National Cyber Warfare Foundation (NCWF)

Nazar


0 user ratings
2024-07-26 20:09:37
blscott

 - archive -- 

"Helvetica",sans-serif\\"\">This actor was identified by Juan Andres Guerrero-Saade\\
from the SIG37 cluster as published in the ShadowBrokers\\\' \\\'Lost in Translation\\\'\\
leak. Earliest known sighting potentially dates back to as far as 2008 with a\\
confirmed center of activity around 2010-2013. The actor name is derived from a\\
PDB debug string fragment: \\\'khzer\\\'. Victimology indicates targeting of Iran,\\
assessed with low confidence based on VT file submission locations. Nazar\\
employs a modular toolkit where a main dropper silently registers multiple DLLs\\
as OLE controls in the Windows registry. 

"Helvetica",sans-serif\\"\">Functionality includes keylogging,\\
sound and screen grabbing, as well as traffic capture using the MicroOlap\\
Packet Sniffer library. (Epic Turla) It’s hard to understand the scope of this\\
operation without access to victimology (e.g.: endpoint visibility or\\
command-and-control sinkholing). Additionally, some possible timestomping\\
muddies the water between this operation possible originating in 2008-2009 or\\
actually coming into full force in 2010-2013 (the latter dates being\\
corroborated by VT firstseen submission times and second-stage drop\\
timestamps). 

"Helvetica",sans-serif\\"\">There’s a level of variable developmental capability visible\\
throughout the stages. Multiple components are abused commonly-available\\
resources, while the orchestrator and two of the DLL drops actually display\\
some developmental ingenuity (in the form of seemingly novel COM techniques).\\
Far from the most advanced coding practices but definitely better than the sort\\
of .NET garbage other ‘Farsi-speaking’ APTs have gotten away with in the past.\\
Somehow, this operation found its way onto the NSA’s radar pre-2013. As far as\\
I can tell, it’s eluded specific coverage from the security industry. A\\
possible scenario to account for the disparate visibility between the NSA and\\
Western researchers when it comes to this cluster of activity is that these\\
samples were exclusively encountered on Iranian boxes overlapping with EQGRP\\
implants. 

"Helvetica",sans-serif\\"\">Submissions of Nazar subcomponents from Iran (as well as privately\\
shared visibility into historical and ongoing victimology clustered entirely on\\
Iranian machines) could support that theory. Perhaps this is an internal\\
monitoring framework (a la Attor) but given the sparse availability of\\
historical data, I wouldn’t push that beyond a low-confidence assessment, at\\
this time.

"Helvetica",sans-serif\\"\">Alternate Group Names
SIG37

\\
\\

"Helvetica",sans-serif\\"\">First Seen- 2008

\\
\\

"Helvetica",sans-serif\\"\">Tools:

\\
\\
mso-fareast-font-family:Aptos;mso-fareast-theme-font:minor-latin;mso-ansi-language:\\
EN-US;mso-fareast-language:EN-US;mso-bidi-language:AR-SA\\"\">Distribute.exe (category:\\
Malware)

\\
type: Loader
\\
(Epic Turla) The Zip2Secure configuration entrusts the distribution of the\\
files contained therein to ‘Distribute.exe’, which places the files and\\
silently registers the subcomponents with regsvr32.exe.
\\
https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=97403e0a-2161-4115-8075-00ab7fb16258
\\
https://www.epicturla.com/blog/the-lost-nazar
\\

\\

\\
EYService (category:\\
Malware)

\\
type: Backdoor
\\
(Epic Turla) The main functionality orchestrating the different subcomponents\\
is contained within Data.bin, later renamed to ‘svchost.exe’. The orchestrator\\
takes 17 different three digit codes to divert functionality within a giant\\
switch statement. Some of the codes have not been fully implemented up to the\\
latest samples I’ve found so far, which further suggests a continued\\
developmental effort.
\\
https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=d1357aaf-4d8d-4164-a083-7c706e00fcbe
\\
https://www.epicturla.com/blog/the-lost-nazar
\\
https://blog.malwarelab.pl/posts/nazar_eyservice/
\\
https://research.checkpoint.com/2020/nazar-spirits-of-the-past/
\\
https://malpedia.caad.fkie.fraunhofer.de/details/win.eyservice
\\

\\

\\
GpUpdates.exe (category:\\
Malware)

\\
type: Dropper
\\
(Epic Turla) The droppers are misidentified as packed by Armadillo but in\\
reality they’re built using now defunct Chilkat software, ‘Zip2Secure’ to\\
create self-extracting executables. The packing alone has led the droppers to\\
be detected under generic AV detections but the subcomponents have low-to-no\\
detections at this time. The Zip2Secure configuration entrusts the distribution\\
of the files contained therein to ‘\\\'Distribute.exe\\\'’, which places the files\\
and silently registers the subcomponents with regsvr32.exe.
\\
https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=2d1ee7a1-0d40-43c8-a24a-d1d903daaeb6
\\
https://www.epicturla.com/blog/the-lost-nazar
\\

\\

\\
Microolap\\
Packet Sniffer (category: Tools)

\\
type: Info stealer
\\
TCPDUMP for Windows® is a clone of TCPDUMP, the most used network\\
sniffer/analyzer for UNIX, compiled with the original tcpdump code\\
(tcpdump.org), and our own packet capture technology Microolap Packet Sniffer\\
SDK (no libpcap/WinPcap/npcap).
\\
https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=496b6627-15e0-4d80-b23b-48aaca89aaf8
\\
https://www.microolap.com/products/network/tcpdump/





Comments
new comment
Nobody has commented yet. Will you be the first?
 




This link is from a restricted area of the forums.
Forum



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.