Threat Advisory

BellaCiao Malware Targets Systems with .NET and C++ Variants

Threat: Malware
Threat Actor Name: APT35
Threat Actor Type: State-Sponsored
Targeted Region: Asia
Alias: G0003, G0059, Charming Kitten, Temp.Beanie, UNC788, Phosphorus, Mint Sandstorm, NewsBeef, Magic Hound, TA453, Timberworm, ITG18, Cobalt illusion, Cobalt Mirage, C-Major, Educated Manticore, Yellow Garuda, TG-2889, Group41, Tarh Andishan, Newscaster, Ali Baba, TunnelVision, Ballistic Bobcat, CharmingCypress
Threat Actor Region: Iran
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY

The BellaCiao malware family exemplifies a unique blend of persistence and stealth, as demonstrated through its evolution from .NET to C++ implementations. Initially surfacing in early spring, the malware’s distinguishing features include a sophisticated versioning system identifiable through descriptive PDB paths. These paths not only reveal insights into campaign details, such as target identifiers and regions, but also illustrate the malware’s developmental maturity. BellaCiao samples frequently use identifiers like “MicrosoftAgentServices” with appended integers, indicating a structured versioning scheme. This meticulous evolution reflects a focused effort to enhance the malware's capabilities, enabling the threat actor to refine their operational efficiency and maintain versatility in attack methodologies.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY

The BellaCiao malware family exemplifies a unique blend of persistence and stealth, as demonstrated through its evolution from .NET to C++ implementations. Initially surfacing in early spring, the malware’s distinguishing features include a sophisticated versioning system identifiable through descriptive PDB paths. These paths not only reveal insights into campaign details, such as target identifiers and regions, but also illustrate the malware’s developmental maturity. BellaCiao samples frequently use identifiers like “MicrosoftAgentServices” with appended integers, indicating a structured versioning scheme. This meticulous evolution reflects a focused effort to enhance the malware's capabilities, enabling the threat actor to refine their operational efficiency and maintain versatility in attack methodologies.[emaillocker id="1283"]

The emergence of BellaCPP, a C++-based variant of the BellaCiao malware family, highlighting its adaptability across different programming environments. Discovered on an already-compromised system, BellaCPP mirrors much of the functionality of its .NET predecessor while eliminating certain components, such as the webshell. It demonstrates robust functionality by leveraging XOR encryption to conceal critical elements and generating custom domains for C2 operations. These domains follow structured patterns, facilitating covert communications with the attacker. Despite gaps in analysis due to missing files, evidence suggests that BellaCPP's workflow aligns closely with BellaCiao’s, employing techniques like SSH tunneling to maintain network persistence. These developments underscore the threat actor's commitment to innovating their malware arsenal, likely to bypass evolving defensive mechanisms.

The investigation into BellaCiao and its C++ iteration reflects a sophisticated and evolving threat landscape. The transition from .NET to C++ demonstrates adaptability, while the absence of a webshell in BellaCPP signals a strategic shift to reduce detection risk. Researchers attribute the malware’s persistence and operational enhancements to a prominent actor in the cyber threat domain. This case highlights the significance of examining every layer of network compromise, as attackers continually adapt their strategies to retain access. These findings emphasize the critical importance of comprehensive cybersecurity measures to address advanced, multi-faceted threats effectively.

THREAT PROFILE:

Tactic Technique ID Technique
Execution T1203 Exploitation for Client Execution
T1059 Command and Scripting Interpreter
Persistence T1547 Boot or Logon Autostart Execution
Defense Evasion T1140 Deobfuscate/Decode Files or Information
T1036 Masquerading
Credential Access T1555 Credentials from Password Stores
Discovery T1082 System Information Discovery
T1012 Query Registry
Command and Control T1071 Application Layer Protocol
T1573 Encrypted Channel
Exfiltration T1041 Exfiltration Over C2 Channel

REFERENCES:

The following reports contain further technical details:

https://securelist.com/bellacpp-cpp-version-of-bellaciao/115087/

[/emaillocker]
crossmenu