Summary: [/subscribe_to_unlock_form]
Summary: [emaillocker id="1283"]
A researcher has uncovered a series of espionage attacks targeting governmental entities in the Middle East and Africa. The attacks aimed to obtain sensitive information related to politicians, military activities, and foreign affairs ministries. The attacks were linked to a highly sophisticated and adaptive threat actor known as CL-STA-0043, suspected to be a nation-state. The attackers employed unique tactics and tools, including an in-memory VBS implant for covert webshell execution and a rare credential theft technique. Additionally, the attackers used a novel Exchange email exfiltration technique selectively on a few targets.
The attackers used multiple infection vectors, including exploiting zero-day vulnerabilities in IIS and Microsoft Exchange Servers. They deployed an in-memory VBS implant after failed attempts to execute the China Chopper webshell. The attackers conducted reconnaissance activities to identify critical assets and administrative accounts within the compromised network. They employed privilege escalation techniques such as the Potato Suite tools and the Sticky Keys attack. Credential theft methods included well-known techniques like Mimikatz, as well as a novel technique involving the creation of a malicious network provider. The attackers utilized a new penetration testing toolset called Yasso for lateral movement, targeting services like SMB, Winrm, SSH, and MSSQL.
Apart from using the Yasso toolset, the attackers employed various common techniques for lateral movement, including native Windows tools such as WMI, Scheduled Task, Winrs, Net, and Samba SMBclient. One of the notable techniques observed was the targeted exfiltration of email data from compromised Exchange servers. The attackers abused the Exchange Management Shell and used PowerShell scripts with added Exchange snap-ins to steal specific emails based on keywords and criteria. The stolen emails were saved as CSV or TIFF files, compressed, password-protected, and sent to the attacker's command and control server.
The investigation into CL-STA-0043 reveals previously undisclosed and rare techniques used by a highly sophisticated threat actor, potentially affiliated with a nation-state. The motives behind these attacks appear to be espionage-related, targeting sensitive geopolitical information and high-ranking public figures. The ongoing research aims to further uncover the identity and intentions of the threat actor involved.
Threat Profile:
| Tactic | Technique Id | Technique |
| Initial Access | T1190 | Exploit Public-Facing Application |
| Execution | T1059 | Command and Scripting Interpreter |
| T1064 | Scripting | |
| T1053 | Scheduled Task/Job | |
| T1204 | User Execution | |
| T1047 | Windows Management Instrumentation | |
| Persistence | T1547 | Boot or Logon AutoStart Execution |
| Privilege Escalation | T1068 | Exploitation for Privilege Escalation |
| T1546 | Event Triggered Execution | |
| Defense Evasion | T1055 | Process Injection |
| T1036 | Masquerading | |
| Credential Access | T1003 | OS Credential Access |
| T1110 | Brute Force | |
| Discovery | T1046 | Network Service Discovery |
| T1082 | System Information Discovery | |
| Lateral Movement | T1021 | Remote Services |
| Collection | T1005 | Data from Local System |
| Exfiltration | T1041 | Exfiltration Over C2 Channel |
References:
The following reports contain further technical details:
https://thehackernews.com/2023/06/state-backed-hackers-employ-advanced.html
[/emaillocker]