Attacks/Breaches

10/10/2018
05:19 PM
Connect Directly
Twitter
LinkedIn
RSS
E-Mail
50%
50%

New Threat Group Conducts Malwareless Cyber Espionage

Gallmaker group is relying exclusively on legitimate tools and living-off-the-land tactics to make detection very difficult.

Cybercriminals seeking to avoid detection by antimalware defenses have increasingly begun using legitimate hacking tools and tactics — in addition to their own malware — to break into enterprise networks and literally hide in plain sight. Now a new and likely state-sponsored threat group has emerged that isn't using any custom malware at all.

Instead, the group is exclusively relying on publicly available hacking tools and living-off-the-land tactics to conduct an especially stealthy and hard-to-detect cyber espionage campaign.

Symantec, which was the first to spot the group, has named it Gallmaker. In a report this week, the security vendor described Gallmaker as targeting government and military organizations in Eastern Europe and the Middle East. The group's targets have included several overseas embassies of a country in Eastern Europe, and also a defense contractor in the Middle East.

Gallmaker's targeting and its use of political- and diplomatic-themed lure documents to gather information from victims suggests it is an espionage-motivated group says Jon DiMaggio, senior threat intelligence analyst at Symantec.

"The type of targets seen in the attacks really fit that of what an espionage group would be interested in," DiMaggio says. "If simply for financial gain, it would be odd [for Gallmaker] to restrict targets to diplomatic, military, and defense personnel."

Gallmaker appears to have started operations in December 2017 and its most recently observed campaign was in June 2018. What makes the group interesting is the fact that it does not use malware at all in carrying out operations. Rather, Gallmaker exclusively has been using only tools and protocols that many organizations use for benign purposes, such as for penetration testing and for data archiving and compression.

"Gallmaker takes advantage of legitimate protocols and uses them in a manner that they were not designed for," DiMaggio says.

The group's modus operandi has been to send Office lure documents to individuals at targeted organizations which when opened give the attackers a way to remotely execute commands in the victim system's memory using Microsoft's Office Dynamic Data Exchange (DDE) protocol.

Once on a system, the attackers have then been executing various tools in memory on the victim system, making their activities hard to spot and to stop.

DDE is a protocol that enables messages to be sent between Microsoft apps that share data, such as between Word and Excel. Microsoft issued an update last December that disabled DDE by default after several malicious campaigns in which attackers executed malicious code on systems via Word and Excel. The victims of the Gallmaker campaign do not appear to have installed the patch and are therefore still vulnerable to attack via DDE, Symantec said in its report.

Gallmaker has been using DDE "to effectively run Rex Powershell scripts, which then allow the attacker to make a reverse TCP shell connection via the publicly available Metaspolit pen test tool," DiMaggio says.

Once the attackers have gained remote control of a system, they have been downloading a legitimate WinZip console for packing and compressing data of interest for exfiltration, he notes. The command-and-control servers used by Gallmaker have all been IP addresses and not domain names.

One reason such activity can be hard to spot is because it can appear very much like legitimate processes. Rex Powershell for instance is a library that is designed to interact with the Metasploit penetration testing suite, DiMaggio says. Metasploit is the go-to tool for legitimate pen testers and its presence on a network may not always been seen as a sign of malicious activity. Similarly, WinZip is a legitimate archive and file compression tool that is commonly found in many organizations.

In fact, the only way that Symantec itself discovered Gallmaker's activity was when one of the company's security tools identified the execution of DDE followed by Powershell commands at a customer site. Symantec's investigation of the activity quickly revealed that it was not legitimate, DiMaggio says.

"Living off the land is definitely on the rise as a tactic," he says. Cybercriminals are adopting the tactic to make it harder for defenders to identify and mitigate their malicious activity. "Often this activity will blend in with legitimate operational activity conducted by administrators," he says.

The trend highlights the need for a multi-tiered defensive strategy that combines the use of firewalls, intrusion prevention systems, and endpoint protection tools. Enterprises also need to make sure to monitor and restrict the use of administrative tools on their networks, he adds.

Threat intelligence sharing can help enable better defenses as well, says Neil Jenkins, chief analytic officer at the Cyber Threat Alliance (CTA), a group of about 20 security vendors committed to sharing threat data with each other. Symantec, which is a member of CTA, for instance, shared indicators of compromise and other Gallmaker-related data with other members of the group before releasing the data publicly.

Such sharing can give security vendors access to a broader set of data than that to which they normally have access, thereby enabling better defenses, Jenkins says.

"Our members acknowledge that they cannot see the full picture when it comes to cybersecurity and that it takes a community approach," he says. "Sharing information enables our members to see the big picture and then compete on the effectiveness on how they use this information."

Related Content:

 

 

Black Hat Europe returns to London Dec 3-6 2018  with hands-on technical Trainings, cutting-edge Briefings, Arsenal open-source tool demonstrations, top-tier security solutions and service providers in the Business Hall. Click for information on the conference and to register.

Jai Vijayan is a seasoned technology reporter with over 20 years of experience in IT trade journalism. He was most recently a Senior Editor at Computerworld, where he covered information security and data privacy issues for the publication. Over the course of his 20-year ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Oldest First  |  Newest First  |  Threaded View
12 Free, Ready-to-Use Security Tools
Steve Zurier, Freelance Writer,  10/12/2018
Most IT Security Pros Want to Change Jobs
Dark Reading Staff 10/12/2018
6 Security Trends for 2018/2019
Curtis Franklin Jr., Senior Editor at Dark Reading,  10/15/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
Flash Poll
The Risk Management Struggle
The Risk Management Struggle
The majority of organizations are struggling to implement a risk-based approach to security even though risk reduction has become the primary metric for measuring the effectiveness of enterprise security strategies. Read the report and get more details today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-10839
PUBLISHED: 2018-10-16
Qemu emulator <= 3.0.0 built with the NE2000 NIC emulation support is vulnerable to an integer overflow, which could lead to buffer overflow issue. It could occur when receiving packets over the network. A user inside guest could use this flaw to crash the Qemu process resulting in DoS.
CVE-2018-13399
PUBLISHED: 2018-10-16
The Microsoft Windows Installer for Atlassian Fisheye and Crucible before version 4.6.1 allows local attackers to escalate privileges because of weak permissions on the installation directory.
CVE-2018-18381
PUBLISHED: 2018-10-16
Z-BlogPHP 1.5.2.1935 (Zero) has a stored XSS Vulnerability in zb_system/function/c_system_admin.php via the Content-Type header during the uploading of image attachments.
CVE-2018-18382
PUBLISHED: 2018-10-16
Advanced HRM 1.6 allows Remote Code Execution via PHP code in a .php file to the user/update-user-avatar URI, which can be accessed through an "Update Profile" "Change Picture" (aka user/edit-profile) action.
CVE-2018-18374
PUBLISHED: 2018-10-16
XSS exists in the MetInfo 6.1.2 admin/index.php page via the anyid parameter.