Summary: [/subscribe_to_unlock_form]
Summary: [emaillocker id="1283"]
Researchers have Discovered attacks by a sophisticated threat actor which used the new backdoor PowerMagic and a previously undiscovered malicious framework CommonMagic. These malware components have been used in continuing operations targeting organizations in the transportation, agricultural, and administrative sectors since at least September 2021. the hackers are trying to get information from victims in Crimea, Donetsk, and Lugansk.
The attackers behind the CommonMagic espionage operation can use different plugins once they have gained access to the victim network to steal files and documents (DOC, DOCX, XLS, XLSX, RTF, ODT, ODS, ZIP, RAR, TXT, PDF) from USB drives. The malware can also use the Windows Graphics Device Interface (GDI) API to take screenshots every three seconds. After that, a URL linking to a ZIP package containing a malicious LNK file (Windows shortcut files) is delivered via spear phishing or a similar technique as the initial infection vector. The target user was diverted from the harmful activity that began in the background when the LNK file disguised as a PDF was launched by a false document (PDF, XLSX, or DOCX) in the archive. A previously unidentified PowerShell-based backdoor called PowerMagic. The malware code would be installed on the machine as a result of the malicious LNK.

Infection Chain
The Backdoor is using OneDrive and Dropbox folders with the command and control (C2) server to receive instructions and upload the results. The hackers created specific modules For a variety of functions, including communicating with the C2, collecting and decrypting communications from the command server, stealing files, and taking screenshots. The data are encrypted using the open-source RC5Simple library with a unique sequence, Hwo7X8p, at the start of the encryption. The C2 is similarly carried out via a OneDrive folder.
Threat Profile:
| Tactic | Technique Id | Technique |
| Initial Access | T1566 | Phishing |
| Execution | T1204 | User Execution |
| T1059 | Command and Scripting Interpreter | |
| T1053 | Scheduled Task/Job | |
| T1567 | Exfiltration Over Web Service | |
| Defense Evasion | T1036 | Masquerading |
| T1070 | Indicator Removal | |
| T1222 | File and Directory Permissions Modification | |
| Collection | T1560 | Archive Collected Data |
| T1113 | Screen Capture | |
| Command and Control | T1102 | Web Service |
| T1105 | Ingress Tool Transfer | |
| Impact | T1486 | Data Encrypted for Impact |
References:
The following reports contain further technical details:
[/emaillocker]