APT

Russia-linked Sandworm APT compromised 11 Ukrainian telecommunications providers

Russia-linked APT group Sandworm has hacked eleven telecommunication service providers in Ukraine between May and September 2023.

The Russia-linked APT group Sandworm (UAC-0165) has compromised eleven telecommunication service providers in Ukraine between May and September 2023, reported the Ukraine’s Computer Emergency Response Team (CERT-UA).

According to public sources, the threat actors targeted ICS of at least 11 Ukrainian telecommunications providers leading to the disruption of their services.

“According to public sources, for the period from 11.05.2023 to 27.09.2023, an organized group of criminals tracked by the identifier UAC-0165 interfered with the information and communication systems (ICS) of no less than 11 telecommunications providers of Ukraine, which, among other things, led to interruptions in the provision of services to consumers.” reads the advisory published by the CERT-UA.

The Sandworm group (aka BlackEnergyUAC-0082Iron VikingVoodoo Bear, and TeleBots) has been active since 2000, it operates under the control of Unit 74455 of the Russian GRU’s Main Center for Special Technologies (GTsST). The group is also the author of the NotPetya ransomware that hit hundreds of companies worldwide in June 2017. In 2022, the Russian APT used multiple wipers in attacks aimed at Ukraine, including AwfulShredCaddyWiperHermeticWiperIndustroyer2IsaacWiperWhisperGatePrestigeRansomBoggs, and ZeroWipe. 

The attacks against the telecommunication service providers commence with a reconnaissance activity through a “rough” scan of the provider’s subnets (autonomous system) using typical set port scanning tools, such as masscan.

Sandworm were observed targeting open ports and unprotected RDP or SSH interfaces to gain access to the internet-facing systems. The attackers were also spotted attempting the exploitation of known vulnerabilities in the target systems.

The threat actors used various tools, including ‘ffuf’, ‘dirbuster’, ‘gowitness’, and ‘nmap.’ The CERT-UA also reported that the state-sponsored hackers used compromised VPN accounts that weren’t protected by multi-factor authentication.

“Note (!) that intelligence and exploitation activity is carried out from pre-compromised servers located, in particular, in the Ukrainian segment of the Internet. Dante, socks5 and other proxy servers are used to route traffic through such nodes.” reads the advisory.

Sandworm employed two backdoors, named Poemgate and Poseidon, in the attacks against the Ukrainian telecommunications providers.

POEMGATE is a malicious PAM module that is used by attackers to authenticate with a statically determined password and saves logins and passwords entered during authentication in a file in XOR-encoded form. Authentication data collected by POEMGATE can be used for lateral movement and other malicious activities on the compromised networks.

Poseidon is a Linux backdoor that supports a full range of remote computer control tools. The malware maintains persistence through Cron jobs.

In order to avoid detection and remove tracks of unauthorized access, the attackers used the WHITECAT utility.

At the final stage of an attack, the attackers were able to interfere with network equipment, as well as data storage systems. 

CERT-UA published Indicators of Compromise for these attacks and recommends reading the article “How to be responsible and hold the cyber front.”

In May, CERT-UA CERT-UA warned of destructive cyberattacks conducted by the Russia-linked Sandworm APT group against the Ukraine public sector.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Sandworm)

Pierluigi Paganini

Pierluigi Paganini is member of the ENISA (European Union Agency for Network and Information Security) Threat Landscape Stakeholder Group and Cyber G7 Group, he is also a Security Evangelist, Security Analyst and Freelance Writer. Editor-in-Chief at "Cyber Defense Magazine", Pierluigi is a cyber security expert with over 20 years experience in the field, he is Certified Ethical Hacker at EC Council in London. The passion for writing and a strong belief that security is founded on sharing and awareness led Pierluigi to find the security blog "Security Affairs" recently named a Top National Security Resource for US. Pierluigi is a member of the "The Hacker News" team and he is a writer for some major publications in the field such as Cyber War Zone, ICTTF, Infosec Island, Infosec Institute, The Hacker News Magazine and for many other Security magazines. Author of the Books "The Deep Dark Web" and “Digital Virtual Currency and Bitcoin”.

Recent Posts

Unlimited Technology Systems Data Breach Exposes Data of 3.8 Million Healthcare Patients

Hackers stole personal, medical, and insurance data of 3.8 million people from Unlimited Technology Systems'…

18 minutes ago

WordPress XSS2Shell Flaw Turns Simple Login Bug Into Full Server Takeover

WordPress XSS2Shell flaw enables admin takeover and remote code execution. Users should update to patched…

15 hours ago

Hackers Impersonate IT Support to Breach Leading Financial Companies

Hackers used fake IT help desks to steal MFA credentials, targeting over 200 firms, including…

16 hours ago

Meta Ordered to Pay $567 Million Over Child Safety Failures in New Mexico Case

Meta was ordered to pay $567M after a judge ruled its platforms harmed children, bringing…

20 hours ago

Researchers Discover Hidden Backdoor in 20 Router Models Allowing Remote Root Access

A hidden backdoor in 20 router models lets remote servers execute commands as root, putting…

21 hours ago

AI Deepfakes Used to Impersonate OnlyFans Creators in New Scam

Scammers use AI deepfakes to impersonate OnlyFans creators, trick fans into sending money, then disappear…

1 day ago

This website uses cookies.