EXECUTIVE SUMMARY
Researcher's recent investigation uncovered a sophisticated cyber-espionage campaign orchestrated by a threat actor identified as UTA0137, suspected to be based in Pakistan. The campaign targets government entities in India, utilizing a custom Linux distribution known as BOSS. The malware used, named DISGOMOJI, is a Golang-based Linux malware variant that employs Discord for command and control (C2), utilizing emojis for communication. This novel approach, along with the use of Linux malware for initial access, indicates a targeted effort towards Linux desktop users within Indian government organizations.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY
Researcher's recent investigation uncovered a sophisticated cyber-espionage campaign orchestrated by a threat actor identified as UTA0137, suspected to be based in Pakistan. The campaign targets government entities in India, utilizing a custom Linux distribution known as BOSS. The malware used, named DISGOMOJI, is a Golang-based Linux malware variant that employs Discord for command and control (C2), utilizing emojis for communication. This novel approach, along with the use of Linux malware for initial access, indicates a targeted effort towards Linux desktop users within Indian government organizations.[emaillocker id="1283"]
DISGOMOJI, a modified version of discord-c2, is delivered through decoy documents and employs Discord channels for individual victim interaction. The malware establishes persistence through cron jobs, survives reboots, and includes functionalities for exfiltration and file manipulation. Commands are executed via Discord emojis, allowing the attacker to execute various actions remotely, including executing commands, taking screenshots, and exfiltrating files. The malware's evolution includes improvements such as dynamic retrieval of Discord credentials and preventing duplicate processes to run simultaneously. Additionally, the threat actor leverages known vulnerabilities like DirtyPipe for privilege escalation, indicating a thorough understanding of the target environment.
Researcher's analysis reveals a well-coordinated and evolving cyber-espionage campaign by UTA0137, targeting Indian government entities with DISGOMOJI malware. The attacker's use of Discord for C2, along with innovative tactics like emoji-based commands, demonstrates a level of sophistication aimed at evading detection. Furthermore, the attacker's post-exploitation techniques, including social engineering tactics and the use of known vulnerabilities, highlight a comprehensive strategy to infiltrate and maintain access to sensitive systems. The campaign's attribution to a Pakistan-based threat actor, combined with consistent targeting of Indian government organizations, emphasizes the geopolitical implications of such cyber threats and the need for enhanced cybersecurity measures.
THREAT PROFILE:
| Tactic | Technique Id | Technique |
| Initial Access | T1566 | Phishing |
| T1190 | Exploit Public-Facing Application | |
| Execution | T1059 | Command and Scripting Interpreter |
| T1053 | Scheduled Task/Job | |
| Persistence | T1547 | Boot or Logon Autostart Execution |
| Defense Evasion | T1027 | Obfuscated Files or Information |
| T1070 | Indicator Removal | |
| Discovery | T1082 | System Information Discovery |
| Collection | T1113 | Screen Capture |
| T1005 | Data from Local System | |
| Command and Control | T1219 | Remote Access Software |
| T1105 | Ingress Tool Transfer | |
| Exfiltration | T1041 | Exfiltration Over C2 Channel |
| Impact | T1485 | Data Destruction |
| T1529 | System Shutdown/Reboot |
REFERENCES:
The following reports contain further technical details:
[/emaillocker]