Skip to main content

Kaspersky reveals final stage malware chain in campaign targeting industrial companies

August 10, 2023

Woburn, MA – August 10, 2023 – Today Kaspersky's ICS CERT released the concluding segment of its research series looking into recent attacks on industrial organizations in Eastern Europe. The new report investigates third-stage malware, designed for the uploading of files to Dropbox and to also coordinate with other malware implants to exfiltrate data.

The third-stage data exfiltration activity involves a three-step malware execution chain. First, the execution chain establishes persistence and orchestrates the deployment and initiation of the second-step malware module. This module is responsible for uploading collected files to a remote server with the help of the third-step module. The intricate architecture allows the threat actor to recalibrate the execution flow by replacing individual modules within the chain. In some cases, the chain could be used for data exfiltration from network segments isolated from the internet by setting up an intermediate/proxy storage for the stolen data inside the victims’ network.

Within this campaign, the threat actor deployed a malware chain to access Outlook mailbox files, execute remote commands, and perform the uploading of local or remote ".rar" files to Dropbox.

Additionally, the investigation highlights the use of tools for manual data transfer. One tool is specifically designed for moving files to and from Yandex Disk, while another allows for easy file uploads to 16 temporary file-sharing services. The third one, being downloaded from Yandex Disk, had the functionality to send the implant chain execution log data to Yandex mail accounts.

These insights provide a glimpse into the threat actor’s intricate data exfiltration techniques.

“Our comprehensive analysis underscores the adaptability of threat actors in their pursuit of sensitive data,” said Kirill Kruglov, senior security researcher at Kaspersky ICS CERT. “By unraveling the mechanics of these advanced implants, we provide the cybersecurity community with crucial knowledge to fortify defenses against increasingly sophisticated attacks.”

To read the full report on the third-stage of the campaign, visit ICS CERT website.

To keep your OT computers protected from various threats, Kaspersky experts recommend:

·       Conducting regular security assessments on OT systems to identify and eliminate possible cyber security issues.

·       Establishing a continuous vulnerability assessment and triage system as a basis for an effective vulnerability management process. Dedicated solutions like Kaspersky Industrial CyberSecurity may become an efficient assistant and a source of unique actionable information, not fully available in public.

·       Performing timely updates for the key components of the enterprise’s OT network; applying security fixes and patches or implementing compensating measures as soon as it is technically possible is crucial for preventing a major incident that might cost millions due to the interruption of the production process.

·       Using integrated attack detection and prevention solutions such as Kaspersky Industrial CyberSecurity for timely detection and prevention of sophisticated threats, investigation, and effective remediation of incidents.

·       Improving the response to new and advanced malicious techniques by building and strengthening your teams’ incident prevention, detection, and response skills. Dedicated OT security training for IT security teams and OT personnel is one of the key measures that can help achieve this.

 

About Kaspersky

Kaspersky is a global cybersecurity and digital privacy company founded in 1997. Kaspersky’s deep threat intelligence and security expertise is constantly transforming into innovative solutions and services to protect businesses, critical infrastructure, governments and consumers around the globe. The company’s comprehensive security portfolio includes leading endpoint protection, specialized security products and services, as well as Cyber Immune solutions to fight sophisticated and evolving digital threats. Over 400 million users are protected by Kaspersky technologies and we help over 220,000 corporate clients protect what matters most to them. Learn more at usa.kaspersky.com.

Media Contact

Sawyer Van Horn

sawyer.vanhorn@Kaspersky.com

(781) 503-1866

Kaspersky reveals final stage malware chain in campaign targeting industrial companies

Kaspersky logo

About Kaspersky

Kaspersky is a global cybersecurity and digital privacy company founded in 1997. With over a billion devices protected to date from emerging cyberthreats and targeted attacks, Kaspersky’s deep threat intelligence and security expertise is constantly transforming into innovative solutions and services to protect individuals, businesses, critical infrastructure, and governments around the globe. The company’s comprehensive security portfolio includes leading digital life protection for personal devices, specialized security products and services for companies, as well as Cyber Immune solutions to fight sophisticated and evolving digital threats. We help millions of individuals and nearly 200,000 corporate clients protect what matters most to them. Learn more at www.kaspersky.com.

Related Articles Press Releases