure details that contain references to Iran, use of Iranian
infrastructure, and targeting that aligns with nation-state interests. This
group was previously tracked under two distinct groups, APT 34 and OilRig, but
was combined due to additional reporting giving higher confidence about the
overlap of the activity.



 OilRig has 1 subgroup: 1. \\\'Subgroup:
Greenbug, Volatile Kitten\\\' OilRig seems to be closely related to \\\'APT 33,
Elfin, Magnallium\\\' since at least 2017 and perhaps \\\'DNSpionage\\\'. They also
seem to overlap with \\\'Hexane\\\'. Also see \\\'HomeLand Justice\\\' and
\\\'Orangeworm\\\'. A subgroup of \\\'OilRig, APT 34, Helix Kitten, Chrysene\\\'.
(Symantec) Symantec discovered the Greenbug cyberespionage group during its
investigation into previous attacks involving W32.Disttrack.B (aka Shamoon).
Shamoon (W32.Disttrack) first made headlines in 2012 when it was used in
attacks against energy companies in Saudi Arabia. It recently resurfaced
in November 2016
(W32.Disttrack.B), again attacking targets in Saudi
Arabia. While these attacks were covered extensively in the media,
how the attackers stole these credentials and introduced W32. Disttrack on
targeted organizations’ networks remains a mystery. Could Greenbug be
responsible for getting Shamoon those stolen credentials? Although there is no
definitive link between Greenbug and Shamoon, the group compromised at least
one administrator computer within a Shamoon-targeted organization’s network
prior to W32.Disttrack.B being deployed on November 17, 2016.



Other Names: APT 34, ATK 40,
CHRYSENE, Chrysene, Cobalt Gypsy, Crambus, DEV-0861, EUROPIUM, Earth Simnavaz,
Evasive Serpens, Greenbug, Hazel Sandstorm, Helix Kitten, IRN2, ITG13, OilRig,
Scarred Manticore, Storm-0861, TA452, Twisted Kitten, UNC1860, Volatile Kitten,
Yellow Maero



Sponsor: Unknown. State-sponsored,
Ministry of Intelligence and Security (MOIS). State-sponsored, Ministry of
Intelligence and Security (MOIS)



Targets: Albania, Azerbaijan,
Bahrain, China, Egypt, Iraq, Israel, Jordan, Kuwait, Lebanon, Mauritius, Oman,
Pakistan, Qatar, Saudi Arabia, Turkey, United Arab Emirates, United Kingdom,
United States - Aviation, Chemical, Defense, Education, Energy, Financial,
Government, High-Tech, Hospitality, IT, Oil and gas, Private sector,
Telecommunications.



Tools:



Alma
Communicator (category: Malware)


type: Backdoor, Tunneling

(Palo Alto) Recently, we observed a new version of the \'Clayslide\' delivery
document used to install a new custom Trojan whose developer calls it “ALMA
Communicator”. The delivery document also saved the post-exploitation
credential harvesting tool known as \'Mimikatz\', which we believe the threat
actors will use to gather account credentials from the compromised system.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=0b467acc-1e16-4e2d-9946-0e84e679c343

https://unit42.paloaltonetworks.com/unit42-oilrig-deploys-alma-communicator-dns-tunneling-trojan/

https://unit42.paloaltonetworks.com/dns-tunneling-in-the-wild-overview-of-oilrigs-dns-tunneling/

https://malpedia.caad.fkie.fraunhofer.de/details/win.alma_communicator



BONDUPDATER (category:
Malware)


type: Backdoor, Info stealer

(Palo Alto) BONDUPDATER is a PowerShell-based Trojan first discovered by
FireEye in mid-November 2017, when OilRig targeted a different Middle Eastern
governmental organization. The BONDUPDATER Trojan contains basic backdoor
functionality, allowing threat actors to upload and download files, as well as
the ability to execute commands. BONDUPDATER, like other OilRig tools, uses DNS
tunneling to communicate with its C2 server. During the past month, Unit 42
observed several attacks against a Middle Eastern government leveraging an
updated version of the BONDUPDATER malware, which now includes the ability to
use TXT records within its DNS tunneling protocol for its C2 communications.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=5ca10b6c-95cb-4ff3-abb0-afc59394a633

https://unit42.paloaltonetworks.com/unit42-oilrig-uses-updated-bondupdater-target-middle-eastern-government/

https://www.fireeye.com/blog/threat-research/2017/12/targeted-attack-in-middle-east-by-apt34.html

https://www.boozallen.com/s/insight/blog/dark-labs-discovers-apt34-malware-variants.html

https://unit42.paloaltonetworks.com/dns-tunneling-in-the-wild-overview-of-oilrigs-dns-tunneling/

https://attack.mitre.org/software/S0360/

https://malpedia.caad.fkie.fraunhofer.de/details/ps1.bondupdater

https://otx.alienvault.com/browse/pulses?q=tag:BONDUPDATER



certutil (category:
Tools)


certutil is a command-line utility that can be used to obtain certificate
authority information and configure Certificate Services.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=4542b4a3-4a50-43b5-a4a6-0fda43f306ae

https://www.bleepingcomputer.com/news/security/certutilexe-could-allow-attackers-to-download-malware-while-bypassing-av/

https://attack.mitre.org/software/S0160/



Clayslide (category:
Malware)


type: Dropper

This is a so-called delivery document. (Palo Alto) n May 2016, Unit 42 began
researching attacks that used spear-phishing emails with attachments,
specifically malicious Excel spreadsheets sent to financial organizations
within Saudi Arabia. We observed spear-phishing emails sent between May 4 and
May 12 of this year that delivered these malicious Excel spreadsheets, which we
are tracking as ‘Clayslide’. ClaySlide documents contain malicious macros that
display decoy content within the spreadsheet and installs a variant of a
\'Helminth\' backdoor.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=bed1c93e-b6c8-4d31-b7b0-b41d1b05bcb2

https://unit42.paloaltonetworks.com/the-oilrig-campaign-attacks-on-saudi-arabian-organizations-deliver-helminth-backdoor/



