Threat Advisory

New Linux malware is controlled through emojis sent from Discord

Threat: Malware
Threat Actor Name: UTA0137
Threat Actor Type: Espionage
Targeted Region: India
Threat Actor Region: Pakistan
Targeted Sector: Government & Defense
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY

Researcher's recent investigation uncovered a sophisticated cyber-espionage campaign orchestrated by a threat actor identified as UTA0137, suspected to be based in Pakistan. The campaign targets government entities in India, utilizing a custom Linux distribution known as BOSS. The malware used, named DISGOMOJI, is a Golang-based Linux malware variant that employs Discord for command and control (C2), utilizing emojis for communication. This novel approach, along with the use of Linux malware for initial access, indicates a targeted effort towards Linux desktop users within Indian government organizations.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY

Researcher's recent investigation uncovered a sophisticated cyber-espionage campaign orchestrated by a threat actor identified as UTA0137, suspected to be based in Pakistan. The campaign targets government entities in India, utilizing a custom Linux distribution known as BOSS. The malware used, named DISGOMOJI, is a Golang-based Linux malware variant that employs Discord for command and control (C2), utilizing emojis for communication. This novel approach, along with the use of Linux malware for initial access, indicates a targeted effort towards Linux desktop users within Indian government organizations.[emaillocker id="1283"]

DISGOMOJI, a modified version of discord-c2, is delivered through decoy documents and employs Discord channels for individual victim interaction. The malware establishes persistence through cron jobs, survives reboots, and includes functionalities for exfiltration and file manipulation. Commands are executed via Discord emojis, allowing the attacker to execute various actions remotely, including executing commands, taking screenshots, and exfiltrating files. The malware's evolution includes improvements such as dynamic retrieval of Discord credentials and preventing duplicate processes to run simultaneously. Additionally, the threat actor leverages known vulnerabilities like DirtyPipe for privilege escalation, indicating a thorough understanding of the target environment.

Researcher's analysis reveals a well-coordinated and evolving cyber-espionage campaign by UTA0137, targeting Indian government entities with DISGOMOJI malware. The attacker's use of Discord for C2, along with innovative tactics like emoji-based commands, demonstrates a level of sophistication aimed at evading detection. Furthermore, the attacker's post-exploitation techniques, including social engineering tactics and the use of known vulnerabilities, highlight a comprehensive strategy to infiltrate and maintain access to sensitive systems. The campaign's attribution to a Pakistan-based threat actor, combined with consistent targeting of Indian government organizations, emphasizes the geopolitical implications of such cyber threats and the need for enhanced cybersecurity measures.

THREAT PROFILE:

Tactic Technique Id Technique
Initial Access T1566 Phishing
T1190 Exploit Public-Facing Application
Execution T1059 Command and Scripting Interpreter
T1053 Scheduled Task/Job
Persistence T1547 Boot or Logon Autostart Execution
Defense Evasion T1027 Obfuscated Files or Information
T1070 Indicator Removal
Discovery T1082 System Information Discovery
Collection T1113 Screen Capture
T1005 Data from Local System
Command and Control T1219 Remote Access Software
T1105 Ingress Tool Transfer
Exfiltration T1041 Exfiltration Over C2 Channel
Impact T1485 Data Destruction
T1529 System Shutdown/Reboot

REFERENCES:

The following reports contain further technical details:

https://www.bleepingcomputer.com/news/security/new-linux-malware-is-controlled-through-emojis-sent-from-discord/

[/emaillocker]
crossmenu