[ << ALL_FEED ]

Operation Chewbacca

More in General

At the end of June, the PT ESC team, during incident investigations, discovered a new group targeting at least oil and gas companies and the financial sector.

During attacks, the threat actors pursue destructive goals while maintaining a presence in the compromised infrastructure for a fairly long time.

For lateral movement within the infrastructure, they primarily use WinRM (usually in combination with WinRb) and SSH.

For persistence in the infrastructure, they mainly use server machines with high uptime (Windows\Linux); persistence is achieved via services in both cases. A wide range of tools is used as payloads:

  • Agents for the merlin framework.
  • An agent based on reverse_ssh.
  • The GoSocks5Proxy utility based on go-socks5.
  • ReverseProxy — a proprietary utility written in Rust.
  • The GoRinet backdoor. It uses config encryption with a key derived from the physical address of the network adapter.

🐻 Various software is used to carry out destructive actions, including some that, by a number of indications, was developed using AI.

  • The T-Riper wiper for network devices manufactured by Cisco/Huawei — deleting images, resetting device configuration, rebooting. They are used in combination with bash scripts for execution against remote targets.
  • A custom wiper for remotely deleting QNAP data.
  • To encrypt data on machines running Windows OS, a malware suite is used consisting of an orchestrator (with the ability to send encryption progress reports to a remote C2). Wiper generation is performed in a multithreaded manner, with individual executables created by adding “junk” to the overlay to evade detection. For automated propagation across the network, config files are used that specify known credentials from previously compromised accounts and target subnets.

The use of the CVE-2026-31431 vulnerability (CopyFail) for privilege escalation has also been noted, along with the custom tool CredsReseter for resetting passwords of Linux-like system accounts and Windows scripts for dumping credentials of third-party services.

Recommendations:

  • Search for and monitor indicators of compromise.
  • Perform signature scanning.
  • Update the OS.

IoCs

File indicators:

Name MD5 PT Fusion
acgid 9f7a688faf61d895a5c1d09084f16436 Open ↗
cf 4c5b89504269b1d73ee5b6449559da4b Open ↗
mnworker.exe a6d00278363e4916c4bc6ff6f36dfe6f Open ↗
NetConfigSvc.exe 56fd630da404d4d8c5afd17eb3506b41 Open ↗
NetSvcHelper.exe 272625644208beab5daa79f676efab9a Open ↗
powerd 0def5f0f50482c887a8fa645e1347e8d Open ↗
ProcessMonitor.exe 85a9e9de754b99095644726faf6124f7 Open ↗
rinetd fe323f8f6d84464b7a7f35d694c64851 Open ↗
rinetd 3874e14eda06779d777f182c39ac9dfe Open ↗
rinetd 1841b49525e0b3ca1a17556e6af775c7 Open ↗
systemd-acpid fc5a346c6bbec19a8463977e05fa14c2 Open ↗
systemd-acpid aa59ebd082118ab7c0a0fded580364da Open ↗
systemd-network-check fe323f8f6d84464b7a7f35d694c64851 Open ↗
systemd-rinetd cc622348b636e654d68763447cdb4599 Open ↗
systemd-rinetd 517ae29a0048d9f21d0debe9476b94e5 Open ↗
systemd-rinetd 40c5c2686fbc451386fc296994664fa2 Open ↗
systemd-udiskd 9dec74a38d9b6e668d616b2ec45159d5 Open ↗
systemd-udiskd 0df3c7d1f30e984318cf3a3a98b9d4d2 Open ↗
systemd-udiskd 005b0b12b59930845fabc6f45c6ca725 Open ↗
test 85ba7a059f33bf40fb1386fd506b38a7 Open ↗
udiskd 846ec88090311868d4e19658ef538077 Open ↗
update 4b6526c735279faf3f938e480c75471b Open ↗
w.exe 0acd888653dba95628f3f403f3c03295 Open ↗
watchdog.exe d363776b4adc2f3a513e0637eb7e957f Open ↗
worker.exe b6e904360c346665117dc97a096f8f96 Open ↗
zabbix_trapper e54147cf021827f5eb9c19f41e561aa3 Open ↗
zabbix_trapper da1d0a016d5ee5190475fe0a8d69e139 Open ↗
zabbix-agent e8cdefcbf2850a233fe6f13f22ec0efb Open ↗
zabbix-trapper 860fd8008365a3e61a21328b0c431076 Open ↗
zabbix-trapper 72fbfee7fabc9be88f263604addb1860 Open ↗
znfs.exe 31d4623ef6d7501c48ac2b3f47e3db16 Open ↗

Network indicators

Address PT Fusion
adv-click-track.online Open ↗
adv-click-track.space Open ↗
cdn.debian-check.space Open ↗
check.cert-update.online Open ↗
dpkg.debian-check.cloud Open ↗
scrt.vdyke.online Open ↗
status.cert-update.space Open ↗
195.58.137.115 Open ↗
199.119.136.138 Open ↗
213.139.205.166 Open ↗
216.146.26.31 Open ↗
45.145.171.112 Open ↗
45.59.170.247 Open ↗
91.221.191.228 Open ↗
94.124.160.113 Open ↗
94.124.160.12 Open ↗

#ir #dfir #ti #malware #apt #ioc
@ptescalator

More from oUth0R

More from oUth0R

More in General