DistTrack (category:
Malware)


type: ICS malware, Wiper, Worm

(Cylance) The malware known as Disttrack is a destructive worm that targets a
system’s master boot record (MBR). Disttrack is also known as Shamoon because
the original payload included debugging information that referenced a
programming database file with this unique name in the path. Disttrack’s
payload has spread in waves, mainly targeting Saudi Arabia’s critical
infrastructure, including, but not limited to: Saudi Aramco, Saudi Arabia’s
General Authority of Civil Aviation (GACA), and the Saudi Electric Company,
leaving critical systems unusable. It is relentless, stealthy, and persistent
as it waits in the shadows of infected computers as a Windows service and
attacks on hardcoded dates, like a ticking time-bomb waiting to go off every 90
seconds.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=3f2012fe-69e0-4c62-8695-c79a2d0ce48c

https://threatvector.cylance.com/en_us/home/threat-spotlight-disttrack-malware.html

http://contagiodump.blogspot.com/2012/08/shamoon-or-disttracka-samples.html

http://researchcenter.paloaltonetworks.com/2016/11/unit42-shamoon-2-return-disttrack-wiper/

http://researchcenter.paloaltonetworks.com/2017/03/unit42-shamoon-2-delivering-disttrack/

https://unit42.paloaltonetworks.com/unit42-second-wave-shamoon-2-attacks-identified/

https://unit42.paloaltonetworks.com/shamoon-3-targets-oil-gas-organization/

http://www.vinransomware.com/blog/detailed-threat-analysis-of-shamoon-2-0-malware

https://www.codeandsec.com/Sophisticated-CyberWeapon-Shamoon-2-Malware-Analysis

https://attack.mitre.org/software/S0140/

https://malpedia.caad.fkie.fraunhofer.de/details/win.disttrack

https://otx.alienvault.com/browse/pulses?q=tag:Disttrack

https://otx.alienvault.com/browse/pulses?q=tag:shamoon



DNSExfitrator (category:
Malware)


type: Exfiltration, Tunneling

(Kasperksy) At the end of May, we observed that Oilrig had included the
DNSExfitrator tool in its toolset. It allows the threat actor to use the DNS
over HTTPS (DoH) protocol. Use of the DNS protocol for malware communications
is a technique that Oilrig has been using for a long time. The difference
between DNS- and DoH-based requests is that, instead of plain text requests to
port 53, they would use port 443 in encrypted packets. Oilrig added the
publicly available DNSExfiltrator tool to its arsenal, which allows DoH queries
to Google and Cloudflare services. This time, the operators decided to use
subdomains of a COVID-related domain which are hardcoded in the DNSExfitrator
detected samples.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=135f3617-9251-4daf-999e-3fa79a029b5d

https://securelist.com/apt-trends-report-q2-2020/97937/



DNSpionage (category:
Malware)


type: Backdoor

(Talos) Based on this actor\'s infrastructure and TTPs, we haven\'t been able to
connect them with any other campaign or actor that\'s been observed recently.
This particular campaign utilizes two fake, malicious websites containing job
postings that are used to compromise targets via malicious Microsoft Office
documents with embedded macros. The malware utilized by this actor, which we
are calling \'DNSpionage,\' supports HTTP and DNS communication with the
attackers. In a separate campaign, the attackers used the same IP to redirect
the DNS of legitimate .gov and private company domains. During each DNS
compromise, the actor carefully generated Let\'s Encrypt certificates for the
redirected domains. These certificates provide X.509 certificates for TLS free
of charge to the user. We don\'t know at this time if the DNS redirections were
successful.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=3b9f0a41-e890-4c2e-aacb-fab6def66f87

https://blog.talosintelligence.com/2018/11/dnspionage-campaign-targets-middle-east.html

https://www.us-cert.gov/ncas/alerts/AA19-024A

https://blog-cert.opmd.fr/dnspionage-focus-on-internal-actions/

https://www.zdnet.com/article/source-code-of-iranian-cyber-espionage-tools-leaked-on-telegram/

https://www.fireeye.com/blog/threat-research/2019/01/global-dns-hijacking-campaign-dns-record-manipulation-at-scale.html

https://www.lastline.com/labsblog/threat-actor-cold-river-network-traffic-analysis-and-a-deep-dive-on-agent-drable/

https://blog.talosintelligence.com/2019/04/dnspionage-brings-out-karkoff.html

https://malpedia.caad.fkie.fraunhofer.de/details/win.dnspionage

https://otx.alienvault.com/browse/pulses?q=tag:DNSpionage



Dustman (category:
Malware)


type: Wiper

(IBM) A \'ZeroCleare\' offshoot has been reported by the Saudi National
Cybersecurity Authority (NCA) in destructive attacks targeting the same region.
This variation of ZeroCleare was dubbed “Dustman,” also per the PDB pathname of
its binary file.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=85552932-c4be-498f-b427-2e45495c62b3

https://securityintelligence.com/posts/enter-dustman-new-wiper-takes-after-zerocleare-targets-organizations-in-saudi-arabia/

https://malpedia.caad.fkie.fraunhofer.de/details/win.dustman



Fox
Panel (
category: Malware)


type: Control panel

A phishing kit that was leaked when OilRig themselves were breached in 2019.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=ce229a4a-11bb-4a2f-b1e4-ed0d069d4310

https://www.zdnet.com/article/source-code-of-iranian-cyber-espionage-tools-leaked-on-telegram/



