Threat Advisory

Iranian APT Group OilRig Using New Menorah Malware for Covert Operations

Threat: Malware
Criticality: High
[subscribe_to_unlock_form]

Summary:

The analysis revolves around a new malware attributed to the APT34 advanced persistent threat (APT) group, which engaged in a targeted phishing attack. A malicious document named "MyCv.doc" was discovered, originating from APT34 and seemingly targeting organizations within the Kingdom of Saudi Arabia. The document dropped a new malware, Menorah which detected as Trojan.W97M.SIDETWIST. AB, responsible for cyberespionage. APT34, known for its cyberespionage activities in the Middle East, employs spear phishing campaigns and advanced techniques to infiltrate networks, consistently evolving its tools to reduce detection.[/subscribe_to_unlock_form]

Summary:

The analysis revolves around a new malware attributed to the APT34 advanced persistent threat (APT) group, which engaged in a targeted phishing attack. A malicious document named "MyCv.doc" was discovered, originating from APT34 and seemingly targeting organizations within the Kingdom of Saudi Arabia. The document dropped a new malware, Menorah which detected as Trojan.W97M.SIDETWIST. AB, responsible for cyberespionage. APT34, known for its cyberespionage activities in the Middle East, employs spear phishing campaigns and advanced techniques to infiltrate networks, consistently evolving its tools to reduce detection.[emaillocker id="1283"]

 

Execution Flow

Menorah, a .NET-written malware, is designed for cyberespionage and exhibits a range of capabilities, including system fingerprinting, file manipulation, and communication with a command and control (C&C) server. Notably, it employs stealthy techniques, such as argument checks for sandbox detection. The malware communicates with the C&C server through an inactive URL and creates a unique fingerprint for each compromised system, incorporating the machine name, username, and MD5 hash. It can execute commands from the C&C server, list files and directories, and upload/download files. This analysis also highlights similarities between Menorah and the SideTwist backdoor, suggesting APT34's continuous development and adaptation of its techniques.

APT34, a formidable cyberespionage group, demonstrates adaptability and resourcefulness in its pursuit of sensitive intelligence in the Middle East. While Menorah's techniques may not be as sophisticated as previous APT34 attacks, the group's ability to rapidly develop and deploy new malware and tools remains a significant threat. Their persistence in using tried-and-tested routines underscores the importance of organizations continuously educating and alerting employees about evolving attack techniques. APT34's ongoing evolution underscores the need for vigilance and robust cybersecurity measures in the face of persistent and determined adversaries.

 Threat Profile:

References:

The following reports contain further technical details:

https://thehackernews.com/2023/09/iranian-apt-group-oilrig-using-new.html

[/emaillocker]
crossmenu