Hellhounds remains one of the most advanced groups attacking companies within Russia
More in Threat actors
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- We will croc you
We will croc you 👻 PhantomCore continues to actively exploit misconfigurations in 1C to attack Russian…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- ⚡Fake news — THAT'S ALL
⚡Fake news — B U L L S H I T PT ESC specialists discovered an…
🫡 Hellhounds remains one of the most advanced groups attacking companies in Russia
We have already covered Hellhounds’ activity in the articles “Operation Lahat” and “Operation Lahat. Part 2“.
During the investigation of an incident at an IT company, an attentive administrator noticed a process on one of the production servers that was connecting to an IP address uncharacteristic for the infrastructure — 185.104.106.147.
udevd 24429 root 9u IPv4 1081871629 0t0 TCP example.com:15777->185.104.106.147:9443 (ESTABLISHED)
A cursory analysis of the artifacts on the host and of the process itself from userspace yielded no results, after which it was decided to additionally request a RAM dump.
To capture the dump, we chose the AVML utility, and for analysis — the linux.malfind.Malfind, linux.proc.Maps, and linux.pslist.PsList modules. We were able to detect memory regions that have code execution permissions, are not mapped to a specific file in the system, and contain an executable ELF file.
DEBUG
volatility3.plugins.linux.malfind: Injections : processing PID 24429 : VMA Anonymous Mapping : 0x55cc7566b000-0x55cc75685000
24429 udevd 0x55cc7566b000 0x55cc75685000 r-x
7f 45 4c 46 02 01 01 00 .ELF....
The udevd process is probably legitimate, but its memory area had been overwritten and contained Decoy Dog code (Pupy RAT). At the time of analysis, there were no persistence mechanisms or backdoor files themselves in the file system. Thus, Decoy Dog operated only in RAM.
In the new version, the attackers added the dumbexec scriptlet — a simplest shell listening on port 39339.
In addition, in one of the configuration files, the attackers used port 31337, which is another nod to eleet:
{'debug': False, 'launcher': 'bind', 'launcher_args': ['-t', 'rsa', '0.0.0.0:31337'], 'delays': [(10, 5, 10), (50, 30, 50), (-1, 150, 300)]...
It is also interesting that for domain generation (DGA), not only DDNS services are used, but also the .info top-level domain. A new launcher, l4beacon, is used, which disguises traffic as UDP (or as TCP, ICMP):
{'debug': False, 'launcher': 'l4beacon', 'launcher_args': ['-p', '161', '-s', 'udp', '--domain', [REDACTED], '-E', 'zzux.com,mooo.com,info'], 'delays': [(10, 5, 10), (50, 30, 50), (-1, 150, 300)]}
In addition, the new version introduced encryption of the configuration containing network interaction parameters, keys, and certificates:
{'debug': False, 'cid': [REDACTED], 'bound': True, 'data': [REDACTED], 'tmpk': b'gFwpC9rCRmSNjHmvjs+3kB4HD22LGmFgs1BSSvc68fzMQiPcNXchPWYEpjQMYB56'}
If the bound flag is set, then data contains the rest of the configuration, encrypted with the ChaCha20 cryptographic algorithm, and the key is generated based on the system identifier.
In addition, a tmpk key has appeared, which is used to encrypt system data sent by the telemetry scriptlet. Previously, the same key was used for this, with which the dynamic configuration file was decrypted.
YARA rule:
rule PTESC_apt_mem_ZZ_DecoyDog__Backdoor{
strings:
$p1 = "pupy://"
$p2 = "--pass-args"
$p3 = "LZMA error"
$p4 = "/__init__.pyo"
$pupy = "pupy"
condition:
all of ($p*) and #pupy >= 2
}
IoCs:
185.104.106.147:9443
0.0.0.0:31337
0.0.0.0:39339
mindly.social
*.zzux.com (DGA)
*.mooo.com (DGA)
#hunt #detect #dfir #hellhounds
@ptescalator
More in Threat actors
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- We will croc you
We will croc you 👻 PhantomCore continues to actively exploit misconfigurations in 1C to attack Russian…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- ⚡Fake news — THAT'S ALL
⚡Fake news — B U L L S H I T PT ESC specialists discovered an…