GoogleDrive
RAT
(category: Malware)


type: Backdoor

(Nyotron) Some of the compromised servers contained an innovative Google
Drive-based RAT under the name Service.exe. The attacker moved Service.exe to
C:\\Windows\\system32 along with a large set of files. These files included DLLs
related to the Google API used for communication and more.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=789aa471-f872-4252-b492-c68d2d8bf8ff

https://www.nyotron.com/collateral/Nyotron-OilRig-Malware-Report-March-2018C.pdf

https://malpedia.caad.fkie.fraunhofer.de/details/win.google_drive_rat



Helminth (category:
Malware)


type: Backdoor

Helminth is a backdoor that has at least two variants - one written in VBScript
and PowerShell that is delivered via a macros in Excel spreadsheets, and one
that is a standalone Windows executable.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=36781ff8-6907-4f06-9ce6-d1f4575b3f71

https://unit42.paloaltonetworks.com/the-oilrig-campaign-attacks-on-saudi-arabian-organizations-deliver-helminth-backdoor/

https://www.fireeye.com/blog/threat-research/2016/05/targeted_attacksaga.html

https://unit42.paloaltonetworks.com/dns-tunneling-in-the-wild-overview-of-oilrigs-dns-tunneling/

http://researchcenter.paloaltonetworks.com/2016/10/unit42-oilrig-malware-campaign-updates-toolset-and-expands-targets/

https://attack.mitre.org/software/S0170/

https://malpedia.caad.fkie.fraunhofer.de/details/win.helminth

https://otx.alienvault.com/browse/pulses?q=tag:Helminth



ISMAgent (category:
Malware)


type: Backdoor

(Palo Alto) On May 1, 2017, Arbor Networks published research on \'ISMDoor\'
using DNS tunneling to communicate with its C2 server, which is nearly
identical to the DNS tunneling the payload of this attack carries out. Due to
considerable differences and evidence of potentially different authors between
the previous ISMDoor samples and this newly discovered variant, we are tracking
this new variant as ISMAgent. The ISMAgent tool comes with a default
configuration that specifies the C2 domain and the number of minutes between
further attempts to execute the tool. However, an actor can use command line
arguments to create a new ISMAgent sample that is configured with a specified
C2 domain and a specified number of minutes to automatically execute the
Trojan.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=da73c338-cd73-48fb-be70-3498915cfad5

https://unit42.paloaltonetworks.com/unit42-oilrig-uses-ismdoor-variant-possibly-linked-greenbug-threat-group/

https://unit42.paloaltonetworks.com/dns-tunneling-in-the-wild-overview-of-oilrigs-dns-tunneling/

http://www.clearskysec.com/ismagent/

https://malpedia.caad.fkie.fraunhofer.de/details/win.ismagent

https://otx.alienvault.com/browse/pulses?q=tag:ISMAgent



ISMDoor (category:
Tools)


type: Backdoor, Tunneling

(Arbor) Ismdoor has an encrypted configuration that contains a primary and
secondary C2 domain, various identifiers, timeouts, and flags. These values can
be updated by later C2 commands. A substitution cipher is used to decrypt the
configuration when it is needed. The character mapping has been consistent
across samples and we have made available a Python snippet of it on Github.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=889bdc01-47e6-4026-ae68-abe9dc87404e

https://www.netscout.com/blog/asert/greenbugs-dns-isms

https://malpedia.caad.fkie.fraunhofer.de/details/win.ismdoor

https://otx.alienvault.com/browse/pulses?q=tag:ismdoor



ISMInjector (category:
Malware)


type: Loader

(Palo Alto) In August 2017, we found this threat group has developed yet
another Trojan that they call ‘Agent Injector’ with the specific purpose of
installing the \'ISMAgent\' backdoor. We are tracking this tool as ISMInjector.
It has a sophisticated architecture and contains anti-analysis techniques that
we have not seen in previous tools developed by this threat group. The complex
structure and inclusion of new anti-analysis techniques may suggest that this
group is increasing their development efforts in order to evade detection and
gain higher efficacy in their attacks.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=323162c2-b731-4641-8797-5870730ddb32

https://unit42.paloaltonetworks.com/unit42-oilrig-group-steps-attacks-new-delivery-documents-new-injector-trojan/

https://attack.mitre.org/software/S0189/

https://otx.alienvault.com/browse/pulses?q=tag:ISMInjector





Jason (category:
Malware)


