Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Cloud

8/12/2019
05:50 PM
Dark Reading
Dark Reading
Products and Releases
50%
50%

Kaspersky Research Finds Cloud Atlas APT Upgraded with Polymorphic Malware

Woburn, MA – August 12, 2019 – Kaspersky research has found that Cloud Atlas, an advanced persistent threat (APT) also known as Inception, has enhanced its attack arsenal with new tools that allow it to avoid detection through standard Indicators of Compromise (IoC). This updated infection chain has been spotted in different organizations in Eastern Europe, Central Asia and Russia.

Cloud Atlas has a long history of cyber-espionage operations targeting industries, government agencies and other entities. The threat actor was first identified in 2014 and has been active ever since. Recently, Kaspersky researchers have seen Cloud Atlas targeting the international economics and aerospace industries as well as government and religious organizations in Portugal, Romania, Turkey, Ukraine, Russia, Turkmenistan, Afghanistan and Kyrgyzstan among other countries.

Upon successful infiltration, Cloud Atlas will:

  • Collect information about the system it has gained access to
  • Log passwords
  • Exfiltrate recent .txt .pdf. xls .doc files to a command and control server

While Cloud Atlas hasn’t dramatically changed its tactics, research from recent waves of attacks have discovered a new technique of infecting victims including lateral movement through networks.

Previously, Cloud Atlas would first send a spear-phishing email with a malicious attachment to a target. In the case of a successful exploitation, PowerShower, the attached malware used for initial investigation and to download additional malicious modules, would then be executed to allow cyberattackers to proceed with an operation.

The newly updated chain of infection postpones the execution of PowerShower until a later stage. Instead, after the initial infection, a malicious HTML app is now downloaded and executed on the target machine. This application will then collect initial information about the attacked computer and download and execute VBShower, another malicious module. VBShower then erases evidence of the presence of malware in the system and consults with its masters through command and control servers to decide on further actions. Depending on the command received, this malware will then download and execute either PowerShower or another well-known Cloud Atlas second stage backdoor.

While this new infection chain is more complicated than the previous model, its main differentiator is that a malicious HTML application and the VBShower module are polymorphic. This means that the code in both modules will be new and unique in each case of infection. According to Kaspersky experts, this updated version is carried out in order to make the malware invisible to security solutions relying on familiar IoCs.

“It has become good practice in the security community to share the IoC of malicious operations we find through research. This practice allows us to respond to ongoing international cyber-espionage operations quite swiftly, preventing any further damage they could cause,” said Felix Aime, security researcher in the Kaspersky Global Research and Analysis Team. “However, as we predicted as early as 2016, IoC have become obsolete as a reliable tool to spot a targeted attack in your network. This first emerged with ProjectSauron, which would create a unique set of IoC for each of its victims and continued with the trend of using open source tools in espionage operations instead of unique ones. Now this is continuing with this recent example of polymorphic malware. This doesn’t mean that actors are becoming harder to catch, but that security skills and the defenders toolkit needs to evolve along with the toolkit and skills of the malicious actors they are tracking.”

Kaspersky recommends that organizations use anti-targeted attack solutions enhanced with Indicators of Attack (IoA) that focus on the tactics, techniques or actions that malefactors may take when preparing for an attack. IoAs track the techniques deployed, no matter what specific tools are used. The latest versions of Kaspersky Endpoint Detection and Response and Kaspersky Anti Targeted Attack both feature a new database of IoAs, maintained and updated by Kaspersky’s own expert threat hunters.

 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
COVID-19: Latest Security News & Commentary
Dark Reading Staff 7/6/2020
Russian Cyber Gang 'Cosmic Lynx' Focuses on Email Fraud
Kelly Sheridan, Staff Editor, Dark Reading,  7/7/2020
Another COVID-19 Side Effect: Rising Nation-State Cyber Activity
Stephen Ward, VP, ThreatConnect,  7/1/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Special Report: Computing's New Normal, a Dark Reading Perspective
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
The Threat from the Internetand What Your Organization Can Do About It
The Threat from the Internetand What Your Organization Can Do About It
This report describes some of the latest attacks and threats emanating from the Internet, as well as advice and tips on how your organization can mitigate those threats before they affect your business. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-15600
PUBLISHED: 2020-07-07
An issue was discovered in CMSUno before 1.6.1. uno.php allows CSRF to change the admin password.
CVE-2020-15599
PUBLISHED: 2020-07-07
Victor CMS through 2019-02-28 allows XSS via the register.php user_firstname or user_lastname field.
CVE-2020-8916
PUBLISHED: 2020-07-07
A memory leak in Openthread's wpantund versions up to commit 0e5d1601febb869f583e944785e5685c6c747be7, when used in an environment where wpanctl is directly interfacing with the control driver (eg: debug environments) can allow an attacker to crash the service (DoS). We recommend updating, or to res...
CVE-2020-12821
PUBLISHED: 2020-07-07
Gossipsub 1.0 does not properly resist invalid message spam, such as an eclipse attack or a sybil attack.
CVE-2020-15008
PUBLISHED: 2020-07-07
A SQLi exists in the probe code of all Connectwise Automate versions before 2020.7 or 2019.12. A SQL Injection in the probe implementation to save data to a custom table exists due to inadequate server side validation. As the code creates dynamic SQL for the insert statement and utilizes the user su...