Threat Advisory

CL-STA-0043 Group's Advanced Tactics and State-Sponsored Intrusions

Threat: Malware
Targeted Region: Middle East and Africa
Targeted Sector: Government & Defense
Criticality: High
[subscribe_to_unlock_form]

 

Summary: [/subscribe_to_unlock_form]

 

Summary: [emaillocker id="1283"]

A researcher has uncovered a series of espionage attacks targeting governmental entities in the Middle East and Africa. The attacks aimed to obtain sensitive information related to politicians, military activities, and foreign affairs ministries. The attacks were linked to a highly sophisticated and adaptive threat actor known as CL-STA-0043, suspected to be a nation-state. The attackers employed unique tactics and tools, including an in-memory VBS implant for covert webshell execution and a rare credential theft technique. Additionally, the attackers used a novel Exchange email exfiltration technique selectively on a few targets.

The attackers used multiple infection vectors, including exploiting zero-day vulnerabilities in IIS and Microsoft Exchange Servers. They deployed an in-memory VBS implant after failed attempts to execute the China Chopper webshell. The attackers conducted reconnaissance activities to identify critical assets and administrative accounts within the compromised network. They employed privilege escalation techniques such as the Potato Suite tools and the Sticky Keys attack. Credential theft methods included well-known techniques like Mimikatz, as well as a novel technique involving the creation of a malicious network provider. The attackers utilized a new penetration testing toolset called Yasso for lateral movement, targeting services like SMB, Winrm, SSH, and MSSQL.

Apart from using the Yasso toolset, the attackers employed various common techniques for lateral movement, including native Windows tools such as WMI, Scheduled Task, Winrs, Net, and Samba SMBclient. One of the notable techniques observed was the targeted exfiltration of email data from compromised Exchange servers. The attackers abused the Exchange Management Shell and used PowerShell scripts with added Exchange snap-ins to steal specific emails based on keywords and criteria. The stolen emails were saved as CSV or TIFF files, compressed, password-protected, and sent to the attacker's command and control server.

The investigation into CL-STA-0043 reveals previously undisclosed and rare techniques used by a highly sophisticated threat actor, potentially affiliated with a nation-state. The motives behind these attacks appear to be espionage-related, targeting sensitive geopolitical information and high-ranking public figures. The ongoing research aims to further uncover the identity and intentions of the threat actor involved.

 

Threat Profile:

Tactic Technique Id Technique
Initial Access T1190 Exploit Public-Facing Application
Execution T1059 Command and Scripting Interpreter
T1064 Scripting
T1053 Scheduled Task/Job
T1204 User Execution
 T1047 Windows Management Instrumentation
Persistence T1547 Boot or Logon AutoStart Execution
Privilege Escalation T1068 Exploitation for Privilege Escalation
T1546 Event Triggered Execution
Defense Evasion T1055 Process Injection
T1036 Masquerading
Credential Access T1003 OS Credential Access
T1110 Brute Force
Discovery T1046 Network Service Discovery
T1082 System Information Discovery
Lateral Movement T1021 Remote Services
Collection T1005 Data from Local System
Exfiltration T1041 Exfiltration Over C2 Channel

 

References:

The following reports contain further technical details:

https://thehackernews.com/2023/06/state-backed-hackers-employ-advanced.html

[/emaillocker]
crossmenu