type: Credential stealer

Jason is a graphic tool implemented to perform Microsoft exchange account
brute-force in order to “harvest” the highest possible emails and accounts
information. Distributed in a ZIP container (a copy is available here) the
interface is quite intuitive: the Microsoft exchange address and its version
shall be provided (even if in the code a DNS-domain discovery mode function is
available). Three brute-force methods could be selected: EWS (Exchange Web
Service), OAB (Offline Address Book) or both (All). Username and password list
can be selected (included in the distributed ZIP file) and threads number
should be provided in order to optimize the attack balance.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=63a5c1de-3df9-4c7f-8fd3-134b26c2866f

https://marcoramilli.com/2019/06/06/apt34-jason-project/

https://malpedia.caad.fkie.fraunhofer.de/details/win.jason



Karkoff (category:
Malware)


type: Backdoor, Dropper

(Talos) In April, Cisco Talos identified an undocumented malware developed in
.NET. On the analyzed samples, the malware author left two different internal
names in plain text: \'DropperBackdoor\' and \'Karkoff.\' We decided to use the
second name as the malware\'s moniker, as it is less generic. The malware is
lightweight compared to other malware due to its small size and allows remote
code execution from the C2 server. There is no obfuscation and the code can be
easily disassembled.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=330eed05-5332-4314-a9ef-ebe891bc3153

https://blog.talosintelligence.com/2019/04/dnspionage-brings-out-karkoff.html

https://malpedia.caad.fkie.fraunhofer.de/details/win.karkoff

https://otx.alienvault.com/browse/pulses?q=tag:Karkoff



LaZagne (category:
Tools)


type: Credential stealer

LaZagne is a post-exploitation, open-source tool used to recover stored
passwords on a system. It has modules for Windows, Linux, and OSX, but is
mainly focused on Windows systems. LaZagne is publicly available on GitHub.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=f2697246-5288-4d3b-94d4-7200c85005e5

https://github.com/AlessandroZ/LaZagne

https://www.trendmicro.com/en_us/research/20/k/weaponizing-open-source-software-for-targeted-attacks.html

https://edu.anarcho-copy.org/Against%20Security%20&%20%20Self%20Security/Group-IB%20RedCurl.pdf

https://unit42.paloaltonetworks.com/lazagne-leverages-d-bus/

https://attack.mitre.org/software/S0349/

https://malpedia.caad.fkie.fraunhofer.de/details/py.lazagne

https://otx.alienvault.com/browse/pulses?q=tag:LazaGne



LIONTAIL (category:
Malware)


type: Loader

(Check Point) In the latest campaign, the threat actor leveraged the LIONTAIL
framework, a sophisticated set of custom loaders and memory resident shellcode
payloads. LIONSTAIL’s implants utilize undocumented functionalities of the
HTTP.sys driver to extract payloads from incoming HTTP traffic. Multiple
observed variants of LIONTAIL-associated malware suggest Scarred Manticore
generates a tailor-made implant for each compromised server, allowing the
malicious activities to blend into and be undiscernible from legitimate network
traffic.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=5206efd1-cfd9-4561-bd80-56789f5efce5

https://research.checkpoint.com/2023/from-albania-to-the-middle-east-the-scarred-manticore-is-listening/

https://malpedia.caad.fkie.fraunhofer.de/details/win.liontail



Living
off the Land
(category: Tools)


(Talos) Attackers\' trends tend to come and go. But one popular technique we\'re
seeing at this time is the use of living-off-the-land binaries — or \'LoLBins\'.
LoLBins are used by different actors combined with fileless malware and
legitimate cloud services to improve chances of staying undetected within an
organisation, usually during post-exploitation attack phases.
Living-off-the-land tactics mean that attackers are using pre-installed tools
to carry out their work. This makes it more difficult for defenders to detect
attacks and researchers to identify the attackers behind the campaign. In the
attacks we\'re seeing, there are binaries supplied by the victim\'s operating
system that are normally used for legitimate purposes, but in these cases, are
being abused by the attackers. (LOLBAS Project) The goal of the LOLBAS project
is to document every binary, script, and library that can be used for Living
Off The Land techniques. A LOLBin/Lib/Script must: • Be a Microsoft-signed
file, either native to the OS or downloaded from Microsoft. • Have extra
\'unexpected\' functionality. It is not interesting to document intended use
cases. o Exceptions are application whitelisting bypasses • Have functionality
that would be useful to an APT or red team Interesting functionality can
include: • Executing code o Arbitrary code execution o Pass-through execution
of other programs (unsigned) or scripts (via a LOLBin) • Compiling code • File
operations o Downloading o Upload o Copy • Persistence o Pass-through
persistence utilizing existing LOLBin o Persistence (e.g. hide data in ADS,
execute at logon) • UAC bypass • Credential theft • Dumping process memory •
Surveillance (e.g. keylogger, network trace) • Log evasion/modification • DLL
side-loading/hijacking without being relocated elsewhere in the filesystem.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=d54e09cf-97b7-40a4-b30e-4c0a2bf0ea40

https://github.com/LOLBAS-Project/LOLBAS

https://lolbas-project.github.io/

https://blog.talosintelligence.com/2019/11/hunting-for-lolbins.html

https://www.microsoft.com/security/blog/2021/03/09/azure-lolbins-protecting-against-the-dual-use-of-virtual-machine-extensions/

https://www.darkreading.com/edge-articles/is-an-attacker-living-off-your-land-

https://www.cybereason.com/blog/threat-hunting-from-lolbins-to-your-crown-jewels

https://pentera.io/blog/the-lol-isnt-so-funny-when-it-bites-you-in-the-bas/

https://www.darkreading.com/vulnerabilities-threats/as-lotl-attacks-evolve-so-must-defenses

