APT

New APT ChamelGang Targets energy and aviation companies in Russia

ChamelGang APT is a new cyberespionage group that focuses on fuel and energy organizations and aviation industry in Russia

ChamelGang is a new APT group that was first spotted in March by researchers at security firm Positive Technologies, it targets Russian companies in the energy and aviation industry.

In March, the cyberespionage group was observed leveraging ProxyShell against targets in 10 countries and used a variety of malware in its campaign.

Now the group is targeting organizations in Russia by exploiting known vulnerabilities like Microsoft Exchange ProxyShell issues, it also used a new set of malware to exfiltrate sensitive information from target networks.

The name ChamelGang comes from the word “chameleon” that was used because the group disguised its malware and network infrastructure under legitimate services of Microsoft, TrendMicro, McAfee, IBM, and Google.

The threat actors used domains mimicking legitimate ones (newtrendmicro.com, centralgoogle.com, microsoft-support.net, cdn-chrome.com, mcafee-upgrade.com) and installed SSL certificates on its servers that imitated legitimate ones (github.com, www.ibm.com, jquery.com, update.microsoft-support.net) on its servers.

Experts pointed out that the ChamelGang group was also involved in supply chain attacks in order to hit the actual victims.

The analysis of the techniques used by the threat actors revealed that the ChamelGang group used both known malicious software (i.e. FRP, Cobalt Strike Beacon, and Tiny Shell) and previously undetected malware tracked as ProxyT, BeaconLoader and the DoorMe backdoor.

Positive Technologies experts investigated two attacks conducted by APT that took place in March and August respectively.

The March attack was spotted after the experts noticed that the antivirus software installed on the systems of a Russia-based energy company repeatedly reported the presence of the Cobalt Strike Beacon in RAM.

“At the end of March 2021, the attackers compromised a subsidiary organization to gain access to the energy company’s network, using a vulnerable version of a web application on the JBoss Application Server platform. The investigation revealed that the attackers, having exploited vulnerability CVE-2017-12149, were able to remotely execute commands on the host.” reads the analysis published by the experts. “When analyzing the server logs, vuln6581362514513155613jboss records were found on the compromised host, indicating that the public exploit jboss-_CVE-2017-12149 had been used.”

Once gained access to the target network through a supply chain attack, the attackers deployed post-exploitations tools to maintain persistence and exfiltrate information. Experts reported the use of the Tiny Shell and the Cobalt Strike Beacon.

The attackers placed collected data on web servers on the compromised network and then downloaded them using the Wget utility.

The August attack was aimed at a Russian organization from the industry.

“We notified the affected company on time—four days after the server was compromised—and, in cooperation with its employees, promptly eliminated the threat. In total, the attackers remained in the victim’s network for eight days, and two weeks passed from the moment of notification to the completion of the incident response and investigation.” continues the report. “According to our data, the APT group did not expect that its backdoors would be detected so quickly, so it did not have time to develop the attack further.”

Experts reported that the threat actors used ProxyShell flaws in this second attack and installed the backdoor DoorMe v2 on two mail servers (Microsoft Exchange Server) on the victim’s network. 

Then the attackers used BeaconLoader for lateral movement and the Cobalt Strike Beacon.

Positive Technologies researchers determined that the hackers have compromised another 13 organizations in the US, Japan, Turkey, Taiwan, Vietnam, India, Afghanistan, Lithuania and Nepal. In most of the attacks, threat actors compromised Microsoft Exchange Servers by exploiting ProxyLogon and ProxyShell flaws.

“Trusted relationship attacks are rare today due to the complexity of their execution. Using this method in the first case, the ChamelGang group was able to achieve its goal and steal data from the compromised network. Also, the group tried to disguise its activity as legitimate, using OS features and plausible phishing domains. In addition, the attackers left a passive backdoor DoorMe in the form of a module for the IIS server.” concludes the report. “We predict that the trend using the supply chain method will continue. New APT groups using this method to achieve their goals will appear on stage.”

Follow me on Twitter: @securityaffairs and Facebook

[adrotate banner=”9″][adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – hacking, ChamelGang)

[adrotate banner=”5″]

[adrotate banner=”13″]

Pierluigi Paganini

Pierluigi Paganini is member of the ENISA (European Union Agency for Network and Information Security) Threat Landscape Stakeholder Group and Cyber G7 Group, he is also a Security Evangelist, Security Analyst and Freelance Writer. Editor-in-Chief at "Cyber Defense Magazine", Pierluigi is a cyber security expert with over 20 years experience in the field, he is Certified Ethical Hacker at EC Council in London. The passion for writing and a strong belief that security is founded on sharing and awareness led Pierluigi to find the security blog "Security Affairs" recently named a Top National Security Resource for US. Pierluigi is a member of the "The Hacker News" team and he is a writer for some major publications in the field such as Cyber War Zone, ICTTF, Infosec Island, Infosec Institute, The Hacker News Magazine and for many other Security magazines. Author of the Books "The Deep Dark Web" and “Digital Virtual Currency and Bitcoin”.

Recent Posts

U.S. Gov imposed Visa restrictions on 13 individuals linked to commercial spyware activity

The U.S. Department of State imposed visa restrictions on 13 individuals allegedly linked to the…

11 hours ago

A cyber attack paralyzed operations at Synlab Italia

A cyber attack has been disrupting operations at Synlab Italia, a leading provider of medical…

12 hours ago

Russia-linked APT28 used post-compromise tool GooseEgg to exploit CVE-2022-38028 Windows flaw

Russia-linked APT28 group used a previously unknown tool, dubbed GooseEgg, to exploit Windows Print Spooler…

22 hours ago

Hackers threaten to leak a copy of the World-Check database used to assess potential risks associated with entities

A financially motivated group named GhostR claims the theft of a sensitive database from World-Check…

1 day ago

Windows DOS-to-NT flaws exploited to achieve unprivileged rootkit-like capabilities

Researcher demonstrated how to exploit vulnerabilities in the Windows DOS-to-NT path conversion process to achieve…

1 day ago

A flaw in the Forminator plugin impacts hundreds of thousands of WordPress sites

Japan's CERT warns of a vulnerability in the Forminator WordPress plugin that allows unrestricted file uploads…

1 day ago

This website uses cookies.