Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Application Security

5/7/2019
08:00 AM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

Russian Nation-State Group Employs Custom Backdoor for Microsoft Exchange Server

Turla hacking team abuses a legitimate feature of the Exchange server in order to hide out and access all of the target organization's messages.

A well-known Russian nation-state hacking group has been infiltrating the Microsoft Exchange email servers of its targeted victims since at least 2014 via a custom backdoor. 

Researchers at ESET say the so-called Turla group, aka Snake, has been hacking into victims' Microsoft Exchange servers and planting its sophisticated LightNeuron backdoor malware for cyber espionage purposes. Turla accesses the email systems by abusing Exchange Server's legitimate Transport Agent feature, which lets other software from Microsoft as well as third parties operate with Exchange, including spam-filtering tools. The feature lets these other applications process email messages coming and going from Exchange.

The LightNeuron backdoor for Exchange specifically allows Turla attackers to read and modify email messages, create and send their own messages, and block messages to users at the victim organization, ESET said in new research it revealed today. Turla previously had been seen targeting Outlook email clients, an attack method ESET detailed last August.

Matthieu Faou, a malware researcher with ESET, says he believes this is the first case of malware specifically targeting Exchange servers. "It's really similar to the Outlook backdoor, but it has access to all emails of the [victim] organization. It's focused on the main email server," he says.

And by employing Exchange's Transport Agent, the attackers can blend into the email environment. "This feature is something generally used by security products, such as anti-spam, to integrate into Microsoft Exchange," Faou says.

Turla's LightNeuron backdoor also operates a rare command-and-control method that uses email JPEG and PDF attachments to transport the commands - hidden within the attachments using steganography. "The attacker sends an email with the JPEG and PDF, and the content is decoded and decrypted by LightNeuron on the main Exchange server," Faou explains.

ESET found three victims of the LightNeuron attacks: a ministry of foreign affairs in Eastern Europe, a diplomatic organization in the Middle East, and an unidentified organization in Brazil. The Brazilian victim was discovered via a sample uploaded to VirusTotal, according to ESET's new report on the newly found Turla operation.

The victims were "the regular, usual targets" of Turla - diplomatic entities, Faou says.

LightNeuron uses a PowerShell script, called msinp.ps1, to install LightNeuron, and a remote administration tool, called IntelliAdmin, both of which were discovered on victim machines, according to ESET.

Security researchers at Kaspersky Lab have seen similar Exchange Server attacks and steganography-masked C2 activity by Turla, according to Kurt Baumgartner, a security researcher with Kaspersky. "They are active," he says, noting that Kaspersky Lab has previously written about the latest twist in Turla attacks in private reports to clients. "Their technical capabilities are impressive and they are really well-resourced ... They are a top-tier APT." 

No Patch
And like other so-called "living-off-the-land"-style attacks that abuse legitimate tools and software in a victim organization, there's no software patch to prevent a LightNeuron backdoor attack. ESET's Faou Microsoft could add some measures, such as enforcing a digital signature from a Transport Agent, for example, to ensure its legitimacy. But if an attacker steals the Exchange server's admin privileges, there's not much even more layers of security for Exchange can do, he says.

"It's not really a vulnerability. They are using legitimate functionality [of Exchange]," he says.

Microsoft was not available for comment at the time of this posting.

If an organization gets hit with Turla's LightNeuron, recovery is complicated. "Simply removing the two malicious files will break Microsoft Exchange, preventing everybody in the organization from sending and receiving emails. Before actually removing the files, the malicious Transport Agent should be disabled," ESET warned in its report on the attacks.

The problem, Faou says, is that Transport Agent is registered in the configuration of the server, so even if LightNeuron gets removed, Exchange will try to load it. "If it's unable to load the Transport Agent, it will totally break the main server so you cannot send or receive emails anymore," he says. "You need to administer Transport Agent properly before removing the files." ESET details the proper removal process in a whitepaper it also published today.

Turla attackers first must steal credentials to the Exchange Server to install LightNeuron. So enabling multifactor authentication among user accounts can help thwart the attack. In addition, ESET recommends monitoring the main Exchange Server, including installing endpoint detection and response (EDR) tools or other security monitoring.

The bottom line is many organizations typically don't monitor when a new Transport Agent gets installed on the Exchange Server. "That's the main problem. It's a feature that's not very well-known," Faou says.

Meanwhile, ESET said code snippets of the Windows version of LightNeuron indicate that Turla also created a Linux variant of the backdoor.

 

 

 

Join Dark Reading LIVE for two cybersecurity summits at Interop 2019. Learn from the industry's most knowledgeable IT security experts. Check out the Interop agenda here.

Kelly Jackson Higgins is Executive Editor at DarkReading.com. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
phillysteak
50%
50%
phillysteak,
User Rank: Apprentice
5/8/2019 | 3:10:26 PM
Did ESET share additional IOCs?
So I looked over the IntelliAdmin documentation, and it listens on default ports 2792 and 5900 per their official documentation, however the connection port can be changed. Did ESET share whether the standard IntelliAdmin ports were used for this Attack or if specific non-default connection ports were used, or if attackers kept changing the connection ports? That would be insightful intel as it could assist in identifying part of this attack through legitimate network communication channels.
Where Businesses Waste Endpoint Security Budgets
Kelly Sheridan, Staff Editor, Dark Reading,  7/15/2019
US Mayors Commit to Just Saying No to Ransomware
Robert Lemos, Contributing Writer,  7/16/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Building and Managing an IT Security Operations Program
As cyber threats grow, many organizations are building security operations centers (SOCs) to improve their defenses. In this Tech Digest you will learn tips on how to get the most out of a SOC in your organization - and what to do if you can't afford to build one.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-17210
PUBLISHED: 2019-07-20
An issue was discovered in PrinterOn Central Print Services (CPS) through 4.1.4. The core components that create and launch a print job do not perform complete verification of the session cookie that is supplied to them. As a result, an attacker with guest/pseudo-guest level permissions can bypass t...
CVE-2019-12934
PUBLISHED: 2019-07-20
An issue was discovered in the wp-code-highlightjs plugin through 0.6.2 for WordPress. wp-admin/options-general.php?page=wp-code-highlight-js allows CSRF, as demonstrated by an XSS payload in the hljs_additional_css parameter.
CVE-2019-9229
PUBLISHED: 2019-07-20
An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M800B-MSBR and 800C-MSBR devices with firmware versions F7.20A to F7.20A.251. An internal interface exposed to the link-local address 169.254.254.253 allows attackers in the local network to access multiple quagga VTYs. Attackers can...
CVE-2019-12815
PUBLISHED: 2019-07-19
An arbitrary file copy vulnerability in mod_copy in ProFTPD up to 1.3.5b allows for remote code execution and information disclosure without authentication, a related issue to CVE-2015-3306.
CVE-2019-13569
PUBLISHED: 2019-07-19
A SQL injection vulnerability exists in the Icegram Email Subscribers & Newsletters plugin through 4.1.7 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system.