https://otx.alienvault.com/browse/pulses?q=tag:lolbin



LONGWATCH (category:
Malware)


type: Keylogger

(FireEye) LONGWATCH is a keylogger that outputs keystrokes to a log.txt file in
the Window’s temp folder.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=36ffdcb2-4db7-4c77-8363-a9ba62782874

https://www.fireeye.com/blog/threat-research/2019/07/hard-pass-declining-apt34-invite-to-join-their-professional-network.html

https://malpedia.caad.fkie.fraunhofer.de/details/win.longwatch

https://otx.alienvault.com/browse/pulses?q=tag:LONGWATCH



Mimikatz (category:
Tools)


type: Credential stealer, Keylogger

(SANS) Mimikatz provides a wealth of tools for collecting and making use of
Windows credentials on target systems, including retrieval of cleartext
passwords, Lan Manager hashes, and NTLM hashes, certificates, and Kerberos
tickets. The tools run with varying success on all versions of Windows from XP
forward, with functionality somewhat limited in Windows 8.1 and later.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=8f0da519-c1bc-4add-9e04-2c429e74564f

https://github.com/gentilkiwi/mimikatz

https://www.sans.org/reading-room/whitepapers/intrusion/mimikatz-overview-defenses-detection-36780

https://www.wired.com/story/how-mimikatz-became-go-to-hacker-tool/

https://www.crowdstrike.com/blog/credential-theft-mimikatz-techniques/

https://attack.mitre.org/software/S0002/

https://malpedia.caad.fkie.fraunhofer.de/details/win.mimikatz

https://otx.alienvault.com/browse/pulses?q=tag:mimikatz



MrPerfectInstaller (category:
Malware)


type: Dropper

(Trend Micro) We found the initial stage .Net dropper malware called
MrPerfectInstaller (detected by Trend Micro as Trojan.MSIL.REDCAP.AD)
responsible for dropping four different files, with each component stored in a
Base64 buffer inside the main dropper.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=17e41087-8373-41d9-a862-8ef0512f2430

https://www.trendmicro.com/en_us/research/23/b/new-apt34-malware-targets-the-middle-east.html





Nautilus (category:
Malware)


type: Backdoor

Nautilus is very similar to \'Neuron\' both in the targeting of mail servers and
how client communications are performed. This malware is referred to as
Nautilus due to its embedded internal DLL name “nautilus-service.dll”, again
sharing some resemblance to Neuron. The Nautilus service listens for HTTP
requests from clients to process tasking requests such as executing commands,
deleting files and writing files to disk.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=20eaa3cf-8388-4a2e-b11b-cdee9413d8d1

https://threatpost.com/turla-compromises-iranian-apt/149375/

https://malpedia.caad.fkie.fraunhofer.de/details/win.nautilus



Neuron (category:
Malware)


type: Backdoor

Neuron consists of both client and server components. The Neuron client and
Neuron service are written using the .NET framework with some codebase
overlaps. The Neuron client is used to infect victim endpoints and extract
sensitive information from local client machines. The Neuron server is used to
infect network infrastructure such as mail and web servers, and acts as local
Command & Control (C2) for the client component. Establishing a local C2
limits interaction with the target network and remote hosts. It also reduces
the log footprint of actor infrastructure and enables client interaction to
appear more convincing as the traffic is contained within the target network.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=a74ca4f9-33e7-4e5b-80d9-a4accb4368d8

https://threatpost.com/turla-compromises-iranian-apt/149375/

https://www.ncsc.gov.uk/alerts/turla-group-malware

https://malpedia.caad.fkie.fraunhofer.de/details/win.neuron



OilRig (category:
Malware)


No description available yet.



https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=b57f8320-e9e2-44c7-8b3a-14dbe3d31068

https://unit42.paloaltonetworks.com/behind-the-scenes-with-oilrig/

https://malpedia.caad.fkie.fraunhofer.de/details/ps1.oilrig





OopsIE (category:
Malware)


type: Backdoor, Exfiltration

OopsIE is a Trojan used by OilRig to remotely execute commands as well as
upload/download files to/from victims.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=b0820673-b28c-4fb1-a26f-bb9fea1ea231

https://unit42.paloaltonetworks.com/unit42-oopsie-oilrig-uses-threedollars-deliver-new-trojan/

https://attack.mitre.org/software/S0264/

https://malpedia.caad.fkie.fraunhofer.de/details/win.oopsie

https://otx.alienvault.com/browse/pulses?q=tag:OopsIE





PICKPOCKET (category:
Malware)


type: Credential stealer

(FireEye) PICKPOCKET is a credential theft tool that dumps the user\'s website
login credentials from Chrome, Firefox, and Internet Explorer to a file. This
tool was previously observed during a Mandiant incident response in 2018 and,
to date, solely utilized by APT34.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=ed5c6d95-e050-478f-b2d5-b7b2726a900c

https://www.fireeye.com/blog/threat-research/2019/07/hard-pass-declining-apt34-invite-to-join-their-professional-network.html

https://malpedia.caad.fkie.fraunhofer.de/details/win.pickpocket

https://otx.alienvault.com/browse/pulses?q=tag:PICKPOCKET



Plink (category:
Tools)


