A Pakistani threat actor has been using a novel malware to spy on high-value targets in Afghanistan, but the same attacks have been running up against a wall in India.

The culprit is Transparent Tribe (aka APT 36), which might be Pakistan’s most active advanced persistent threat (APT) actor. More often than not, it has been found spying on governments and militaries in neighboring India and Afghanistan. The nature of its cyber espionage has long led researchers to believe that it works for the Pakistani state.

This year, researchers from Acronis have observed Transparent Tribe doing its usual business, but with a sharpened-up toolset: fresh backdoors called “Patchcord” and “Sheetcord.” Patchcord in particular is a bit of an uneven thing: it’s perfectly capable at command-and-control (C2) and anti-analysis, but its main trick is an old and largely detectable persistence mechanism in which the malware hijacks victims’ desktop shortcuts.

Related:‘Grandoreiro’ Malware Resurfaces With Mexico Campaign

Recent targets in Afghanistan have included major government and telecommunications organizations, and oddly small fish, including a small business and an unidentified individual, according to Acronis. The group also appears to have been targeting Indian organizations, though no successful compromises there have yet been confirmed.

Transparent Tribe’s Cyberattacks in Afghanistan & India

Transparent Tribe’s campaign in Afghanistan and India dates back to at least last December. It appears to have ramped up in May, and remains ongoing to this day.

Researchers have deduced the hackers’ lofty ambitions from its social engineering tactics. Its phishing lures have impersonated network and logistics tools used by a large Afghani telecommunications company, a fuel-conservation tool for India’s energy sector, an Indian government employee benefits resource, and so on. Its C2 domains have likewise impersonated major Indian government organizations and Afghani telecoms.

Dark Reading has specifically confirmed that Transparent Tribe successfully infected an Afghan subsidiary of an international company, as well as an IT officer at the Khost branch of the state-owned Afghan Telecom (AFTEL). “The threat actor has been stealing data from his desktop and looking into his WhatsApp and private data,” says Acronis senior threat researcher Subhajeet Singha. “They’re trying to use that data to [design] decoy Excel files, or something like it, to phish some more employees. Then laterally moving into the entire company.”

The threat actor shot even higher in India. It developed phishing paraphernalia tailored to multiple government agencies, including the Ministries of Defense and Foreign Affairs, the National Informatics Centre (part of the the Ministry of Electronics and Information Technology), as well as the Indian Air Force. As mentioned, no evidence suggests that these attacks were successful, though.

Related:China-Linked Hacker Shows AI Capabilities in APAC Attack

The Patchcord Pakistani Backdoor Malware

Behind many of Transparent Tribe’s phishing lures lies Patchcord, a newly documented C++ implant. Patchcord supports a few basic functions like host fingerprinting and process enumeration, but most importantly, it’s designed to run arbitrary code in-memory. A variant of Patchcord first seen in March also implemented a variety of checks for detecting whether it’s running in a virtual machine or sandbox environment.

Patchcord’s emphases on executing commands in-memory and frustrating analysis tools might suggest that it’s quite concerned with avoiding detection. This is in some contrast, though, to other elements of its build, such as its standout persistence mechanism: browser shortcut hijacking.

Every day, when you open your computer, you click on your preferred browser’s shortcut icon on your laptop screen. Patchcord, like plenty of aged malware before it, injects itself into that interaction, rewriting the shortcut to instead execute itself first, and then the intended browser second. Users don’t see the difference — the shortcut icon is the same as ever, and the browser opens as they expect — but each time they click, they ensure that the secret malware gets to run in the background, too. Shortcut modification is a simple and long-recognized tactic, but one relatively unseen among high-level APTs that need to prioritize stealth.

Related:Ransomware Hits Colombian Justice Ministry Days Before Presidential Transition

In cases where it perhaps can’t get away with cheap tactics like browser shortcut hijacking, Transparent Tribe can use Sheetcord, a Go-based evolution of Patchcord; and a remote access Trojan (RAT) called “Sheetcreep.” Sheetcord uses the more conventional persistence tactic of registering itself as a Windows startup process, and tries to conceal its C2 traffic by sending it through Google Sheets.

How to Detect, or Block, Transparent Tribe Cyberattacks

Singha argues that when a malware performs browser shortcut hijacking, “it’s quite easy to defend against, because when they are trying to change the shortcuts, a lot of endpoint products detect it. It’s quite common and it’s an old technique.”

Transparent Tribe’s low-grade tactics, techniques, and procedures (TTPs) may be indicative of its limited sophistication, or, perhaps, how low a bar it has to clear to compromise its chosen targets. Singha is inclined to believe that it’s just playing down to the competition.

“I think they did nice recon on their targets — what they use, what antivirus product they have, and stuff like that — and depending on that they use this technique,” he says.

As further evidence of the Pakistani APT’s habits, Acronis also discovered a third malware framework in its coffers called “HackerAI.” HackerAI was likely generated using help from an artificial intelligence (AI) coding tool, and it otherwise distinguishes itself by using GitHub Gist for C2. In Afghanistan, Singha notes, “the cybersecurity maturity is not quite good. So in this case, they could just spin up a vibecoded malware and do their work.”

India is levels above Afghanistan when it comes to national cybersecurity defense, he adds. When Singha reached out to the Indian government’s Computer Emergency Response Team (CERT-In), CERT-In didn’t seem too fussed about Transparent Tribe. He recalled how it deals with the attacks: by broadly blocking the hackers’ very well-known infrastructure.





Source link

#

Comments are closed