Operation Chewbacca

More in General
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- DragonDoll: a matryoshka in the world of Android spies
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring,…
- ⚡Fake news — THAT'S ALL
⚡Fake news — B U L L S H I T PT ESC specialists discovered an…
At the end of June, the PT ESC team, during incident investigations, discovered a new group targeting at least oil and gas companies and the financial sector.
During attacks, the threat actors pursue destructive goals while maintaining a presence in the compromised infrastructure for a fairly long time.
For lateral movement within the infrastructure, they primarily use WinRM (usually in combination with WinRb) and SSH.
For persistence in the infrastructure, they mainly use server machines with high uptime (Windows\Linux); persistence is achieved via services in both cases. A wide range of tools is used as payloads:
- Agents for the merlin framework.
- An agent based on reverse_ssh.
- The
GoSocks5Proxyutility based on go-socks5. ReverseProxy— a proprietary utility written in Rust.- The
GoRinetbackdoor. It uses config encryption with a key derived from the physical address of the network adapter.
🐻 Various software is used to carry out destructive actions, including some that, by a number of indications, was developed using AI.
- The
T-Riperwiper for network devices manufactured byCisco/Huawei— deleting images, resetting device configuration, rebooting. They are used in combination with bash scripts for execution against remote targets. - A custom wiper for remotely deleting
QNAPdata. - To encrypt data on machines running Windows OS, a malware suite is used consisting of an orchestrator (with the ability to send encryption progress reports to a remote C2). Wiper generation is performed in a multithreaded manner, with individual executables created by adding “junk” to the overlay to evade detection. For automated propagation across the network, config files are used that specify known credentials from previously compromised accounts and target subnets.
The use of the CVE-2026-31431 vulnerability (CopyFail) for privilege escalation has also been noted, along with the custom tool CredsReseter for resetting passwords of Linux-like system accounts and Windows scripts for dumping credentials of third-party services.
Recommendations:
- Search for and monitor indicators of compromise.
- Perform signature scanning.
- Update the OS.
IoCs
File indicators:
| Name | MD5 | PT Fusion |
|---|---|---|
acgid |
9f7a688faf61d895a5c1d09084f16436 | Open ↗ |
cf |
4c5b89504269b1d73ee5b6449559da4b | Open ↗ |
mnworker.exe |
a6d00278363e4916c4bc6ff6f36dfe6f | Open ↗ |
NetConfigSvc.exe |
56fd630da404d4d8c5afd17eb3506b41 | Open ↗ |
NetSvcHelper.exe |
272625644208beab5daa79f676efab9a | Open ↗ |
powerd |
0def5f0f50482c887a8fa645e1347e8d | Open ↗ |
ProcessMonitor.exe |
85a9e9de754b99095644726faf6124f7 | Open ↗ |
rinetd |
fe323f8f6d84464b7a7f35d694c64851 | Open ↗ |
rinetd |
3874e14eda06779d777f182c39ac9dfe | Open ↗ |
rinetd |
1841b49525e0b3ca1a17556e6af775c7 | Open ↗ |
systemd-acpid |
fc5a346c6bbec19a8463977e05fa14c2 | Open ↗ |
systemd-acpid |
aa59ebd082118ab7c0a0fded580364da | Open ↗ |
systemd-network-check |
fe323f8f6d84464b7a7f35d694c64851 | Open ↗ |
systemd-rinetd |
cc622348b636e654d68763447cdb4599 | Open ↗ |
systemd-rinetd |
517ae29a0048d9f21d0debe9476b94e5 | Open ↗ |
systemd-rinetd |
40c5c2686fbc451386fc296994664fa2 | Open ↗ |
systemd-udiskd |
9dec74a38d9b6e668d616b2ec45159d5 | Open ↗ |
systemd-udiskd |
0df3c7d1f30e984318cf3a3a98b9d4d2 | Open ↗ |
systemd-udiskd |
005b0b12b59930845fabc6f45c6ca725 | Open ↗ |
test |
85ba7a059f33bf40fb1386fd506b38a7 | Open ↗ |
udiskd |
846ec88090311868d4e19658ef538077 | Open ↗ |
update |
4b6526c735279faf3f938e480c75471b | Open ↗ |
w.exe |
0acd888653dba95628f3f403f3c03295 | Open ↗ |
watchdog.exe |
d363776b4adc2f3a513e0637eb7e957f | Open ↗ |
worker.exe |
b6e904360c346665117dc97a096f8f96 | Open ↗ |
zabbix_trapper |
e54147cf021827f5eb9c19f41e561aa3 | Open ↗ |
zabbix_trapper |
da1d0a016d5ee5190475fe0a8d69e139 | Open ↗ |
zabbix-agent |
e8cdefcbf2850a233fe6f13f22ec0efb | Open ↗ |
zabbix-trapper |
860fd8008365a3e61a21328b0c431076 | Open ↗ |
zabbix-trapper |
72fbfee7fabc9be88f263604addb1860 | Open ↗ |
znfs.exe |
31d4623ef6d7501c48ac2b3f47e3db16 | Open ↗ |
Network indicators
| Address | PT Fusion |
|---|---|
adv-click-track.online |
Open ↗ |
adv-click-track.space |
Open ↗ |
cdn.debian-check.space |
Open ↗ |
check.cert-update.online |
Open ↗ |
dpkg.debian-check.cloud |
Open ↗ |
scrt.vdyke.online |
Open ↗ |
status.cert-update.space |
Open ↗ |
195.58.137.115 |
Open ↗ |
199.119.136.138 |
Open ↗ |
213.139.205.166 |
Open ↗ |
216.146.26.31 |
Open ↗ |
45.145.171.112 |
Open ↗ |
45.59.170.247 |
Open ↗ |
91.221.191.228 |
Open ↗ |
94.124.160.113 |
Open ↗ |
94.124.160.12 |
Open ↗ |
#ir #dfir #ti #malware #apt #ioc
@ptescalator
More in General
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- DragonDoll: a matryoshka in the world of Android spies
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring,…
- ⚡Fake news — THAT'S ALL
⚡Fake news — B U L L S H I T PT ESC specialists discovered an…