type: Tunneling



(FireEye) A common utility used to tunnel RDP sessions is PuTTY Link, commonly
known as Plink. Plink can be used to establish secure shell (SSH) network
connections to other systems using arbitrary source and destination ports.
Since many IT environments either do not perform protocol inspection or do not
block SSH communications outbound from their network, attackers such as FIN8
have used Plink to create encrypted tunnels that allow RDP ports on infected
systems to communicate back to the attacker command and control (C2) server.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=598b6f11-cd88-4ce8-8179-ad644c424419

https://www.fireeye.com/blog/threat-research/2019/01/bypassing-network-restrictions-through-rdp-tunneling.html

https://otx.alienvault.com/browse/pulses?q=tag:plink





POWBAT (category:
Malware)


type: Info stealer, Exfiltration, Tunneling

(FireEye) After the macro successfully creates the scheduled task, the dropped
VBScript, update.vbs (Figure 5), will be launched every three minutes. This
VBScript performs the following operations: 1. Leverages PowerShell to download
content from the URI hxxp://go0gIe[.]com/sysupdate.aspx?req=xxx\\dwn&m=d and
saves it in the directory %PUBLIC%\\Libraries\\dn. 2. Uses PowerShell to download
a BAT file from the URI hxxp://go0gIe[.]com/sysupdate.aspx?req=xxx\\bat&m=d
and saves it in the directory %PUBLIC%\\Libraries\\dn. 3. Executes the BAT file
and stores the results in a file in the path %PUBLIC%\\Libraries\\up. 4. Uploads
this file to the server by sending an HTTP POST request to the URI
hxxp://go0gIe[.]com/sysupdate.aspx?req=xxx\\upl&m=u. 5. Finally, it executes
the PowerShell script dns.ps1, which is used for the purpose of data
exfiltration using DNS.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=e87032a7-d42b-4d9b-a20e-9380e1c51cd7

https://www.fireeye.com/blog/threat-research/2016/05/targeted_attacksaga.html

https://www.fireeye.com/blog/threat-research/2017/12/targeted-attack-in-middle-east-by-apt34.html



PowerExchange (category:
Malware)


type: Backdoor

(Symantec) PowerShell-based malware that can log into an Exchange Server with
hardcoded credentials and monitor for emails sent by the attackers. It uses an
Exchange Server as a C&C. Mails received with \'@@\' in the subject contain
commands sent from the attackers which allows them to execute arbitrary
PowerShell commands, write files and steal files. The malware creates an
Exchange rule (called ‘defaultexchangerules’) to filter these messages and move
them to the Deleted Items folder automatically.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=0762792c-0150-4a3c-965d-c3e6d5f23ff1

https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/crambus-middle-east-government



POWRUNER (category:
Malware)


type: Backdoo

(FireEye) POWRUNER is a PowerShell script that sends and receives commands to
and from the C2 server.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=15f8edbf-1649-4f14-af27-8252da45f845

https://www.fireeye.com/blog/threat-research/2017/12/targeted-attack-in-middle-east-by-apt34.html

https://www.boozallen.com/s/insight/blog/dark-labs-discovers-apt34-malware-variants.html

https://attack.mitre.org/software/S0184/

https://malpedia.caad.fkie.fraunhofer.de/details/ps1.powruner

https://otx.alienvault.com/browse/pulses?q=tag:powruner



PsList (category:
Tools)


Utility for viewing a list of processes currently running in the operating
system. Part of \'SysInternals\' Tools.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=abf14046-7e05-4ae5-9ad3-3ece6228d025

https://technet.microsoft.com/ru-ru/sysinternals/pslist.aspx



QUADAGENT (category:
Malware)


type: Backdoor, Tunneling

(Palo Alto) Once the QUADAGENT payload has executed, it will use rdppath[.]com
as the C2, first via HTTPS, then HTTP, then via DNS tunneling, each being used
as a corresponding fallback channel if the former fails.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=0951e35a-f91b-43e8-936a-e6b6f1439555

https://unit42.paloaltonetworks.com/unit42-oilrig-targets-technology-service-provider-government-agency-quadagent/

https://attack.mitre.org/software/S0269/

https://malpedia.caad.fkie.fraunhofer.de/details/ps1.quadagent

https://otx.alienvault.com/browse/pulses?q=tag:QUADAGENT



RDAT (category:
Malware)


type: Backdoor, Tunneling

(Palo Alto) The adversaries compiled the RDAT payloads used in the attacks on
the Middle Eastern telecommunications organization on March 1, 2020, and
configured it to use a domain provided on the command line or the hardcoded
domain rsshay[.]com as its C2 server. Unlike previous RDAT samples, this
particular sample only uses DNS tunneling for its C2 communications with no
HTTP fallback channel. This RDAT sample can only use TXT queries in its DNS
tunnel.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=52268b11-5917-4022-a87a-3cb14973ccb0

https://unit42.paloaltonetworks.com/oilrig-novel-c2-channel-steganography/

https://go.crowdstrike.com/rs/281-OBQ-266/images/Report2020OverWatchNowheretoHide.pdf

https://attack.mitre.org/software/S0495/

https://malpedia.caad.fkie.fraunhofer.de/details/win.rdat

https://otx.alienvault.com/browse/pulses?q=tag:rdat



RGDoor (category:
Malware)


