Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

10/1/2019
04:15 PM
Connect Directly
Twitter
LinkedIn
RSS
E-Mail
50%
50%

New Malware Campaign Targets US Petroleum Companies

Attackers are using an obfuscated version of Adwind Remote Access Trojan for stealing data, Netskope says.

An unknown threat actor is targeting companies in the US petroleum industry with a sophisticated data-stealing remote access Trojan (RAT) that previously had been used in attacks against retail and hospitality organizations.

Netskope says it observed a recent spike in alerts for the malware family — the Adwind RAT — among its customers operating within the petroleum industry.

The attacks appear to be originating from a domain belonging to Westnet, an Australian ISP. What's not clear is if the attacker is a Westnet customer or has compromised accounts belonging to Westnet customers and is using them to distribute Adwind, Netskope said in a report.  

News of the attacks on US petroleum companies coincides with recent reports about the US government planning a major cyberstrike against Iran to punish the country for its reported involvement in this month's bombing of a major Saudi Arabian oil facility.

On Sunday, Reuters reported on Iran's oil minister warning the country's petroleum industry to be on alert for cyber attacks from the US. In June, the Washington Post quoted unnamed sources as saying US Cyber Command had carried out an offensive attack on Iranian computer systems that had allegedly been used to plan attacks on oil tankers in the region.

According to Netskope, the command and control infrastructure that the attackers are using in the latest Adwind campaign is different from that used in the previous attacks on organizations in the retail and hospitality sectors. So Netskope has no data to suggest the two groups are linked, according to the security vendor.

Adwind is sold as commodity malware on Dark Web markets and several threat actors have used it in various campaigns over the last two years. From a functionality standpoint, the Adwind strain being used in the petroleum industry attacks is very similar to older Adwind samples.

It can encrypt and exfiltrate data; capture Web cam images; scan hard drives for specific files based on extensions defined in the malware's configuration; inject malicious code into legitimate processes to remain under the radar; and monitor system status, Netskope said. The malware modifies registry settings to achieve persistence and can terminate firewalls, AV, and other security services on infected devices.

Sophisticated Obfuscation

One area where the latest Adwind strain is significantly superior to its predecessors, however, is obfuscation. Netskope's analysis of the malware showed that it uses multiple embedded JAR archives before unpacking the final payload. JAR, or Java Archive, is a file format that allows for multiple files to be aggregated into one file.

"Java being cross-platform makes it an ideal choice if the attackers want to target multiple operating systems," says Abhinav Singh, information security researcher at Netskope. "By creating multiple layers of embedded and encrypted JAR archives, it becomes incredibly difficult for security solutions to understand the actual behavior and functionality of the JAR." 

The latest Adwind version also spins up multiple execution processes, which further complicates the task of keeping track of suspicious behaviors, Singh says. "Analyzing this malware sample was like peeling an onion, layer after layer."

The obfuscation measures in the Adwind samples that Netskope analyzed were so effective, that only five out of 56 anti-virus tools on Virus Total were able to detect the malware initially. But when Netskope managed to extract the final unencrypted JAR through manual analysis, it discovered that more than 30 vendors were able to detect the malware, Singh says.

Netskope's analysis shows the attackers are primarily interested in documents, files, and other locally stored data. They also appear keen on finding information like FTP passwords and SSH keys that can give the more access to the network.

For targeted organizations, the latest attacks are another reminder of the need to get the basics right in terms of network monitoring and content downloads, Singh says. "The main takeaway here is that attacks and threat actors are constantly evolving. By re-using the old techniques in new ways, they are trying to target companies where infrastructure management is complex and hard to upgrade."

Related Content:

Check out The Edge, Dark Reading's new section for features, threat data, and in-depth perspectives. Today's top story: "5 Disruptive Trends Transforming Cybersecurity"

Jai Vijayan is a seasoned technology reporter with over 20 years of experience in IT trade journalism. He was most recently a Senior Editor at Computerworld, where he covered information security and data privacy issues for the publication. Over the course of his 20-year ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Why Cyber-Risk Is a C-Suite Issue
Marc Wilczek, Digital Strategist & CIO Advisor,  11/12/2019
DevSecOps: The Answer to the Cloud Security Skills Gap
Lamont Orange, Chief Information Security Officer at Netskope,  11/15/2019
Unreasonable Security Best Practices vs. Good Risk Management
Jack Freund, Director, Risk Science at RiskLens,  11/13/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Navigating the Deluge of Security Data
In this Tech Digest, Dark Reading shares the experiences of some top security practitioners as they navigate volumes of security data. We examine some examples of how enterprises can cull this data to find the clues they need.
Flash Poll
Rethinking Enterprise Data Defense
Rethinking Enterprise Data Defense
Frustrated with recurring intrusions and breaches, cybersecurity professionals are questioning some of the industrys conventional wisdom. Heres a look at what theyre thinking about.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-19040
PUBLISHED: 2019-11-17
KairosDB through 1.2.2 has XSS in view.html because of showErrorMessage in js/graph.js, as demonstrated by view.html?q= with a '"sampling":{"value":"<script>' substring.
CVE-2019-19041
PUBLISHED: 2019-11-17
An issue was discovered in Xorux Lpar2RRD 6.11 and Stor2RRD 2.61, as distributed in Xorux 2.41. They do not correctly verify the integrity of an upgrade package before processing it. As a result, official upgrade packages can be modified to inject an arbitrary Bash script that will be executed by th...
CVE-2019-19012
PUBLISHED: 2019-11-17
An integer overflow in the search_in_range function in regexec.c in Oniguruma 6.x before 6.9.4_rc2 leads to an out-of-bounds read, in which the offset of this read is under the control of an attacker. (This only affects the 32-bit compiled version). Remote attackers can cause a denial-of-service or ...
CVE-2019-19022
PUBLISHED: 2019-11-17
iTerm2 through 3.3.6 has potentially insufficient documentation about the presence of search history in com.googlecode.iterm2.plist, which might allow remote attackers to obtain sensitive information, as demonstrated by searching for the NoSyncSearchHistory string in .plist files within public Git r...
CVE-2019-19035
PUBLISHED: 2019-11-17
jhead 3.03 is affected by: heap-based buffer over-read. The impact is: Denial of service. The component is: ReadJpegSections and process_SOFn in jpgfile.c. The attack vector is: Open a specially crafted JPEG file.