[ << ALL_FEED ]

Hellhounds remains one of the most advanced groups attacking companies within Russia

More in Threat actors

🫡 Hellhounds remains one of the most advanced groups attacking companies in Russia

We have already covered Hellhounds’ activity in the articles “Operation Lahat” and “Operation Lahat. Part 2“.

During the investigation of an incident at an IT company, an attentive administrator noticed a process on one of the production servers that was connecting to an IP address uncharacteristic for the infrastructure — 185.104.106.147.

udevd   24429 root    9u  IPv4         1081871629      0t0        TCP example.com:15777->185.104.106.147:9443 (ESTABLISHED)

A cursory analysis of the artifacts on the host and of the process itself from userspace yielded no results, after which it was decided to additionally request a RAM dump.

To capture the dump, we chose the AVML utility, and for analysis — the linux.malfind.Malfind, linux.proc.Maps, and linux.pslist.PsList modules. We were able to detect memory regions that have code execution permissions, are not mapped to a specific file in the system, and contain an executable ELF file.


DEBUG    
volatility3.plugins.linux.malfind: Injections : processing PID 24429 : VMA Anonymous Mapping : 0x55cc7566b000-0x55cc75685000

24429   udevd   0x55cc7566b000  0x55cc75685000  r-x
7f 45 4c 46 02 01 01 00 .ELF....

The udevd process is probably legitimate, but its memory area had been overwritten and contained Decoy Dog code (Pupy RAT). At the time of analysis, there were no persistence mechanisms or backdoor files themselves in the file system. Thus, Decoy Dog operated only in RAM.

In the new version, the attackers added the dumbexec scriptlet — a simplest shell listening on port 39339.

In addition, in one of the configuration files, the attackers used port 31337, which is another nod to eleet:


{'debug': False, 'launcher': 'bind', 'launcher_args': ['-t', 'rsa', '0.0.0.0:31337'], 'delays': [(10, 5, 10), (50, 30, 50), (-1, 150, 300)]...

It is also interesting that for domain generation (DGA), not only DDNS services are used, but also the .info top-level domain. A new launcher, l4beacon, is used, which disguises traffic as UDP (or as TCP, ICMP):


{'debug': False, 'launcher': 'l4beacon', 'launcher_args': ['-p', '161', '-s', 'udp', '--domain', [REDACTED], '-E', 'zzux.com,mooo.com,info'], 'delays': [(10, 5, 10), (50, 30, 50), (-1, 150, 300)]}

In addition, the new version introduced encryption of the configuration containing network interaction parameters, keys, and certificates:


{'debug': False, 'cid': [REDACTED], 'bound': True, 'data': [REDACTED], 'tmpk': b'gFwpC9rCRmSNjHmvjs+3kB4HD22LGmFgs1BSSvc68fzMQiPcNXchPWYEpjQMYB56'}

If the bound flag is set, then data contains the rest of the configuration, encrypted with the ChaCha20 cryptographic algorithm, and the key is generated based on the system identifier.

In addition, a tmpk key has appeared, which is used to encrypt system data sent by the telemetry scriptlet. Previously, the same key was used for this, with which the dynamic configuration file was decrypted.

YARA rule:


rule PTESC_apt_mem_ZZ_DecoyDog__Backdoor{
  strings:
      $p1 = "pupy://" 
      $p2 = "--pass-args"
      $p3 = "LZMA error"
      $p4 = "/__init__.pyo"
      $pupy = "pupy" 
  condition:
      all of ($p*) and #pupy >= 2
}

IoCs:


185.104.106.147:9443
0.0.0.0:31337
0.0.0.0:39339
mindly.social

*.zzux.com (DGA)
*.mooo.com (DGA)

#hunt #detect #dfir #hellhounds
@ptescalator

More from oUth0R

More from oUth0R

More in Threat actors