type: Backdoor, Info stealer

RGDoor is a malicious Internet Information Services (IIS) backdoor developed in
the C++ language. RGDoor has been seen deployed on webservers belonging to the
Middle East government organizations. RGDoor provides backdoor access to
compromised IIS servers.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=260ce10a-405e-4723-a836-5430dcf54336

https://unit42.paloaltonetworks.com/unit42-oilrig-uses-rgdoor-iis-backdoor-targets-middle-east/

https://researchcenter.paloaltonetworks.com/2017/09/unit42-striking-oil-closer-look-adversary-infrastructure/

https://attack.mitre.org/software/S0258/

https://malpedia.caad.fkie.fraunhofer.de/details/win.rgdoor



Saitama (category:
Malware)


type: Backdoor

(Malwarebytes) Saitama backdoor abuses the DNS protocol for its command and
control communications. This is stealthier than other communication methods,
such as HTTP. Also, the actor cleverly uses techniques such as compression and
long random sleep times. They employed these tricks to disguise malicious
traffic in between legitimate traffic.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=c6b4335f-c2fe-4109-971f-12c06e9ec7ef

https://blog.malwarebytes.com/threat-intelligence/2022/05/apt34-targets-jordan-government-using-new-saitama-backdoor/

https://malpedia.caad.fkie.fraunhofer.de/details/win.saitama





SideTwist (category:
Malware)


type: Backdoor, Downloader, Exfiltration

(Check Point) The backdoor in this stage, is a variant we haven’t seen before
in previous APT34 operations, but provides functionality which is simple and
similar to other C based backdoors utilized by the group: \'DNSpionage\' and
\'TONEDEAF\' and \'TONEDEAF 2.0\'. The functionality of the backdoor includes
download, upload and shell command execution.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=0bd63c8b-6c80-46dc-8af6-8dfe4072b37a

https://research.checkpoint.com/2021/irans-apt34-returns-with-an-updated-arsenal/

https://nsfocusglobal.com/apt34-unleashes-new-wave-of-phishing-attack-with-variant-of-sidetwist-trojan/

https://www.trendmicro.com/en_fi/research/23/i/apt34-deploys-phishing-attack-with-new-malware.html

https://attack.mitre.org/software/S0610/

https://malpedia.caad.fkie.fraunhofer.de/details/win.sidetwist



SpyNote
RAT
(category: Malware)


type: Backdoor, Info stealer, Exfiltration

SpyNote RAT (Remote Access Trojan) is a family of malicious Android apps. The
SpyNote RAT builder tool can be used to develop malicious apps with the
malware\'s functionality.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=f6df192b-ad71-4097-b372-0edf8a586d50

https://threatpost.com/new-trojan-spynote-installs-backdoor-on-android-devices/119560/

https://www.zscaler.com/blogs/research/spynote-rat-posing-netflix-app

https://www.cleafy.com/cleafy-labs/spynote-continues-to-attack-financial-institutions

https://blog.f-secure.com/take-a-note-of-spynote/

https://www.bleepingcomputer.com/news/security/spynote-android-malware-spreads-via-fake-volcano-eruption-alerts/

https://www.fortinet.com/blog/threat-research/android-spynote-moves-to-crypto-currencies

https://www.cyfirma.com/research/spynote-unmasking-a-sophisticated-android-malware/

https://attack.mitre.org/software/S0305/

https://malpedia.caad.fkie.fraunhofer.de/details/apk.spynote

https://otx.alienvault.com/browse/pulses?q=tag:spynote



StoneDrill (category:
Malware)


type: Wiper

StoneDrill is wiper malware discovered in destructive campaigns against both
Middle Eastern and European targets in association with APT33.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=3fbd9978-1421-4d34-9a4e-507fd1880629

https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2018/03/07180722/Report_Shamoon_StoneDrill_final.pdf

https://www.fireeye.com/blog/threat-research/2017/09/apt33-insights-into-iranian-cyber-espionage.html

https://www.megabeets.net/decrypting-dropshot-with-radare2-and-cutter-part-1/

https://www.megabeets.net/decrypting-dropshot-with-radare2-and-cutter-part-2/

https://attack.mitre.org/software/S0380/

https://malpedia.caad.fkie.fraunhofer.de/details/win.stonedrill

https://malpedia.caad.fkie.fraunhofer.de/details/win.dropshot

https://otx.alienvault.com/browse/pulses?q=tag:stonedrill



ThreeDollars (category:
Malware)


type: Dropper

This is a so-called delivery document. (Palo Alto) Ultimately, the payload
delivered by ThreeDollars is a new tool that we track as \'ISMInjector\'.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=1cd821a4-0679-4292-929b-6a0ed74e0de9

https://unit42.paloaltonetworks.com/unit42-oilrig-group-steps-attacks-new-delivery-documents-new-injector-trojan/



