Threat Advisory

New Voldemort Malware Targets Global Organizations Through Tax Authority Phishing

Threat: Malware
Targeted Region: Global
Targeted Sector: Technology & IT, Finance & Banking, Aerospace & Aviation, Healthcare, Government & Defense, Energy & Utilities, Telecommunications, Critical Infrastructure, Retail & E-commerce, Education
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY

A sophisticated malware campaign involving custom malware named "Voldemort." This campaign features a novel attack chain that leverages various techniques for infiltration, command and control (C2). The malware primarily targets organizations worldwide by impersonating tax authorities from multiple countries, including the U.S., UK, France, Germany, Italy, India, and Japan. Despite the campaign’s broad reach and varied targets, the primary goal appears to be espionage rather than financial gain. The attack chain is notable for its unusual combination of methods, including using Google Sheets for C2 and employing a saved search file format to deploy malware.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY

A sophisticated malware campaign involving custom malware named "Voldemort." This campaign features a novel attack chain that leverages various techniques for infiltration, command and control (C2). The malware primarily targets organizations worldwide by impersonating tax authorities from multiple countries, including the U.S., UK, France, Germany, Italy, India, and Japan. Despite the campaign’s broad reach and varied targets, the primary goal appears to be espionage rather than financial gain. The attack chain is notable for its unusual combination of methods, including using Google Sheets for C2 and employing a saved search file format to deploy malware.[emaillocker id="1283"]

 

The Voldemort campaign affected over 20,000 emails impacting more than 70 organizations globally. Initial emails contained Google AMP Cache URLs leading to landing pages that redirected victims based on their browser's User Agent. Victims using Windows were prompted to open a Windows Explorer search that led to a fake PDF file or ZIP archive. Executing these files triggered the malware, which involved a backdoor written in C. It utilizes Python scripts hosted on WebDAV shares, enabling it to gather information and drop additional payloads. The malware communicates with its C2 infrastructure via Google Sheets, using Google Drive for exfiltration and command execution. This method allows the malware to bypass traditional security mechanisms and maintain a low profile.

 

The Voldemort malware campaign represents a blend of advanced persistent threat techniques and cybercriminal methods. Its use of Google Sheets and Drive for C2 and data exfiltration is particularly unconventional, showcasing the threat actor’s innovation in evading detection. The campaign's extensive use of impersonation and targeting across different sectors, including insurance and aerospace, highlights its broad scope and potential impact. Although the exact objectives remain unclear, the espionage capabilities of Voldemort and its sophisticated attack chain underline the evolving nature of cyber threats, merging traditional espionage with emerging cybercrime tactics.

THREAT PROFILE:

Tactic Technique ID Technique
Initial Access T1566 Phishing
Execution T1204 User Execution
T1059 Command and Scripting Interpreter
T1072 Software Deployment Tools
Defense Evasion T1078 Valid Accounts
T1140 Deobfuscate/Decode Files or Information
T1070 Indicator Removal
T1218 System Binary Proxy Execution
Credential Access T1555 Credentials from Password Stores
Discovery T1082 System Information Discovery
T1012 Query Registry
T1083 File and Directory Discovery
T1033 System Owner/User Discovery
Collection T1119 Automated Collection
Command and Control T1105 Ingress Tool Transfer
T1071 Application Layer Protocol: DNS
Exfiltration T1041 Exfiltration Over C2 Channel

REFERENCES:

The following reports contain further technical details:

https://www.bleepingcomputer.com/news/security/new-voldemort-malware-abuses-google-sheets-to-store-stolen-data/

[/emaillocker]
crossmenu