{"id":4940,"date":"2024-08-20T04:00:00","date_gmt":"2024-08-20T09:00:00","guid":{"rendered":"https:\/\/www.darkreading.com\/threat-intelligence\/irgc-linked-hackers-package-modular-malware-into-monolithic-trojan"},"modified":"2024-08-20T04:00:00","modified_gmt":"2024-08-20T09:00:00","slug":"irgc-linked-hackers-package-modular-malware-in-monolithic-trojan","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/08\/20\/irgc-linked-hackers-package-modular-malware-in-monolithic-trojan\/","title":{"rendered":"IRGC-Linked Hackers Package Modular Malware in Monolithic Trojan"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt5290ac90eca329c1\/66c3a95e1c62a67c1753fee9\/cybertrojanhorse1800_the_lightwriter_alamyjpg.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/irgc-linked-hackers-package-modular-malware-in-monolithic-trojan.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/irgc-linked-hackers-package-modular-malware-in-monolithic-trojan.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">A state-level Iranian APT is turning back the clock by consolidating its modular backdoor into a monolithic PowerShell Trojan.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Recently, TA453 (aka APT42, CharmingCypress, Mint Sandstorm, Phosphorus, Yellow Garuda), which overlaps broadly with <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/application-security\/irans-charming-kitten-israeli-exchange-servers\" rel=\"noopener\">Charming Kitten<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, executed a phishing attack against an Israeli rabbi. Masquerading as the research director of the Institute for the Study of War (ISW), the group engaged with the religious leader over email, inviting him to feature on a fake podcast.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">At the end of its infection chain, TA453 delivered its victim the newest in its line of modular PowerShell backdoors. This time, though, unlike in prior campaigns, the group bundled its entire malware package into a single script.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;This is the first time I have personally seen malware that&#8217;s been modular, in many different pieces, then consolidated into one piece,&#8221; says Josh Miller, threat researcher at Proofpoint, which published a blog about the case on Tuesday.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Single PowerShell Trojan\">Single PowerShell Trojan<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/modular-downloaders-could-pose-new-threat-for-enterprises\" rel=\"noopener\">Around a half decade ago<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, a major new trend spread among malware authors. Taking a page from legitimate software developers \u2014 who, at the time, were increasingly adopting microservices architectures in place of monolithic ones \u2014 bad guys began to design their malicious tools not as single files, but as frameworks with pluggable parts.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The flexibility of <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/modular-malware-brings-stealthy-attacks-to-former-soviet-states\" rel=\"noopener\">&#8220;modular&#8221; malware<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> offered a variety of benefits. Hackers could now more easily fine tune the same malware for different targets by simply adding and dropping components ad hoc, even after an infection had already taken place.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Modular malware is kind of neat, because I can start with just the core functionality,&#8221; says Steven Adair, founder of Volexity. &#8220;Then once I&#8217;ve validated the target machine is actually real and not a researcher&#8217;s sandbox system, I can push down additional tooling and functions.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Its newest backdoor, dubbed &#8220;AnvilEcho,&#8221; is a successor to the group&#8217;s previous espionage tools: GorjolEcho\/PowerStar, TAMECURL, MischiefTut, and CharmPower. The difference: rather than parts sold separately, all of AnvilEcho&#8217;s component parts come squished into a single PowerShell Trojan. Why?<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;You could have a backdoor that has literally every feature under the sun, but sometimes that may raise the size of the malware download, and it may be better detected,&#8221; Adair says. Besides taking up a smaller footprint, malware delivered in more disparate chunks can also confuse analysts who see only the trees, not the forest.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"A Malware Toss-Up\">A Malware Toss-Up<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">On the other hand, monolithic malware is simpler to deploy. And in the course of its attack on the Israeli rabbi, TA453 compensated for any resultant lack of secrecy in all kinds of other ways along its attack path.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;In the past,&#8221; Miller explains, &#8220;we&#8217;ve seen that after getting a response back from someone, TA453 just immediately sends an attachment which loads malware. Now they&#8217;re sending a ZIP file that has an LNK inside of it, that then deploys all of these additional stages too. It seems almost unnecessarily complicated in some ways.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">He adds that, this time, &#8220;It wasn&#8217;t deployed until they&#8217;d already known that the target was engaging with them, and willing to click on links and download stuff from file sharing websites and enter passwords into files. I think they had confidence that the malware would be run when delivered.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Ultimately, when it comes to bundling versus separating malware components, &#8220;There&#8217;s not necessarily a super pro or con to one or the other \u2014 both approaches work fine,&#8221; Adair says.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/threat-intelligence\/irgc-linked-hackers-package-modular-malware-into-monolithic-trojan\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A state-level Iranian APT is turning back the clock by<\/p>\n","protected":false},"author":12,"featured_media":4941,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-4940","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/irgc-linked-hackers-package-modular-malware-in-monolithic-trojan-scaled.jpg?fit=2560%2C1440&ssl=1",2560,1440,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/irgc-linked-hackers-package-modular-malware-in-monolithic-trojan-scaled.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/irgc-linked-hackers-package-modular-malware-in-monolithic-trojan-scaled.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/irgc-linked-hackers-package-modular-malware-in-monolithic-trojan-scaled.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/irgc-linked-hackers-package-modular-malware-in-monolithic-trojan-scaled.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/irgc-linked-hackers-package-modular-malware-in-monolithic-trojan-scaled.jpg?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/irgc-linked-hackers-package-modular-malware-in-monolithic-trojan-scaled.jpg?fit=2048%2C1152&ssl=1",2048,1152,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/irgc-linked-hackers-package-modular-malware-in-monolithic-trojan-scaled.jpg?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/irgc-linked-hackers-package-modular-malware-in-monolithic-trojan-scaled.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/irgc-linked-hackers-package-modular-malware-in-monolithic-trojan-scaled.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/irgc-linked-hackers-package-modular-malware-in-monolithic-trojan-scaled.jpg?fit=2560%2C1440&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4940","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=4940"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4940\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/4941"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=4940"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=4940"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=4940"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}