Threat Advisory

Clasiopa hackers use new Atharvan malware in targeted attacks

Threat: Malware
Targeted Region: Asia
Threat Actor Region: India
Criticality: High
[subscribe_to_unlock_form]

 

Summary: [/subscribe_to_unlock_form]

 

Summary: [emaillocker id="1283"]

Security experts have identified a hacking group that targets companies in the materials research industry using a special toolkit that includes a customized remote access trojan (RAT) named Atharvan. Upon a compromise, attackers take a variety of actions. Clasiopa also utilized authorized software to sign with an outdated certification. The hacker used two backdoors for their attack, custom Atharvan and open-source Lilith RAT. After that, they utilize the compromised system to run PowerShell scripts, execute commands, and control processes. The hardcoded command and control (C2) address is contacted after the custom backdoor has been executed and before it establishes a mutex to prevent multiple instances of itself from running. The unique aspect is that it can be set up for scheduled communication with the C2 and can even be made to attempt connections on particular days of the week or at specific times. The researchers point out that some methods are used to protect Atharvan's contacts with the C2. Atharvan can download data from the infected machine run executables, execute commands, and exfiltrate the output.

 

Threat Profile:

   Tactic Technique id Technique
Resource Development T1587 Develop Capabilities
Execution T1053 Scheduled Task/Job
T1204 User Execution
T1059 Command and Scripting Interpreter
Defense Evasion T1562 Impair Defenses
T1070 Indicator Removal
T1055 Process Injection
T1562 Impair Defenses
Credential Access T1110 Brute Force
Discovery T1016 System Network Configuration Discovery
Command and Control T1219 Remote Access Software
Impact T1489 Service Stop
T1529 System Shutdown/Reboot

 

References:

The following reports contain further technical details:

https://www.bleepingcomputer.com/news/security/clasiopa-hackers-use-new-atharvan-malware-in-targeted-attacks/

[/emaillocker]
crossmenu