<span id="hs_cos_wrapper_post_body" class="hs_cos_wrapper hs_cos_wrapper_meta_field hs_cos_wrapper_type_rich_text" style="" data-hs-cos-general-type="meta_field" data-hs-cos-type="rich_text" ><p style="text-align: justify;">APT29 – otherwise known as NOBELIUM and Cozy Bear, or "the <a href="/solarwinds-fireeye-and-you" rel="noopener">SolarWinds </a>attackers" – have recently launched a global spear-phishing campaign against a variety of government-related organizations, as discovered by the security firm <a href="https://www.volexity.com/blog/2021/05/27/suspected-apt29-operation-launches-election-fraud-themed-phishing-campaigns/" rel="noopener" target="_blank">Volexity</a>. In their campaign, the cyber group is distributing election fraud-themed phishing emails, attempting to infect victim networks with malware and exfiltrate critical data. Among their targets are NGOs, research institutions, and government agencies across the United States and Europe.</p> <p><!--more--></p> <p style="text-align: justify;">In order to gain access to sensitive internal networks, APT29 first successfully compromised a Constant Contact account used by the USAID government agency for email campaigns. Constant Contact is an email marketing software that can also be used to track click-throughs on links, thus allowing the attackers to track their campaign success after exploiting the account to send spear phishing emails. The emails pose as a special alert from USAID referencing fraud in the 2020 U.S. Federal Elections.</p> <p>&nbsp;</p> <p><img src="https://www.volexity.com/wp-content/uploads/2021/05/phish_email-1024x817.png" loading="lazy" width="503" style="width: 503px; margin-left: auto; margin-right: auto; display: block;" alt="Nobelium phish email example"></p> <p style="text-align: center;"><em>2020 Elections phishing email. Image: Volexity</em></p> <p style="text-align: justify;">Once a victim presses on one of the email links, they are prompted to download HTML attachments - including four new malware variants created by the APT: EnvyScout, BoomBox, NativeZone and VaporRage.</p> <p style="font-weight: bold; text-align: justify;">The HTML Attachment - EnvyScout</p> <p style="text-align: justify;">EnvyScout is a malicious HTML/JS file attachment used in spear-phishing emails that attempts to steal the NTLM credentials of Windows accounts and drop a malicious ISO on a victim's device.</p> <p style="text-align: justify;"><span style="font-weight: bold;">The Downloader - BoomBox</span></p> <p style="text-align: justify;"><span>An EXE (PE) file executed by the the ISO image, BoomBox is used to download two encrypted malware files to the infected device from DropBox. The BoomBox malware decrypts and saves the downloaded files, after which it gathers information about the Windows domain, encrypts the collected data, and sends it to the attackers' command and control servers (C2s).</span></p> <p style="text-align: justify;"><span style="font-weight: bold;">The Loader - NativeZone</span></p> <p style="text-align: justify;">A malware dropped by BoomBox and configured to start automatically when a user logs into Windows. When running, it will launch a DLL (<em>CertPKIProvider.dll) that </em>Microsoft dubbs "VaporRage".</p> <p style="font-weight: bold; text-align: justify;">The shellcode Downloader and Launcher - VaporRage</p> <p style="text-align: justify;">Upon being launched, the malware will connect to a remote C2 server, register itself, and repeatedly attempt to connect until it downloads malicious shellcodes. Then, the malware will execute them to perform various malicious activities, including the deployment of Cobalt Strike beacons.</p> <p style="text-align: justify;"><em>For more information regarding these malware variants, check out <a href="https://www.bleepingcomputer.com/news/security/microsoft-russian-hackers-used-4-new-malware-in-usaid-phishing/" rel="noopener" target="_blank">BleepingComputer's extensive report</a>.</em></p> <p>&nbsp;</p> <p style="text-align: justify;"><span style="font-weight: normal;"><span style="font-weight: bold;">ThreatSTOP has been monitoring and blocking malicious activity in this campaign.