Categories: Geopolitical

Govt hackers impersonate HR employees to hit Israeli targets

Govt hackers impersonate HR employees to hit Israeli targets

Hackers associated with the Iranian government have focused attack efforts on IT and communication companies in Israel, likely in an attempt to pivot to their real targets.

The campaigns have been attributed to the Iranian APT group known as Lyceum, Hexane, and Siamesekitten, running espionage campaigns since at least 2018 [12].

In multiple attacks detected in May and July, the hackers combined social engineering techniques with an updated malware variant that would ultimately give them remote access to the infected machine.

Also Read: Data Minimization; Why Bigger is Not Always Better

In one case, the hackers used the name of a former HR manager at technology company ChipPC to create a fake LinkedIn profile, a clear indication that the attackers did their homework before starting the campaign.

source:ClearSky

Threat researchers at cybersecurity company ClearSky in a report today say that Siamesekitten actors then used the fake profile to deliver malware to potential victims under the pretext of a job offer:

  1. Identifying the potential victim (employee)
  2. Identifying the human resources department employee to impersonate
  3. Creating a phishing website that impersonates the target organization
  4. Creating lure files compatible with the impersonated organization
  5. Setting up a fake profile on LinkedIn in the name of the HR employee
  6. Contacting potential victims with an “alluring” job offer, detailing a position in the impersonated organization
  7. Sending the victim to a phishing website with a lure file
  8. A backdoor infects the system and connects to the C&C server over DNS and HTTPS
  9. The DanBot RAT is downloaded to the infected system
  10. Hackers get data for espionage purposes and try to spread on the network

ClearSky believes that Siamesekitten has spent months trying to breach a large number of organizations in Israel using supply chain tools.

While the threat actor’s interest seems to have changed from organizations in the Middle East and Africa, the researchers say that the IT and communication companies in Israel are just a means to getting to the real targets.

“We believe that these attacks and their focus on IT and communication companies are intended to facilitate supply chain attacks on their clients. According to our assessment, the group’s main goal is to conduct espionage and utilize the infected network to gain access to their clients’ networks. As with other groups, it is possible that espionage and intelligence gathering are the first steps toward executing impersonation attacks targeting ransomware or wiper malware” – ClearSky

The researchers discovered two websites that are part of Siamesekitten’s infrastructure for the cyberespionage campaigns targeting companies in Israel.

One imitates the site of German enterprise software company Software AG and the other mimics the website of ChipPc. In both cases, the potential victim is asked to download an Excel (XLS) file that purportedly contains details about the job offer or the resume format.

The two files include a password-protected malicious macro that starts the infection chain by extracting a backdoor called MsNpENg.

source: ClearSky

ClearSky notes that between the two campaigns (May through July) they observed, Siamesekitten switched from an older backdoor version written in C++ and named Milan to a newer variant called Shark, which is written in .NET.

Today’s report [PDF] contains technical details for both variants along with IP addresses for the attacker’s infrastructure, email addresses used to register servers, and hashes for malicious files.

Also Read: Lessons from PDPC Incident and Undertaking: August 2021 Cases

Privacy Ninja

Recent Posts

Role of Enhanced Access Controls in Safeguarding Personal Data in Telecommunications

Role of Enhanced Access Controls in Safeguarding Personal Data in Telecommunications that every Organisation in…

6 days ago

Role of Effective Incident Response Procedures in Strengthening Data Security

Effective Incident Response Procedures in Strengthening Data Security that every Organisation in Singapore should know…

7 days ago

Strengthening Your Cyber Defenses: The Crucial Role of Regular Vulnerability Scanning

Crucial Role of Regular Vulnerability Scanning that every Organisation in Singapore should know. Strengthening Your…

1 week ago

Enhancing Data Security with Multi-Factor Authentication

Enhancing Data Security with Multi-Factor Authentication that every Organisation in Singapore should know. Enhancing Data…

2 weeks ago

A Strong Password Policy: Your Organization’s First Line of Defense Against Data Breaches

Strong Password Policy as a first line of defense against data breaches for Organisations in…

2 weeks ago

Enhancing Website Security: The Importance of Efficient Access Controls

Importance of Efficient Access Controls that every Organisation in Singapore should take note of. Enhancing…

3 weeks ago