Skip to main content

Kaspersky reveals final stage malware chain for data exfiltration from industrial companies

10 August 2023

Kaspersky's ICS CERT has revealed the concluding segment of its research series, devoted to attacks on industrial organizations in Eastern Europe. This latest announcement investigates third-stage malware, designed for the uploading of files to Dropbox and to also coordinate with other malware implants to exfiltrate data.

This third-stage data exfiltration activity involves itself a three-step malware execution chain. Firstly, this execution chain establishes persistence and orchestrates the deployment and initiation of the second-step malware module. This module is responsible for uploading collected files to a remote server with the help of the third-step module. The intricate architecture allows the threat actor to recalibrate the execution flow by replacing individual modules within the chain. In some cases, the chain could be used for data exfiltration from network segments isolated from internet by setting up an intermediate/proxy storage for the stolen data inside the victims’ network.

In the evolving landscape of this cyberattack campaign, the threat actor deployed a malware chain to access Outlook mailbox files, execute remote commands, and perform the uploading of local or remote ".rar" files to Dropbox.

Additionally, our investigation highlights the use of tools for manual data transfer. One tool is specifically designed for moving files to and from Yandex Disk, while another allows for easy file uploads to 16 temporary file sharing services. The third one, being downloaded from Yandex Disk, had the functionality to send the implant chain execution log data to Yandex mail accounts. 

These insights provide a glimpse into the threat actor’s intricate data exfiltration techniques.

“Our comprehensive analysis underscores the adaptability of threat actors in their pursuit of sensitive data. By unraveling the mechanics of these advanced implants, we provide the cybersecurity community with crucial knowledge to fortify defenses against increasingly sophisticated attacks,” comments Kirill Kruglov, Senior Security Researcher at Kaspersky ICS CERT.

To read the full report on the third-stage of the campaign, visit ICS CERT website.

To keep your OT computers protected from various threats, Kaspersky experts recommend:

  • Conducting regular security assessments on OT systems to identify and eliminate possible cyber security issues.
  • Establishing a continuous vulnerability assessment and triage system as a basis for an effective vulnerability management process. Dedicated solutions like Kaspersky Industrial CyberSecurity may become an efficient assistant and a source of unique actionable information, not fully available in public.
  • Performing timely updates for the key components of the enterprise’s OT network; applying security fixes and patches or implementing compensating measures as soon as it is technically possible is crucial for preventing a major incident that might cost millions due to the interruption of the production process.
  • Using integrated attack detection and prevention solutions such as Kaspersky IndustrialCyberSecurity for timely detection and prevention of sophisticated threats, investigation, and effective remediation of incidents.
  • Improving the response to new and advanced malicious techniques by building and strengthening your teams’ incident prevention, detection, and response skills. Dedicated OT security training for IT security teams and OT personnel is one of the key measures that can help achieve this.

Kaspersky reveals final stage malware chain for data exfiltration from industrial companies

Kaspersky's ICS CERT has revealed the concluding segment of its research series, devoted to attacks on industrial organizations in Eastern Europe. This latest announcement investigates third-stage malware, designed for the uploading of files to Dropbox and to also coordinate with other malware implants to exfiltrate data.
Kaspersky logo

About Kaspersky

Kaspersky is a global cybersecurity and digital privacy company founded in 1997. With over a billion devices protected to date from emerging cyberthreats and targeted attacks, Kaspersky’s deep threat intelligence and security expertise is constantly transforming into innovative solutions and services to protect businesses, critical infrastructure, governments and consumers around the globe. The company’s comprehensive security portfolio includes leading endpoint protection, specialized security products and services, as well as Cyber Immune solutions to fight sophisticated and evolving digital threats. We help over 200,000 corporate clients protect what matters most to them. Learn more at www.kaspersky.com.

Related Articles Press Releases