TONEDEAF (category:
Malware)


type: Reconnaissance, Backdoor, Tunneling, Info stealer, Exfiltration

(FireEye) TONEDEAF is a backdoor that communicates with Command and Control
servers using HTTP or DNS. Supported commands include system information
collection, file upload, file download, and arbitrary shell command execution.
Although this backdoor was coded to be able to communicate with DNS requests to
the hard-coded Command and Control server, c[.]cdn-edge-akamai[.]com, it was
not configured to use this functionality.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=fe0cfb06-ded6-4220-90c8-038cb2e88126

https://www.fireeye.com/blog/threat-research/2019/07/hard-pass-declining-apt34-invite-to-join-their-professional-network.html

https://malpedia.caad.fkie.fraunhofer.de/details/win.tonedeaf

https://otx.alienvault.com/browse/pulses?q=tag:TONEDEAF



TONEDEAF
2.0
(category: Malware)


type: Reconnaissance, Backdoor, Tunneling, Info stealer, Exfiltration

(Intezer) At first glance, “Client update.exe” seems like a completely new
backdoor malware. However, further examination reveals it’s most likely a
highly modified version of the previously seen \'TONEDEAF\' backdoor. TONEDEAF is
a backdoor that communicates with its Command and Control server via HTTP in
order to receive and execute commands. It was mentioned in FireEye’s recent
report about an ongoing APT34 operation, as one of the group’s custom tools. We
have named the new variant TONEDEAF 2.0. TONEDEAF 2.0 is an advanced version of
TONEDEAF, serving the same purpose as the original, but with a revamped C2
communication protocol and a substantially modified code base. In contrast to
the original TONEDEAF, TONEDEAF 2.0 contains solely arbitrary shell execution
capabilities, and doesn’t support any predefined commands. It’s also more
stealthy and contains new tricks such as dynamic importing, string decoding,
and a victim deception method.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=23cf2c05-faff-48b6-91af-4fc9158edbec

https://intezer.com/blog/apt/new-iranian-campaign-tailored-to-us-companies-uses-updated-toolset/



TwoFace (category:
Malware)


type: Backdoor, Info stealer, Exfiltration

According to Unit42, TwoFace is a two-staged (loader+payload) webshell, written
in C# and meant to run on webservers with ASP.NET. The author of the initial
loader webshell included legitimate and expected content that will be displayed
if a visitor accesses the shell in a browser, likely to remain undetected. The
code in the loader webshell includes obfuscated variable names and the embedded
payload is encoded and encrypted. To interact with the loader webshell, the
threat actor uses HTTP POST requests to the compromised server. The secondary
webshell, which we call the payload, is embedded within the loader in encrypted
form and contains additional functionality that we will discuss in further
detail. When the threat actor wants to interact with the remote server, they
provide data that the loader will use to modify a decryption key embedded
within the loader that will be in turn used to decrypt the embedded TwoFace
payload. Commands supported by the payload are execution of programs, up-,
download and deletion of files and capability to manipulate MAC timestamps.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=f02989df-45bc-4162-ba5b-8617795ee749

https://unit42.paloaltonetworks.com/unit42-twoface-webshell-persistent-access-point-lateral-movement/

https://unit42.paloaltonetworks.com/unit42-oilrig-performs-tests-twoface-webshell/

https://www.zdnet.com/article/source-code-of-iranian-cyber-espionage-tools-leaked-on-telegram/

https://attack.mitre.org/software/S0185/



https://malpedia.caad.fkie.fraunhofer.de/details/asp.twoface



VALUEVAULT (category:
Malware)


type: Credential stealer

(Intezer) VALUEVAULT is a browser credential theft tool built in Golang,
discovered by FireEye in the aforementioned APT34 operation analysis.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=9d9e466c-fe14-4cab-93cf-73724d3d7539

https://intezer.com/blog/apt/new-iranian-campaign-tailored-to-us-companies-uses-updated-toolset/

https://malpedia.caad.fkie.fraunhofer.de/details/win.valuevault

https://otx.alienvault.com/browse/pulses?q=tag:VALUEVAULT



Webmask (category:
Malware)


type: Tunneling

A DNS tunneling tool (the main tool behind \'DNSpionage\') that was leaked when
OilRig themselves were breached in 2019.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=6f04995b-5e88-45d8-a817-9a1f74cfd558

https://www.zdnet.com/article/source-code-of-iranian-cyber-espionage-tools-leaked-on-telegram/



WinRAR (category:
Tools)


type: Compression

WinRAR is a data compression tool for Windows that focuses on RAR and ZIP
files. It also supports CAB, ARJ, LZH, TAR, Gzip, UUE, ISO, BZIP2, Z and 7-Zip.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=92f5812c-9f8a-4fcc-88cf-62308fc8fc0a

https://www.win-rar.com/



ZeroCleare (category:
Malware)


type: Wiper

(IBM) New malware from the wiper class, used in a destructive attack in the
Middle East. We named this malware “ZeroCleare” per the program database (PDB)
pathname of its binary file.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=7d4138d7-655e-48a2-82b8-e4973ec045d4

https://securityintelligence.com/posts/new-destructive-wiper-zerocleare-targets-energy-sector-in-the-middle-east/

https://attack.mitre.org/software/S1151

https://malpedia.caad.fkie.fraunhofer.de/details/win.zerocleare

https://otx.alienvault.com/browse/pulses?q=tag:ZeroCleare



mso-ascii-theme-font:minor-latin;mso-fareast-font-family:Aptos;mso-fareast-theme-font:
minor-latin;mso-hansi-theme-font:minor-latin;mso-bidi-font-family:"Times New Roman";
mso-bidi-theme-font:minor-bidi;mso-ansi-language:EN-US;mso-fareast-language:
EN-US;mso-bidi-language:AR-SA\">Source: https://andreacristaldi.github.io/APTmap/


Comments
new comment
Nobody has commented yet. Will you be the first?


Primary Names
OilRig
 




This link is from a restricted area of the forums.
Forum



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.