Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

8/30/2017
06:00 PM
Connect Directly
Twitter
LinkedIn
RSS
E-Mail
50%
50%

Russian-Speaking Turla Group Uses New Tools to Target Embassies, Consulates

Turla cyber espionage gang has been around for a long time and appears to be back in action after a temporary lull.

The Russian-language speaking advanced persistent threat (APT) group Turla, which appeared to have gone dormant for a while, seems to be back at it again.

In separate advisories, two security vendors this week reported on recent malicious activity that they described as being linked in one way or the other to Turla.

One of the advisories was from ESET and warned about a hitherto undocumented backdoor dubbed Gazer, that members of Turla have begun using relatively recently to spy on embassies and consulates worldwide.

The backdoor is being used in a data-stealing campaign and was discovered on an unspecified number of computers belonging mostly to targets located in Southeastern Europe and member nations of the former Soviet Union.

The other advisory was from Kaspersky Lab and provided details of Turla-related APT activity called WhiteBear that the security vendor had warned its customers about back in mid-February 2017. According to Kaspersky Lab, the WhiteBear campaign appeared to be the second phase of White Atlas, another Turla project that the company had privately warned its customers about in 2016.

As with previous Turla campaigns, WhiteBear's command and control infrastructure also is comprised of a collection of compromised websites and hijacked satellite connections. Some portions of the infrastructure that WhiteBear is using was also used previously in other Turla campaigns, such as one involving a data-stealing backdoor dubbed Kopiluwak.

In addition, attempts to deploy WhiteBear modules are always preceded by attempts to deploy WhiteAtlas as well, further suggesting a link between the two, Kaspersky Lab said.

"The connections appear pretty solid," says Kurt Baumgartner, principal security researcher at Kaspersky Lab, pointing to other similarities such as the use of a shared command and control server and a logging facility that shares components associated with previous Turla campaigns.

Despite such similarities, though, the WhiteBear campaign seems to be a separate and smaller project targeting consular operations, embassies and, starting June, defense organizations as well.

"The target profiles appear to be a subset of what we have seen with WhiteAtlas," Baumgartner says. Several other operations involving WhiteAtlas and other Turla operations also have been broader than what Kaspersky Lab has seen with WhiteBear, he adds.

Meanwhile, Jean-Ian Boutin, senior malware researcher at ESET, says the security vendor was able to tie Gazer to Turla because of its similarities with Carbon and Kazuar - two other backdoors that the Turla group has used. "For example, they can all receive encrypted tasks from a C&C server, which can be executed either by the infected machine or by another compromised machine on the network," he says.

Similarly, all the malware samples use an encrypted container to store the malware’s components and configuration information and to also log their actions in a file, Boutin says. Skipper, yet another backdoor associated with Turla, was found alongside Gazer in most of the cases that ESET investigated, Boutin says.

"Turla is very sophisticated – they are constantly changing their tools to evade detection, and all of their second stage backdoor implements advanced techniques to remain persistent and stealthy on a system," he says.

The alerts from Kaspersky Lab and ESET mark the second and the third time this month that a security vendor has reported on Turla. Earlier, Proofpoint said it had discovered a new JavaScript dropper for the KopiLuwak backdoor being used in a data theft campaign targeting G20 participants. Among those targeted by the campaign that Proofpoint reported were policymakers, journalists, and representatives from G20 member nations.

Learn from the industry’s most knowledgeable CISOs and IT security experts in a setting that is conducive to interaction and conversation. Click for more info and to register.

 

Related Content:

 

Jai Vijayan is a seasoned technology reporter with over 20 years of experience in IT trade journalism. He was most recently a Senior Editor at Computerworld, where he covered information security and data privacy issues for the publication. Over the course of his 20-year ... View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
COVID-19: Latest Security News & Commentary
Dark Reading Staff 11/19/2020
New Proposed DNS Security Features Released
Kelly Jackson Higgins, Executive Editor at Dark Reading,  11/19/2020
How to Identify Cobalt Strike on Your Network
Zohar Buber, Security Analyst,  11/18/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win an Amazon Gift Card! Click Here
Latest Comment: He hits the gong anytime he sees someone click on an email link.
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-29071
PUBLISHED: 2020-11-25
An XSS issue was found in the Shares feature of LiquidFiles before 3.3.19. The issue arises from the insecure rendering of HTML files uploaded to the platform as attachments, when the -htmlview URL is directly accessed. The impact ranges from executing commands as root on the server to retrieving se...
CVE-2020-29072
PUBLISHED: 2020-11-25
A Cross-Site Script Inclusion vulnerability was found on LiquidFiles before 3.3.19. This client-side attack requires user interaction (opening a link) and successful exploitation could lead to encrypted e-mail content leakage via messages/sent?format=js and popup?format=js.
CVE-2020-26241
PUBLISHED: 2020-11-25
Go Ethereum, or "Geth", is the official Golang implementation of the Ethereum protocol. This is a Consensus vulnerability in Geth before version 1.9.17 which can be used to cause a chain-split where vulnerable nodes reject the canonical chain. Geth's pre-compiled dataCopy (at 0x00...04) co...
CVE-2020-26242
PUBLISHED: 2020-11-25
Go Ethereum, or "Geth", is the official Golang implementation of the Ethereum protocol. In Geth before version 1.9.18, there is a Denial-of-service (crash) during block processing. This is fixed in 1.9.18.
CVE-2020-26240
PUBLISHED: 2020-11-25
Go Ethereum, or "Geth", is the official Golang implementation of the Ethereum protocol. An ethash mining DAG generation flaw in Geth before version 1.9.24 could cause miners to erroneously calculate PoW in an upcoming epoch (estimated early January, 2021). This happened on the ETC chain on...