
Security experts have analyzed a new attack by the APT group TA397 - also known as "Bitter" - in more detail. As is often the case, it started with a special spear phishing email with an attachment. It contained a shortcut file and malicious PowerShell code.
The attack was directed against an organization in the Turkish defense industry and took place in November 2024. The cybercrime group, which is known for espionage attacks in Europe and the Asia-Pacific region, used new attack methods that further develop its previous tactics, techniques and procedures (TTPs). The use of alternative data streams (ADS) within RAR archives is particularly notable.
spear phishing email attack
The attack began with a spear phishing email that came from a compromised government organization account. The email contained a RAR archive attachment with a benign PDF file about a World Bank infrastructure project in Madagascar. However, hidden in the archive was also a disguised shortcut file (LNK) and hidden ADS files that contained malicious PowerShell code.
When the LNK file was opened, the hidden PowerShell code was executed while the harmless PDF was displayed. The code created a scheduled task (“DsSvcCleanup”) that sent system information to a staging server (jacknwoods[.]com) every 17 minutes. The attackers manually responded to these requests and in this case delivered two different malware families: WmRAT and MiyaRAT. Additionally, they stole information about the target system, including running processes and installed antivirus software.
Subscribe to our newsletter now
Read the best news from B2B CYBER SECURITY once a monthAccording to experts from Proofpoint: The campaign shows characteristic features of TA397 and indicates an evolution of its tactics. The time zone analysis (UTC+5:30) and other evidence suggest that the group is operating on behalf of a South Asian government. The experts' full analysis was published in a blog post.
More at Proofpoint.com
About Proofpoint Proofpoint, Inc. is a leading cybersecurity company. The focus for Proofpoint is the protection of employees. Because these mean the greatest capital for a company, but also the greatest risk. With an integrated suite of cloud-based cybersecurity solutions, Proofpoint helps organizations around the world stop targeted threats, protect their data, and educate enterprise IT users about the risks of cyberattacks.