[ad_1]
Researchers say they Found a new disk wipe malicious software Pretend as Ransomware Because it launched destructive attacks on Israeli targets.
Researchers at the security company SentinelOne called Apostle malware, which was originally deployed to wipe data, but failed to do so, possibly due to a logical flaw in its code. The internal name given to it by the developer is “wiper-action”. In later versions, the bug has been fixed, and the malware has achieved full ransomware behavior, including the ability to leave a comment asking the victim to pay a ransom in exchange for the decryption key.
in a Posts posted on Tuesday, SentinelOne researchers said that they have been highly certain that, according to the code and server reported by Apostle, the malware is being used by a newly discovered organization linked to the Iranian government. Although the ransomware noticed that the researchers found that the ransomware had been used against a key facility in the United Arab Emirates, the main target was Israel.
“The use of ransomware as a destructive tool is often difficult to prove because it is difficult to determine the intent of the threat actor,” the report on Tuesday said. “Analysis of Apostle malware provides rare insights into this type of attack, thereby drawing a clear line from the initial wiper malware to fully operational ransomware.”
Researchers call it the new hacker organization Agrius. SentinelOne saw that the team first used Apostle as a disk wiper, although a vulnerability in the malware prevented this operation, most likely due to a logical error in its code. Then, Agrius returned to Deadwood, a type of wiper that has been used in 2019 against targets in Saudi Arabia.
Agrius’ new version of Apostle is mature ransomware.
“We believe that the implementation of the encryption function obscures its actual intention, which is to destroy the victim’s data,” the post said on Tuesday. “This article was supported by an earlier version of Apostle, and the attacker internally named it “wiper-action”.
The main code of Apostle overlaps with the backdoor called IPSec Helper that Agrius also uses. IPSec Helper receives a series of commands issued from the attacker’s control server, such as downloading and executing executable files. Both Apostle and IPSec Helper are written in .Net language.
Agrius also uses webshell so that the attacker can move laterally within the threatened network. In order to hide their IP address, members use ProtonVPN.
Iranian-sponsored hackers have become interested in disk wipers. In 2012, self-replicating malware was destroyed via the Saudi Aramco network (the world’s largest crude oil exporter) headquartered in Saudi Arabia, and Destroy the hard drive permanently More than 30,000 workstations. The researchers later identified the wiper worm as Shamoon and said it was Iranian work.
In 2016, Shamoon appears again The campaign attacked multiple organizations in Saudi Arabia, including several government agencies.Three years later, the researchers found a The new Iranian wiper is called ZeroCleare.
The Apostle is not the first wiper disguised as ransomware. NotPetya, the worm Cause billions of dollars in damages worldwide, Was also disguised as ransomware until the researchers determined that the file was created by a hacker supported by the Russian government to destabilize Ukraine.
Juan Andres Guerrero-Saade, principal threat researcher at SentinelOne, said in an interview that malware like Apostle illustrates the frequent interactions between financial motivations. Cybercriminals And nation-state hackers.
He said: “The threat ecosystem continues to evolve, and attackers have developed different technologies to achieve their goals.” “We have seen cybercriminal groups learn from the more resource-rich nation-state groups. Similarly, the nation-state groups are from criminal groups. Borrowed, they disguised destructive attacks under the guise of ransomware, and there is no indication that the victims will actually retrieve their files in exchange for extortion.”
This story originally appeared in Technology studio.
More exciting wired stories
[ad_2]
Source link






