{"id":3669,"date":"2024-05-21T09:43:37","date_gmt":"2024-05-21T14:43:37","guid":{"rendered":"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/russia-turla-apt-msbuild-tinyturla-backdoor"},"modified":"2024-05-21T09:43:37","modified_gmt":"2024-05-21T14:43:37","slug":"russiaaposs-turla-apt-abuses-msbuild-to-deliver-tinyturla-backdoor","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/05\/21\/russiaaposs-turla-apt-abuses-msbuild-to-deliver-tinyturla-backdoor\/","title":{"rendered":"Russia&amp;apos;s Turla APT Abuses MSBuild to Deliver TinyTurla Backdoor"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/bltb14c0d2c67b918b0\/64f15ab30e69a0a7de8e33d6\/backdoor-agefotostock-alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/russiaaposs-turla-apt-abuses-msbuild-to-deliver-tinyturla-backdoor.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/russiaaposs-turla-apt-abuses-msbuild-to-deliver-tinyturla-backdoor.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">A Russia-linked advanced persistent threat (APT) group has been abusing PDF and MSBuild project files in a campaign that uses socially engineered emails to deliver the TinyTurla backdoor as a fileless payload. The campaign&#8217;s seamless delivery routine is a notable evolution in sophistication, researchers said.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Researchers from Cyble Researchers and Intelligence Labs (CRIL) identified the campaign, which uses emails with documents pitching invitations to human rights seminars or providing public advisories as a lure to infect users with TinyTurla. In <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/cyble.com\/blog\/tiny-backdoor-goes-undetected-suspected-turla-leveraging-msbuild-to-evade-detection\/\" rel=\"noopener\">a blog post<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> published yesterday on the campaign, they said the attackers also impersonate legitimate authorities in an effort to lure victims in.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;When targeted individuals mistakenly believe this to be a legitimate invitation or advisory and open it, they could inadvertently install a tiny backdoor into their system,&#8221; according to the post. Attackers then can use the backdoor to execute commands from a command-and-control (C2) server that they control and infiltrate the victim&#8217;s system.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The campaign \u2014 which targets individuals and entities in the Philippines \u2014 demonstrates attacker sophistication by embedding lure PDFs and <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/one-year-later-a-look-back-at-zerologon\" rel=\"noopener\">MSBuild project files<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> within .LNK files &#8220;for seamless execution,&#8221; according to CRIL. The attacker also &#8220;executes the project files using the Microsoft Build Engine (MSBuild) to deliver a stealthy, fileless final payload,&#8221; according to the post.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"The Likely Culprit: Turla APT\">The Likely Culprit: Turla APT<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The TinyTurla backdoor is linked to a long-running Russia-sponsored threat actor, <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/russia-turla-apt-hijacks-andromeda-usb-infections\" rel=\"noopener\">Turla,<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> that typically <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/russian-apt-turla-novel-backdoor-malware-polish-ngos\" rel=\"noopener\">targets NGOs<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, &#8220;particularly those with connections to supporting Ukraine,&#8221; the researchers noted. They believe the group is behind the malicious activity, according to the post.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Code observed by the researchers, the content of the emails, and other tactics also point to the APT. &#8220;The utilization of basic first-stage backdoor functionalities, coupled with the exploitation of compromised Web servers for their C2 infrastructure, aligns with the behavior exhibited by the Turla,&#8221; according to the post.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Turla also is known to deploy PHP-based C2s within specific directories of compromised websites, which is a behavior also observed in the campaign.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"From Spam Email to Backdoor Malware\">From Spam Email to Backdoor Malware<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">As mentioned, the campaign begins with spam emails that include a document either inviting someone to a human rights seminar or impersonating the Philippine Statistics Authority with a public advisory. The latter was discovered and <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/x.com\/k3yp0d\/status\/1788590090324754477\" rel=\"noopener\">shared<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> on the social-media platform X by security researcher Simon Kenin, according to CRIL.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">When a victim clicks on a document \u2014 which is actually a malicious .LNK file \u2014 it triggers the execution of a PowerShell script embedded within that kicks off a series of operations. These include reading the content of the .LNK file and writing it into three distinct files \u2014 a lure PDF, encrypted data, and a custom MSBuild project \u2014 in the %temp% location. The MSBuild project executes to open the lure document.