Summary:
Researchers has issued a warning about a new wave of cyberattacks orchestrated by the Russian state-sponsored Turla hacking group. This advanced persistent threat actor (APT), also known as Secret Blizzard, KRYPTON, and UAC-0003, has a history of targeting Western interests, including the recently disrupted Snake cyber-espionage malware botnet under Operation MEDUSA.[/subscribe_to_unlock_form]
Summary:
Researchers has issued a warning about a new wave of cyberattacks orchestrated by the Russian state-sponsored Turla hacking group. This advanced persistent threat actor (APT), also known as Secret Blizzard, KRYPTON, and UAC-0003, has a history of targeting Western interests, including the recently disrupted Snake cyber-espionage malware botnet under Operation MEDUSA.[emaillocker id="1283"]
The recent attacks identified by researchers focus on the defense sector in Ukraine and Eastern Europe. The modus operandi begins with phishing emails carrying Excel XLSM attachments embedded with malicious macros. Once these macros are activated, they execute a PowerShell command, creating a scheduled task that impersonates a Firefox browser updater. The real danger lies in this task's download of the DeliveryCheck backdoor (also referred to as CapiBar and GAMEDAY), which is then executed in memory. This backdoor connects to the threat actor's command and control server, receiving instructions to carry out additional malware deployments or execute specific commands. Of particular concern is the use of XSLT stylesheets to embed and launch these malware payloads. Notably, the DeliveryCheck malware distinguishes itself by its targeting of Microsoft Exchange servers.
It installs a server-side component on the Exchange server using Desired State Configuration (DSC), a PowerShell module meant to standardize server configurations automatically. The threat actors exploit DSC to load a base64-encoded Windows executable, essentially converting the Exchange server into a command and control server for their use. During these attacks, Turla also deploys the KAZUAR information-stealing backdoor, which is described as a "fully-featured Secret Blizzard implant." This malware enables the threat actors to launch JavaScript on infected devices, extract data from event logs, gather system file information, and steal authentication tokens, cookies, and credentials from various applications, including browsers, FTP clients, VPN software, KeePass, Azure, AWS, and Outlook. One alarming aspect is Turla's specific interest in exfiltrating files containing messages from the popular Signal Desktop messaging application. This capability would grant the threat actors access to private Signal conversations, as well as various documents, images, and archive files stored on targeted systems.
The Russian state-sponsored Turla hacking group continues to pose a significant cybersecurity threat, with recent attacks focusing on the defense industry and Microsoft Exchange servers. The use of sophisticated tactics, such as malicious macros in phishing emails, PowerShell commands, and DSC exploitation, highlights the group's advanced capabilities. Organizations, especially those in the defense sector and using Microsoft Exchange, should be vigilant against these attacks and ensure robust cybersecurity measures are in place to protect against such threats. Collaborative efforts between security teams and cybersecurity providers are essential to detect and mitigate Turla's evolving tactics effectively.
Threat Profile:

References:
The following reports contain further technical details:
[/emaillocker]