After all, cats are not that cute; a group known as Nemesis Kitten has been exfiltrating data from an infected computer using a legitimate hosting service as a dead drop.
Nemesis Kitten, a subgroup of an Iranian nation-state group, has been found connected to an undocumented malware called Drokbk. The said malware leverages the legitimate GitHub as a dead drop.
For context, a dead drop takes information and files out of the general internet stream using a secret location.
Rafe Pilling, Secureworks principal, emphasised, “The use of GitHub as a virtual dead drop helps the malware blend in.”
“All the traffic to GitHub is encrypted, meaning defensive technologies can’t see what is being passed back and forth. And because GitHub is a legitimate service, it raises fewer questions.”
The nefarious operations of the Iranian government-sponsored actor first came to light in February 2022, when it was detected abusing Log4Shell weaknesses in unpatched VMware Horizon servers to deliver ransomware.
“Drokbk provides the threat actors with arbitrary remote access and an additional foothold alongside tunnelling tools like Fast Reverse Proxy (FRP) and Ngrok,” Pilling said.
It is also alleged to have tactical overlaps with Cobalt Illusion (aka APT42), a Phosphorus subgroup tasked with conducting information collection and surveillance activities against individuals and groups of strategic relevance to the Iranian leadership.
The investigation further uncovered two intrusion sets, A and B. Cluster A conducts opportunistic ransomware assaults for financial gain using BitLocker and DiskCryptor. In contrast, Cluster B runs targeted break-ins for intelligence gathering. And, Drokbk falls under B.
Unified information from Secureworks, Google Mandiant, and Microsoft has revealed that Iranian front companies Afkar System and Najee Technology, connected with Islamic Revolutionary Guard Corps (IRGC), is where Cobalt Mirage originates.
“Early signs of its use in the wild appeared in a February 2022 intrusion at a U.S. local government network,” according to a report published with The Hacker News by the cybersecurity firm.
More Stories
Killnet and AnonymousSudan Collaborate to Launch Cyber Attacks on Western Organisations
In recent news, it has been reported that two Russia-sympathetic hacktivist groups, Killnet and AnonymousSudan, have allegedly launched a series...
$4000 Gone In An Instant: Mother Defrauded in Facebook Marketplace Car Deal
A mother of four is warning others to be cautious after believing she had purchased a safe and dependable car...
Shocking Scam: Sydney Family Loses $200K Life-Savings in Suncorp Spoofing Fraud
A family from Sydney has lost their life savings worth $200,000 due to a fraudulent scam. Peter and Madison, who...
Mysterious Money Transfer Leaves Couple Speechless: How They Got an Unsolicited $4000
A young couple in Melbourne claims their bank is making up a personal loan they do not understand. Ashley and...
Phishing + AI + Voice Cloning= Big Trouble: The New Way Criminals are Stealing Your Money
New Alert: Criminals use AI and voice cloning to trick you out of your money. Earlier this year, Microsoft unveiled...
‘Impossible to Spot’ Delivery Scam Email Targets Australia Post Customers – Don’t Fall Victim!
Unsuspecting shoppers should be cautious as a parcel delivery scam that is hard to distinguish targets Australia Post customers. Email...