Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Threat Intelligence

11/10/2016
03:55 PM
Connect Directly
Google+
Twitter
RSS
E-Mail
100%
0%

Russian Hackers Behind DNC Breach Wage Post-US Election Attacks

Less than six hours after Donald Trump was named President-Elect of the US, Cozy Bear/APT29/CozyDuke nation-state hackers kicked off waves of spearphishing attacks.

Russia's cyber-spying machine was in full force within six hours of the final US Presidential election results with at least five different waves of spear-phishing campaigns targeting users associated with US think-tanks and non-governmental organizations.

Researchers with Volexity posted their findings surrounding a jump in spearphishing activity by the so-called Russian hacking group known as Cozy Bear, APT29, and CozyDuke, best known for its recent breach of the Democratic National Committee (DNC). There were five different spearphishing campaigns spotted by Volexity, including attacks posing as emails forwarded from the Clinton Foundation, and two others posing as eFax URLs or documents.

"These e-mails came from a mix of attacker-created Google Gmail accounts and what appears to be compromised e-mail accounts at Harvard’s Faculty of Arts and Sciences (FAS). These e-mails were sent in large quantities to different individuals across many organizations and individuals focusing in national security, defense, international affairs, public policy, and European and Asian studies," said Steven Adair, founder at Volexity, in a post yesterday.

Think-tanks and NGOs have been common targets of the group, also known as The Dukes, since July of 2015.

"The Dukes continue to launch well-crafted and clever attack campaigns. They have had tremendous success evading anti-virus and anti-malware solutions at both the desktop and mail gateway levels," Adair wrote.

The group employs anti-VM macros and PowerShell scripts that help them bypass sandboxes that could detect them, for instance. "This combined with their use of steganography to hide their backdoor within PNG files that are downloaded remotely and loaded in memory only or via alternate data streams (ADS) is quite novel in its approach," he said. "Volexity believes that the Dukes are likely working to gain long-term access into think tanks and NGOs and will continue to launch new attacks for the foreseeable future."

The first spear-phishing attack wave uses a lure of the "The Shocking Truth About Election-Rigging in the United States." The email is purportedly an electronic fax from Secure Fax Corp., and contains a link to a ZIP file. That file has a Microsoft .LNK file that houses PowerShell commands, which execute anti-virtual machine checks and install a backdoor onto the victim's machine.

"The PowerDuke backdoor boasts a pretty extensive list of features that allow the Dukes to examine and control a system. Volexity suspects the feature set that has been built into PowerDuke is an extension of their anti-VM capabilities in the initial dropper files," Adair wrote. "Several commands supported by PowerDuke facilitate getting information about the system." 

Dark Reading's all-day virtual event Nov. 15 offers an in-depth look at myths surrounding data defense and how to put business on a more effective security path. 

 

In the second attack wave, the hackers uses a Word document with a malicious macro that checks for anti-VM features, and appears to come from [email protected] The subject line is "Incoming eFax: Elections Outcome Could Be revised [Facts of Elections Fraud]."

The most widespread attack was the third one, which uses an email purportedly from Harvard's "PDF Mobile Service," which doesn’t actually exist. (There appears to be a typo in the message as well, calling it "PFD Mobile Service" as well). The subject line: "Why American Elections Are Flawed." This one uses a ZIP file to mask the malicious executable.

The Clinton Foundation is the lure for the fourth and fifth waves of spearphishing campaigns by the hacking group. The first one uses "Clinton Foundation FYI #1" in its subject line, and deploys a Word document with a malicious embedded macro. The macro checks for anti-VM features. The email purportedly comes from the fictitious Harvard PDF Mobile Service.

Then there's the "Clinton Foundation FYI #2" email wave from the same "Harvard" email address, which contains a link to a ZIP file with an LNK file embedded. It contains the signature PowerShell commands that look for anti-VM, and installs a backdoor on the victim's machine.

"Like Attack Wave #3, this e-mail message also purported to be forwarded from Laura Graham at the Clinton Foundation. The message body contained dozens of e-mail addresses to which the message originally claims to have been sent, with organizations similar to Attack Wave #3," Adair wrote.

Volexity's post includes screenshots of the emails and code snippets.

