EXECUTIVE SUMMARY
A sophisticated malware campaign involving custom malware named "Voldemort." This campaign features a novel attack chain that leverages various techniques for infiltration, command and control (C2). The malware primarily targets organizations worldwide by impersonating tax authorities from multiple countries, including the U.S., UK, France, Germany, Italy, India, and Japan. Despite the campaign’s broad reach and varied targets, the primary goal appears to be espionage rather than financial gain. The attack chain is notable for its unusual combination of methods, including using Google Sheets for C2 and employing a saved search file format to deploy malware.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY
A sophisticated malware campaign involving custom malware named "Voldemort." This campaign features a novel attack chain that leverages various techniques for infiltration, command and control (C2). The malware primarily targets organizations worldwide by impersonating tax authorities from multiple countries, including the U.S., UK, France, Germany, Italy, India, and Japan. Despite the campaign’s broad reach and varied targets, the primary goal appears to be espionage rather than financial gain. The attack chain is notable for its unusual combination of methods, including using Google Sheets for C2 and employing a saved search file format to deploy malware.[emaillocker id="1283"]
The Voldemort campaign affected over 20,000 emails impacting more than 70 organizations globally. Initial emails contained Google AMP Cache URLs leading to landing pages that redirected victims based on their browser's User Agent. Victims using Windows were prompted to open a Windows Explorer search that led to a fake PDF file or ZIP archive. Executing these files triggered the malware, which involved a backdoor written in C. It utilizes Python scripts hosted on WebDAV shares, enabling it to gather information and drop additional payloads. The malware communicates with its C2 infrastructure via Google Sheets, using Google Drive for exfiltration and command execution. This method allows the malware to bypass traditional security mechanisms and maintain a low profile.
The Voldemort malware campaign represents a blend of advanced persistent threat techniques and cybercriminal methods. Its use of Google Sheets and Drive for C2 and data exfiltration is particularly unconventional, showcasing the threat actor’s innovation in evading detection. The campaign's extensive use of impersonation and targeting across different sectors, including insurance and aerospace, highlights its broad scope and potential impact. Although the exact objectives remain unclear, the espionage capabilities of Voldemort and its sophisticated attack chain underline the evolving nature of cyber threats, merging traditional espionage with emerging cybercrime tactics.
THREAT PROFILE:
| Tactic | Technique ID | Technique |
| Initial Access | T1566 | Phishing |
| Execution | T1204 | User Execution |
| T1059 | Command and Scripting Interpreter | |
| T1072 | Software Deployment Tools | |
| Defense Evasion | T1078 | Valid Accounts |
| T1140 | Deobfuscate/Decode Files or Information | |
| T1070 | Indicator Removal | |
| T1218 | System Binary Proxy Execution | |
| Credential Access | T1555 | Credentials from Password Stores |
| Discovery | T1082 | System Information Discovery |
| T1012 | Query Registry | |
| T1083 | File and Directory Discovery | |
| T1033 | System Owner/User Discovery | |
| Collection | T1119 | Automated Collection |
| Command and Control | T1105 | Ingress Tool Transfer |
| T1071 | Application Layer Protocol: DNS | |
| Exfiltration | T1041 | Exfiltration Over C2 Channel |
REFERENCES:
The following reports contain further technical details:
[/emaillocker]