[ << ALL_FEED ]

Operation Tartaria Part 2

More in General

Operation Tartaria Part 2

In addition to the passive backdoor PlugX, we managed to discover another version of it that mimicked the launch of Yandex Browser.

{"TaskId":"[REDACTED]","TaskName":"Yandexstart_Server","TaskRegistryPath":"\\Yandexstart_Server","TaskAuthor":"[REDACTED]","IsHiddenTask":false,"IsMissingOnFS":true,"Action":{"Context":"Author","Properties":[{"Id":"","ActionName":"Execution","Arguments":"-d restart","Command":"C:\\PROGRA~1\\Yandex\\browser\\Yandex.exe","WorkingDirectory":"","Flags":0}],"Version":3},"Triggers":[{"TriggerType":"Boot","Comment":"Boot"}],"CreatedTime":"2024-12-11T01:11:34Z","LastRunTime":"2025-06-23T06:37:17Z","LastErrorCode":1223,"Timeline":"2024-12-11T01:11:34Z"}
Code language: JSON / JSON with Comments (json)


Yandex.exe turned out to be vulnerable to the DLL Side-Loading technique, carried out by the Umdh.exe utility (User-Mode Dump Heap), which loads a malicious dbghelp.dll library under a VMProtect packer with custom section names; the payload is stored in the desktop.ini file.

🫣 As in the previous case, we are dealing with a two-module backdoor. The connector is injected into the choice.exe process, and the command interpreter into mspaint.exe. The processes communicate via the pipe .\\PIPE\\[%d].

Upon successful startup, the sample under investigation connects to a blog on livejournal.com (screenshot 1) and on ok.ru (screenshots 2-3). It then parses the response content and searches for a sequence that begins with R241223 and ends with R251223, and within which an encrypted token for the Yandex Disk API is located. The backdoor then communicates via the API. A similar sample was described in “CloudSorcerer: a new APT threat targeting Russian government organizations.”

In addition to Yandex Disk, the backdoor supports communication via Microsoft Graph and Dropbox:

cloud-api.yandex.net
graph.microsoft.com
content.dropboxapi.com
Code language: plaintext (plaintext)


Communication occurs by reading and overwriting files in a specified folder in the cloud. The files themselves are protected by a simple substitution cipher, and the structure of the messages differs depending on the command being executed. However, the same header is used everywhere:

0         2          6             10             14
| command | msg size | short answer | ticketcount |
Code language: plaintext (plaintext)


☝️ The following backdoor functions are noteworthy:

• the ability to receive shellcodes and PE files, injecting them into the TSTheme.exe and msiexec.exe processes;
• execution of WMI queries to obtain system information:
SELECT * FROM Win32_OperatingSystem
SELECT * FROM Win32_TimeZone
SELECT * FROM Win32_ComputerSystem
SELECT * FROM Win32_QuickFixEngineering
Code language: SQL (Structured Query Language) (sql)

• disconnection of all network connections via the WNetCancelConnection2W API;
• modification of account logon parameters or password via the NetUserSetInfo API.

C2:
devtunnels.ms
https://anddes.livejournal.com/511.html
https://ok.ru/profile/587950172233/statuses/157023463517001
Code language: YAML (yaml)


✅ Recommendations:

• block DevTunnels using group policy;
• search for hidden tasks;
• search for tasks with the parameter:
reg query "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks" /s | findstr "2D00720065006D006F0074006500200075007000"
Code language: plaintext (plaintext)

reg query "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks" /s | findstr "2d00640020007200650073007400610072007400"
Code language: plaintext (plaintext)

• search for the PlugX identifier:
reg query HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Mail\cf
Code language: plaintext (plaintext)


Happy hunting!


@ptescalator
#dfir #ti #apt #reverse #malware

More from oUth0R

More from oUth0R

More in General