Threat Advisory

Gamaredon's LitterDrifter USB Malware Extends Reach Beyond Ukraine

Threat: Malware
Criticality: High
[subscribe_to_unlock_form]

Summary:

Gamaredon, a discernible player in Russian espionage focusing predominantly on Ukrainian targets, exhibited conspicuous behavior despite the usual opacity surrounding Russian espionage activities. Within its recent operations, Gamaredon introduced LitterDrifter, a VBS-coded worm strategically engineered with dual functionalities: automatic USB drive propagation and the establishment of a dynamic command-and-control (C2) infrastructure. Gamaredon's primary focus remains Ukrainian entities, yet signs of possible infections have surfaced in various countries, suggesting broader reach.[/subscribe_to_unlock_form]

Summary:

Gamaredon, a discernible player in Russian espionage focusing predominantly on Ukrainian targets, exhibited conspicuous behavior despite the usual opacity surrounding Russian espionage activities. Within its recent operations, Gamaredon introduced LitterDrifter, a VBS-coded worm strategically engineered with dual functionalities: automatic USB drive propagation and the establishment of a dynamic command-and-control (C2) infrastructure. Gamaredon's primary focus remains Ukrainian entities, yet signs of possible infections have surfaced in various countries, suggesting broader reach.[emaillocker id="1283"]

LitterDrifter, the VBS-based worm, serves as a pivotal tool for USB drive dissemination and sustaining a resilient C2 channel. Despite its adaptable infrastructure, Gamaredon maintains consistent operational characteristics and patterns. LitterDrifter's architecture centers around "trash.dll," housing two pivotal modules. Spreader Module adeptly disseminates malware, with a particular emphasis on infiltrating removable USB drives. Leveraging the identification of NULL MediaType disks, it recursively accesses subfolders to implant hidden copies of "trash.dll" and generate LNK shortcuts. C2 Module Tasked with retrieving C2 server IPs, this module employs an innovative approach using domains as placeholders. Utilizing a WMI query, it generates a diverse range of subdomains, establishing dynamic communication channels. A fail-counter strategy is employed to manage C2 connections and payload execution, with varied methods to retrieve alternative C2 IPs, including utilizing Telegram channels as backups.

An exhaustive technical dive further dissects the functionality of the orchestration component, termed DEOBFUSCODER, unveiling its heavily obfuscated nature. This component decodes and executes additional modules while ensuring persistent infiltration by creating hidden files within user directories. The Spreader Module's operation involves intricate subfolder traversal and the strategic deployment of LNK decoy shortcuts alongside concealed copies of the malware within USB drives. Meanwhile, the C2 Module employs domain-based IP placeholders, utilizing WMI queries to dynamically retrieve IP addresses for operational C2 connections, enhancing adaptability and evasiveness. The scrutiny of Gamaredon's infrastructure highlights distinct patterns, predominantly utilizing domains registered by REGRU-RU. The C2 resolution method through WMI queries generates a myriad of subdomains, with frequent IP address rotations enhancing operational agility and thwarting detection.

LitterDrifter, embodying a Spreader and C2 module, stands as a testament to Gamaredon's strategic emphasis on large-scale data collection. Despite its seemingly straightforward design, the efficacy of its approach mirrors Gamaredon's persistent and successful operations in Ukraine.

Threat Profile:

References:

The following reports contain further technical details:

https://www.bleepingcomputer.com/news/security/gamaredons-littledrifter-usb-malware-spreads-beyond-ukraine/

[/emaillocker]
crossmenu