Threat Advisory

AtlasCross APT Attacker Unveiled in Targeted Phishing Campaign

Threat: Malware
Criticality: High
[subscribe_to_unlock_form]

Summary:

A new advanced persistent threat (APT) actor, referred to as "AtlasCross," engaging in targeted cyberattacks. This sophisticated attacker employs meticulous techniques, including phishing documents, and has introduced two new Trojan horse programs, named "DangerAds" and "AtlasAgent." AtlasCross primarily focuses on infiltrating specific network domains, displaying a high level of technical proficiency and a cautious approach. Their attack methodology consists of a multi-phase process, involving decoy documents, loader components, and Trojan horse payloads. The attacker's actions indicate potential for larger-scale network attack operations in the future.[/subscribe_to_unlock_form]

Summary:

A new advanced persistent threat (APT) actor, referred to as "AtlasCross," engaging in targeted cyberattacks. This sophisticated attacker employs meticulous techniques, including phishing documents, and has introduced two new Trojan horse programs, named "DangerAds" and "AtlasAgent." AtlasCross primarily focuses on infiltrating specific network domains, displaying a high level of technical proficiency and a cautious approach. Their attack methodology consists of a multi-phase process, involving decoy documents, loader components, and Trojan horse payloads. The attacker's actions indicate potential for larger-scale network attack operations in the future.[emaillocker id="1283"]


Execution Flow

AtlasCross initiates its attacks with decoy documents, using malicious macros to extract and execute payloads while setting up scheduled tasks for stealthy execution. These malicious macros also communicate with specific network locations to count victims. The loader phase involves the deployment of "DangerAds," which detects the host environment and executes shellcode. Importantly, this loader only activates within specific usernames or local domains, suggesting intranet penetration as a key objective. The final stage features "AtlasAgent," which obtains host information, executes shellcode, and communicates with command-and-control servers via multiple backup channels. Notably, AtlasCross employs advanced evasion techniques such as process injection, reflective loading, API obfuscation, and anti-virtualization measures.

AtlasCross represents a formidable APT actor characterized by a cautious, adaptable, and sophisticated approach to cyberattacks. Their resource development involves compromising numerous public network hosts through known vulnerabilities, while persistence is achieved through scheduled tasks, designed to evade detection. The attacker's arsenal includes shellcode injection, API encryption, and anti-analysis measures, demonstrating a clear understanding of defense evasion. With a robust command and control infrastructure and a focus on targeted intranet penetration, AtlasCross poses a significant threat to potential targets. Organizations should remain vigilant and proactive in defending against such advanced threats.

Threat Profile:

References:

The following reports contain further technical details:

https://www.bleepingcomputer.com/news/security/new-atlascross-hackers-use-american-red-cross-as-phishing-lure/

[/emaillocker]
crossmenu