Related Content:

Save

Kelly Jackson Higgins is the Executive Editor of Dark Reading. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Benefiter
50%
50%
Benefiter,
User Rank: Apprentice
11/12/2016 | 10:12:09 AM
Re:
I really like your page and the of the author's style . I always loking for your new posts. Thank you, I really like it, it is useful
Lily652
50%
50%
Lily652,
User Rank: Moderator
11/12/2016 | 4:58:47 AM
prayer times

I've been surfing online more than three hours today, yet I never found any interesting article like yours. It's pretty worth enough for me. In my opinion, if all webmasters and bloggers made good content as you did, the web will be a lot more useful than ever before. 

lucysecurity
50%
50%
lucysecurity,
User Rank: Apprentice
11/11/2016 | 4:03:19 PM
The Phishing Message looks like a LUCY Attack Simulation Template
Thank you for your article! The interesting fact is that the real Phishing e-mails look the same as our own best practice DIY phishing simulation templates which we provide together with LUCY Server! Obviously the cyber criminals are using best practices too: Our customers and partners say that the eFax Attack is a scenario with a high penetration rate! See our article on lucysecurity.com

 

Best Regards Palo
Kelly Jackson Higgins
50%
50%
Kelly Jackson Higgins,
User Rank: Strategist
11/11/2016 | 11:04:20 AM
Re: Typo
Thank you for the catch. There definitely was a typo in the Volexity blog... now it's been corrected in our article. =)

 
Kelly Jackson Higgins
50%
50%
Kelly Jackson Higgins,
User Rank: Strategist
11/11/2016 | 11:01:13 AM
Re: Typo
Thank you for the catch. There definitely was a typo in the Volexity blog... now it's been corrected in our article. =)

 
CJETT624
50%
50%
CJETT624,
User Rank: Apprentice
11/11/2016 | 10:36:35 AM
Possible Russian Hackers maybe Kapersky Institute security software sold in USA and around the world
check Kapersky institute out for hackers

 
JoeM066
50%
50%
JoeM066,
User Rank: Strategist
11/11/2016 | 10:14:27 AM
Typo
"stenography" should be "steganography".
Exploits Released for As-Yet Unpatched Critical Citrix Flaw
Jai Vijayan, Contributing Writer,  1/13/2020
Microsoft to Officially End Support for Windows 7, Server 2008
Kelly Sheridan, Staff Editor, Dark Reading,  1/13/2020
Active Directory Needs an Update: Here's Why
Raz Rafaeli, CEO and Co-Founder at Secret Double Octopus,  1/16/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
The Year in Security: 2019
This Tech Digest provides a wrap up and overview of the year's top cybersecurity news stories. It was a year of new twists on old threats, with fears of another WannaCry-type worm and of a possible botnet army of Wi-Fi routers. But 2019 also underscored the risk of firmware and trusted security tools harboring dangerous holes that cybercriminals and nation-state hackers could readily abuse. Read more.
Flash Poll
[Just Released] How Enterprises are Attacking the Cybersecurity Problem
[Just Released] How Enterprises are Attacking the Cybersecurity Problem
Organizations have invested in a sweeping array of security technologies to address challenges associated with the growing number of cybersecurity attacks. However, the complexity involved in managing these technologies is emerging as a major problem. Read this report to find out what your peers biggest security challenges are and the technologies they are using to address them.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-15625
PUBLISHED: 2020-01-18
A memory usage vulnerability exists in Trend Micro Password Manager 3.8 that could allow an attacker with access and permissions to the victim's memory processes to extract sensitive information.
CVE-2019-19696
PUBLISHED: 2020-01-18
A RootCA vulnerability found in Trend Micro Password Manager for Windows and macOS exists where the localhost.key of RootCA.crt might be improperly accessed by an unauthorized party and could be used to create malicious self-signed SSL certificates, allowing an attacker to misdirect a user to phishi...
CVE-2019-19697
PUBLISHED: 2020-01-18
An arbitrary code execution vulnerability exists in the Trend Micro Security 2019 (v15) consumer family of products which could allow an attacker to gain elevated privileges and tamper with protected services by disabling or otherwise preventing them to start. An attacker must already have administr...
CVE-2019-20357
PUBLISHED: 2020-01-18
A Persistent Arbitrary Code Execution vulnerability exists in the Trend Micro Security 2020 (v160 and 2019 (v15) consumer familiy of products which could potentially allow an attacker the ability to create a malicious program to escalate privileges and attain persistence on a vulnerable system.
CVE-2020-7222
PUBLISHED: 2020-01-18
An issue was discovered in Amcrest Web Server 2.520.AC00.18.R 2017-06-29 WEB 3.2.1.453504. The login page responds with JavaScript when one tries to authenticate. An attacker who changes the result parameter (to true) in this JavaScript code can bypass authentication and achieve limited privileges (...