[ << ALL_FEED ]

Attackers are looking for new ways to "open the gates"

More in General

⛩ Attackers are looking for new ways to “open the gates”

We recently discovered an unusual attack scheme. The attackers first establish contact with the victim, lull their vigilance by posing as an interested company, and after receiving a reply, send the target the malicious attachment they expect.

The urgency of opening the attachment is conveyed implicitly: for example, the sender is going on vacation and a commercial proposal needs to be prepared today, and to do that, the attachment must be opened.

The cybercriminals operate in a time zone between UTC−4 and UTC+4 and are fluent in Russian. It is evident that the text was typed manually, without a translator, which is why there is a typo in it.

👉 The choice of victim is also interesting. Import substitution is more relevant now than ever — there is a large number of requests to distributors of domestic software. Compromising such organizations can open a path to many other companies, including in critically important sectors, through trusted relationship attacks.

In this particular case, the attackers posed as the company “Industrial Automation” and used the domain promautomautic.ru. It differs from the real one by just a single letter and was registered shortly before the attack.

The email had an archive attached, Promautomatic.zip, which contains a DOCX document Kartochka_Promautomatic.docx (a company profile) and an executable file:

Scan_Promautomatic_P7_Office_241_06_13.06.2024_ann←fdp.exe

The file is the DarkGate backdoor, typically used to steal confidential information and gain remote access to a system. DarkGate is distributed under the malware-as-a-service model, which makes identifying the attackers difficult.

The attackers used the RTLO (Right-To-Left Override) control character to change the order of the last characters:

Scan_Promautomatic_P7_Office_241_06_13.06.2024_annexe.pdf

As a result, the victim gets the impression that this is a PDF document rather than an executable file.

IoCs:


promautomautic.ru
45.151.62.66
f81593ac3586e61eb9ee1b332eca2afc
5d586682ff20db587d991716dafa0b231ed7b2f8
f127c29f095f1771c6afc476e4b3adf3442d7f014f39cc47875226f651d64c92
35bd6ff114bbaeaa1b8f959e00042a33
00da82325086c940306d9df23fb8f8d09e044290
70afae352a5f8b2aaab952f2e702aac2fd0b4e38781f3a778b1756e67f779d54
Code language: plaintext (plaintext)

#TI #DarkGate #Phishing
@ptescalator

More from ti_author

More from ti_author

More in General