Threat Advisory

Hackers use new PowerMagic and CommonMagic malware to steal data

Threat: Malware
Threat Actor Type: APT
Targeted Region: Donetsk, Lugansk & Crimea
Targeted Sector: Government & Defense
Criticality: High
[subscribe_to_unlock_form]

 

Summary: [/subscribe_to_unlock_form]

 

Summary: [emaillocker id="1283"]

Researchers have Discovered attacks by a sophisticated threat actor which used the new backdoor PowerMagic and a previously undiscovered malicious framework CommonMagic. These malware components have been used in continuing operations targeting organizations in the transportation, agricultural, and administrative sectors since at least September 2021. the hackers are trying to get information from victims in Crimea, Donetsk, and Lugansk.

The attackers behind the CommonMagic espionage operation can use different plugins once they have gained access to the victim network to steal files and documents (DOC, DOCX, XLS, XLSX, RTF, ODT, ODS, ZIP, RAR, TXT, PDF) from USB drives. The malware can also use the Windows Graphics Device Interface (GDI) API to take screenshots every three seconds. After that, a URL linking to a ZIP package containing a malicious LNK file (Windows shortcut files) is delivered via spear phishing or a similar technique as the initial infection vector. The target user was diverted from the harmful activity that began in the background when the LNK file disguised as a PDF was launched by a false document (PDF, XLSX, or DOCX) in the archive. A previously unidentified PowerShell-based backdoor called PowerMagic. The malware code would be installed on the machine as a result of the malicious LNK.

 

Infection Chain

 

The Backdoor is using OneDrive and Dropbox folders with the command and control (C2) server to receive instructions and upload the results. The hackers created specific modules For a variety of functions, including communicating with the C2, collecting and decrypting communications from the command server, stealing files, and taking screenshots. The data are encrypted using the open-source RC5Simple library with a unique sequence, Hwo7X8p, at the start of the encryption. The C2 is similarly carried out via a OneDrive folder.

 

Threat Profile:

Tactic Technique Id Technique
Initial Access T1566 Phishing
 Execution T1204 User Execution
T1059 Command and Scripting Interpreter
T1053 Scheduled Task/Job
T1567 Exfiltration Over Web Service
 Defense Evasion T1036 Masquerading
T1070 Indicator Removal
T1222 File and Directory Permissions Modification
 Collection T1560 Archive Collected Data
T1113 Screen Capture
 Command and Control T1102 Web Service
T1105 Ingress Tool Transfer
Impact T1486 Data Encrypted for Impact

 

References:

The following reports contain further technical details:

https://www.bleepingcomputer.com/news/security/hackers-use-new-powermagic-and-commonmagic-malware-to-steal-data/

[/emaillocker]
crossmenu