Threat Advisory

New Malware Wave Distributing OCEANMAP, MASEPIE, STEELHOOK

Threat: Malicious Campaign
Criticality: High
[subscribe_to_unlock_form]

Summary:

A series of email-based attacks targeted government organizations, leading to malware infections on compromised computers. Investigation revealed that malicious links redirected victims to a web resource using JavaScript and the "ms-search" application protocol, ultimately delivering a PowerShell command to download and execute a decoy document, Python interpreter, and MASEPIE client.py file.[/subscribe_to_unlock_form]

Summary:

A series of email-based attacks targeted government organizations, leading to malware infections on compromised computers. Investigation revealed that malicious links redirected victims to a web resource using JavaScript and the "ms-search" application protocol, ultimately delivering a PowerShell command to download and execute a decoy document, Python interpreter, and MASEPIE client.py file.[emaillocker id="1283"]

The MASEPIE tool facilitated the deployment of OPENSSH for tunneling, STEELHOOK PowerShell scripts to extract data from Chrome/Edge browsers, and the OCEANMAP backdoor. Within an hour of the initial compromise, additional tools like IMPACKET and SMBEXEC were created for network reconnaissance and horizontal movement attempts. The overall tactics, techniques, procedures, and tools used strongly align with the APT28 group's activities, indicating a sophisticated and potentially widespread cyberattack on the target organization's information and communication system.

Similar attacks were reported against Polish organizations. OCEANMAP, coded in C#, executed commands through cmd.exe using the IMAP protocol as a control channel. Configuration updates, command results, and persistence were managed through email drafts and the creation of specific files and registry entries. MASEPIE, coded in Python, focused on file operations and command execution over TCP, ensuring persistence through registry keys and startup directory manipulation.

The STEELHOOK PowerShell script specialized in data theft from Internet browsers. It intercepted sensitive browser data, encrypted it, and sent it to a command server via HTTP POST requests. The comprehensive nature of these attacks, attributed to APT28, underscores the potential threat to the entire network infrastructure due to compromised computers.

Threat Profile:

 

References:

The following reports contain further technical details:

https://thehackernews.com/2023/12/cert-ua-uncovers-new-malware-wave.html

[/emaillocker]
crossmenu