</span> The related Indicators of Compromise (IOCs) are live in our systems. We've seen thousands of communication attempts from our customer networks to these IOCs on a daily basis. In an operation conducted by the FBI, two C2 domains used in this campaign by APT29 were successfully taken over - theyardservice[.]com and worldhomeoutlet[.]com. Law enforcement agencies, including the FBI, will investigate these domains to gain a better understanding of these attackers' tactics and infrastructure use.&nbsp;</span></p> <p style="text-align: justify;"><span style="font-weight: normal;">But until this gang is taken down, it is important that you protect your network from this and other targeted attacks. Block the malicious infrastructure in this campaign by blacklisting the IOCs below. If you are a ThreatSTOP customer, you're automatically protected.&nbsp;</span></p> <p>&nbsp;</p> <p style="text-align: center; font-weight: bold;">Related Domains:</p> <table width="762" style="border-collapse: collapse; table-layout: fixed; margin-left: auto; margin-right: auto; border: 1px solid #99acc2;"> <tbody> <tr> <td style="width: 233.608px; text-align: left; padding: 4px; border: 1px solid #99acc2;">theyardservice[.]com</td> <td style="width: 261.676px; text-align: left; padding: 4px; border: 1px solid #99acc2;">stockmarketon[.]com</td> <td style="width: 265.71px; text-align: left; padding: 4px; border: 1px solid #99acc2;">security-updater-default-rtdb[.]firebaseio[.]com</td> </tr> <tr> <td style="width: 233.608px; text-align: left; padding: 4px; border: 1px solid #99acc2;">worldhomeoutlet[.]com</td> <td style="width: 261.676px; text-align: left; padding: 4px; border: 1px solid #99acc2;">stsnews[.]com</td> <td style="width: 265.71px; text-align: left; padding: 4px; border: 1px solid #99acc2;">cdnappservice[.]web[.]app</td> </tr> <tr> <td style="width: 233.608px; text-align: left; padding: 4px; border: 1px solid #99acc2;">aimsecurity[.]net</td> <td style="width: 261.676px; text-align: left; padding: 4px; border: 1px solid #99acc2;">tacomanewspaper[.]com</td> <td style="width: 265.71px; text-align: left; padding: 4px; border: 1px solid #99acc2;">humanitarian-forum[.]web[.]app</td> </tr> <tr> <td style="width: 233.608px; text-align: left; padding: 4px; border: 1px solid #99acc2;">cityloss[.]com</td> <td style="width: 261.676px; text-align: left; padding: 4px; border: 1px solid #99acc2;">techiefly[.]com</td> <td style="width: 265.71px; text-align: left; padding: 4px; border: 1px solid #99acc2;">logicworkservice[.]web[.]app</td> </tr> <tr> <td style="width: 233.608px; text-align: left; padding: 4px; border: 1px solid #99acc2;">cross-checking[.]com</td> <td style="width: 261.676px; text-align: left; padding: 4px; border: 1px solid #99acc2;">theadminforum[.]com</td> <td style="width: 265.71px; text-align: left; padding: 4px; border: 1px solid #99acc2;">humanitarian-forum-default-rtdb[.]firebaseio[.]com</td> </tr> <tr> <td style="width: 233.608px; text-align: left; padding: 4px; border: 1px solid #99acc2;">dailydews[.]com</td> <td style="width: 261.676px; text-align: left; padding: 4px; border: 1px solid #99acc2;">trendignews[.]com</td> <td style="width: 265.71px; text-align: left; padding: 4px; border: 1px solid #99acc2;">cdnappservice[.]firebaseio[.]com</td> </tr> <tr> <td style="width: 233.608px; text-align: left; padding: 4px; border: 1px solid #99acc2;">doggroomingnews[.]com</td> <td style="width: 261.676px; text-align: left; padding: 4px; border: 1px solid #99acc2;">refreshauthtoken-default-rtdb[.]firebaseio[.]com</td> <td style="width: 265.71px; text-align: left; padding: 4px; border: 1px solid #99acc2;">74d6b7b2[.]app[.]giftbox4u[.]com</td> </tr> <tr> <td style="width: 233.608px; text-align: left; padding: 4px; border: 1px solid #99acc2;">emergencystreet[.]com</td> <td style="width: 261.676px; text-align: left; padding: 4px; border: 1px solid #99acc2;">cdn[.]theyardservice[.]com</td> <td style="width: 265.71px; text-align: left; padding: 4px; border: 1px solid #99acc2;">content[.]pcmsar[.]net</td> </tr> <tr> <td style="width: 233.608px; text-align: left; padding: 4px; border: 1px solid #99acc2;">enpport[.]com</td> <td style="width: 261.676px; text-align: left; padding: 4px; border: 1px solid #99acc2;">dataplane[.]theyardservice[.]com</td> <td style="width: 265.71px; text-align: left; padding: 4px; border: 1px solid #99acc2;">email[.]theyardservice[.]com</td> </tr> <tr> <td style="width: 233.608px; text-align: left; padding: 4px; border: 1px solid #99acc2;">financialmarket[.]org</td> <td style="width: 261.676px; text-align: left; padding: 4px; border: 1px solid #99acc2;">static[.]theyardservice[.]com</td> <td style="width: 265.71px; text-align: left; padding: 4px; border: 1px solid #99acc2;">smtp2[.]theyardservice[.]com</td> </tr> <tr> <td style="width: 233.608px; text-align: left; padding: 4px; border: 1px solid #99acc2;">giftbox4u[.]com</td> <td style="width: 261.676px; text-align: left; padding: 4px; border: 1px solid #99acc2;">usaid[.]theyardservice[.]com</td> <td style="width: 265.71px; text-align: left; padding: 4px; border: 1px solid #99acc2;">cdn[.]theyardservice[.]com</td> </tr> <tr> <td style="width: 233.608px; text-align: left; padding: 4px; border: 1px solid #99acc2;">hanproud[.]com</td> <td style="width: 261.676px; text-align: left; padding: 4px; border: 1px solid #99acc2;">eventbrite-com-default-rtdb[.]firebaseio[.]com</td> <td style="width: 265.71px; text-align: left; padding: 4px; border: 1px solid #99acc2;">dataplane[.]theyardservice[.]com</td> </tr> <tr> <td style="width: 233.608px; text-align: left; padding: 4px; border: 1px solid #99acc2;">newsplacec[.]com</td> <td style="width: 261.676px; text-align: left; padding: 4px; border: 1px solid #99acc2;">supportcdn-default-rtdb[.]firebaseio[.]com</td> <td style="width: 265.71px; text-align: left; padding: 4px; border: 1px solid #99acc2;">static[.]theyardservice[.]com</td> </tr> <tr> <td style="width: 233.608px; text-align: left; padding: 4px; border: 1px solid #99acc2;">newstepsco[.]com</td> <td style="width: 261.676px; text-align: left; padding: 4px; border: 1px solid #99acc2;">supportcdn[.]web[.]app</td> <td style="width: 265.71px; text-align: left; padding: 4px; border: 1px solid #99acc2;">worldhomeoutlet[.]com</td> </tr> <tr> <td style="width: 233.608px; text-align: left; padding: 4px; border: 1px solid #99acc2;">pcmsar[.]net</td> <td style="width: 261.676px; text-align: left; padding: 4px; border: 1px solid #99acc2;">security-updater[.]web[.]app</td> <td style="width: 265.71px; text-align: left; padding: 4px; border: 1px solid #99acc2;">usaid[.]theyardservice[.]com</td> </tr> </tbody> </table> <p>&nbsp;</p> <p style="font-weight: bold; text-align: center;">Related IPs:</p> <table width="295" style="border-collapse: collapse; table-layout: fixed; margin-left: auto; margin-right: auto; width: 169px; border: 1px solid #99acc2;"> <tbody> <tr> <td style="width: 168.991px; padding: 4px; border: 1px solid #99acc2;">192[.]99[.]221[.]77</td> </tr> <tr> <td style="width: 168.991px; padding: 4px; border: 1px solid #99acc2;">83[.]171[.]237[.]173</td> </tr> <tr> <td style="width: 168.991px; padding: 4px; border: 1px solid #99acc2;">139[.]99[.]167[.]177</td> </tr> <tr> <td style="width: 168.991px; padding: 4px; border: 1px solid #99acc2;">185[.]158[.]250[.]239</td> </tr> <tr> <td style="width: 168.991px; padding: 4px; border: 1px solid #99acc2;">195[.]206[.]181[.]169</td> </tr> <tr> <td style="width: 168.991px; padding: 4px; border: 1px solid #99acc2;">37[.]120[.]247[.]135</td> </tr> <tr> <td style="width: 168.991px; padding: 4px; border: 1px solid #99acc2;">45[.]135[.]167[.]27</td> </tr> <tr> <td style="width: 168.991px; padding: 4px; border: 1px solid #99acc2;">51[.]254[.]241[.]158</td> </tr> <tr> <td style="width: 168.991px; padding: 4px; border: 1px solid #99acc2;">51[.]38[.]85[.]225</td> </tr> </tbody> </table> <p>&nbsp;</p> <p style="text-align: center;"><em>Ready to try ThreatSTOP in your network? Want an expert-led demo to see how it works?</em></p> <p style="text-align: center;"><em>&nbsp; &nbsp; &nbsp; </em></p></span>