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;This MSBuild project contains code to decrypt the encrypted data, which is then saved in a %temp% location with the .log extension,&#8221; according to the post. &#8220;Subsequently, this .log file, also an MSBuild project, is scheduled to be executed using &#8216;MSBuild.exe&#8217; through Task Scheduler to carry out backdoor activities.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">TinyTurla manages its operations by using multiple threads, each of which are designed to execute specific tasks. The &#8220;shell&#8221; enables the backdoor to execute commands on the victim&#8217;s machine by creating a new process to run the specified command within that process. The &#8220;sleep&#8221; operation allows attackers to dynamically adjust the sleep interval of the backdoor.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Other operations the backdoor executes are an &#8220;upload&#8221; operation that allows it to download a file from the C2 server and save it locally on the victim&#8217;s machine, and a &#8220;download&#8221; operation that can exfiltrate files from the victim&#8217;s machine to the C2 server.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;By coordinating these diverse operations, the backdoor functions as a versatile tool for [the threat actors],&#8221; according to the post. &#8220;It allows them to carry out subsequent malicious activities while avoiding detection and enhancing their control over compromised systems.&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Avoiding Compromise by Turla, Other APTs\">Avoiding Compromise by Turla, Other APTs<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Though the campaign&#8217;s impersonation of legitimate files and seamless deployment routine makes it difficult to detect, there are several ways defenders can avoid compromise, the researchers suggested.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">As the entry point of the campaign comes in the form of spam emails, deploying strong email-filtering systems can identify and prevent the dissemination of harmful attachments.&nbsp;Further, organizations should advise employees to exercise extreme caution when handling email attachments or links, particularly those from unknown senders.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Regarding the campaign&#8217;s abuse of MSBuild, organizations can limit the use of this tool to authorized personnel or specific systems, which will &#8220;reduce the risk of unauthorized usage by threat actors,&#8221; according to CRIL. Indeed, a Russia-based APT also abused this tool in the infamous <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/threat-intelligence\/critical-zerologon-flaw-exploited-in-ta505-attacks\" rel=\"noopener\">Zerologon campaign<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> several years ago.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Defenders also should consider disabling or limiting the execution of scripting languages, such as <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/ukraine-military-targeted-with-russian-apt-powershell-attack\" rel=\"noopener\">PowerShell<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, on user workstations and servers if they are not essential for legitimate purposes, researchers noted.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/russia-turla-apt-msbuild-tinyturla-backdoor\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A Russia-linked advanced persistent threat (APT) group has been abusing<\/p>\n","protected":false},"author":12,"featured_media":3670,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-3669","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/russiaaposs-turla-apt-abuses-msbuild-to-deliver-tinyturla-backdoor-scaled.jpg?fit=2560%2C1683&ssl=1",2560,1683,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/russiaaposs-turla-apt-abuses-msbuild-to-deliver-tinyturla-backdoor-scaled.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/russiaaposs-turla-apt-abuses-msbuild-to-deliver-tinyturla-backdoor-scaled.jpg?fit=300%2C197&ssl=1",300,197,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/russiaaposs-turla-apt-abuses-msbuild-to-deliver-tinyturla-backdoor-scaled.jpg?fit=640%2C421&ssl=1",640,421,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/russiaaposs-turla-apt-abuses-msbuild-to-deliver-tinyturla-backdoor-scaled.jpg?fit=640%2C421&ssl=1",640,421,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/russiaaposs-turla-apt-abuses-msbuild-to-deliver-tinyturla-backdoor-scaled.jpg?fit=1536%2C1010&ssl=1",1536,1010,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/russiaaposs-turla-apt-abuses-msbuild-to-deliver-tinyturla-backdoor-scaled.jpg?fit=2048%2C1347&ssl=1",2048,1347,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/russiaaposs-turla-apt-abuses-msbuild-to-deliver-tinyturla-backdoor-scaled.jpg?fit=1024%2C673&ssl=1",1024,673,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/russiaaposs-turla-apt-abuses-msbuild-to-deliver-tinyturla-backdoor-scaled.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/russiaaposs-turla-apt-abuses-msbuild-to-deliver-tinyturla-backdoor-scaled.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/russiaaposs-turla-apt-abuses-msbuild-to-deliver-tinyturla-backdoor-scaled.jpg?fit=2560%2C1683&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3669","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=3669"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3669\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/3670"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=3669"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=3669"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=3669"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}