Security-X

Forum Security-X => News => Discussion démarrée par: igor51 le août 10, 2021, 12:00:22

Titre: [FireEye]UNC215: Spotlight on a Chinese Espionage Campaign in Israel
Posté par: igor51 le août 10, 2021, 12:00:22
UNC215: Spotlight on a Chinese Espionage Campaign in Israel

This blog post details the post-compromise tradecraft and operational
  tactics, techniques, and procedures (TTPs) of a Chinese espionage
  group we track as UNC215. While UNC215’s targets are located
  throughout the Middle East, Europe, Asia, and North America, this
  report focuses on intrusion activity primarily observed at Israeli entities.


 

This report comes on the heels of the July 19, 2021,   href="https://www.whitehouse.gov/briefing-room/statements-releases/2021/07/19/the-united-states-joined-by-allies-and-partners-attributes-malicious-cyber-activity-and-irresponsible-state-behavior-to-the-peoples-republic-of-china/">announcements
  by governments in North America, Europe, and Asia and
  intragovernmental organizations, such as the North Atlantic Treaty
  Organization (NATO), and the European Union, condemning widespread
  cyber espionage conducted on behalf of the Chinese Government. These
  coordinated statements attributing sustained cyber espionage
  activities to the Chinese Government corroborate our long-standing
  reporting on Chinese threat actor targeting of private companies,
  governments, and various organizations around the world, and this blog
  post shows yet another region where Chinese cyber espionage is active.


 

Threat Detail


 

In early 2019, Mandiant began identifying and responding to
  intrusions in the Middle East by Chinese espionage group UNC215. These
  intrusions exploited the Microsoft SharePoint vulnerability
  CVE-2019-0604 to install web shells and FOCUSFJORD payloads at targets
  in the Middle East and Central Asia. There are targeting and high
  level technique overlaps with between UNC215 and APT27, but we do not
  have sufficient evidence to say that the same actor is responsible for
  both sets of activity. APT27 has not been seen since 2015, and UNC215
  is targeting many of the regions that APT27 previously focused on;
  however, we have not seen direct connection or shared tools, so we are
  only able to assess this link with low confidence.


 

In addition to data from Mandiant Incident Response and FireEye
  telemetry, we worked with Israeli defense agencies to review data from
  additional compromises of Israeli entities. This analysis showed
  multiple, concurrent operations against Israeli government
  institutions, IT providers and telecommunications entities beginning
  in January 2019. During this time, UNC215 used new TTPs to hinder
  attribution and detection, maintain operational security, employ false
  flags, and leverage trusted relationships for lateral movement. We
  believe this adversary is still active in the region.


 

Attack Lifecycle


 

Between 2019 and 2020, Mandiant responded to several incidents where
  Microsoft SharePoint vulnerability CVE-2019-0604 was used to deliver
  web shells, and then FOCUSFJORD payloads to select government and
  academic targets in the Middle East and Central Asia.


 

After gaining initial access, the operators conduct credential
  harvesting and extensive internal network reconnaissance. This
  includes running native Windows commands on compromised servers,
  executing ADFind on the Active Directory, and scanning the internal
  network with numerous publicly available tools and a non-public
  scanner we named WHEATSCAN. The operators made a consistent effort to
  delete these tools and remove any residual forensic artifacts from
  compromised systems.


 

In another incident response investigation, UNC215 pivoted to
  multiple OWA servers and installed web shells. In the following days,
  the operators interacted with these web shells from internal IP
  addresses, attempting to harvest credentials.


 

After identifying key systems within the target network, such as
  domain controllers and Exchange servers, UNC215 moved laterally and
  deployed their signature malware FOCUSFJORD. UNC215 often uses
  FOCUSFJORD for the initial stages of an intrusion, and then later
  deploys HYPERBRO, which has more information collection capabilities
  such as screen capture and keylogging. While UNC215 heavily relies on
  the custom tools FOCUSFJORD and HYPERBRO, Chinese espionage groups
  often have resource sharing relationships with other groups, and we do
  not have enough information to determine if these tools are developed
  and used exclusively by UNC215.


 


      src="https://www.fireeye.com/content/dam/fireeye-www/blog/images/unc215-israel/fig1.png" alt="" />
 
 Figure 1: Attack Lifecycle


 

Tradecraft and Operational Security


 

We identified numerous examples of efforts by UNC215 to foil network
  defenders by minimizing forensic evidence left on compromised hosts,
  exploiting relationships with trusted third parties, continuously
  improving the FOCUSFJORD backdoor, concealing command and control (C2)
  infrastructure, and incorporating false flags.


 


  Reducing Forensic Evidence on Disk


 

UNC215 consistently cleaned up evidence of their intrusion after
  gaining access to a system. This type of action can make it more
  difficult for incident responders to reconstruct what happened during
  a compromise.


 
 


  Exploiting Trust Relationships


 

UNC215 leveraged trusted third parties in a 2019 operation targeting
  an Israeli government network. As illustrated in Figure 2, the
  operators were able to access their primary target via RDP connections
  from a trusted third party using stolen credentials and used this
  access to deploy and remotely execute FOCUSFJORD on their primary target.


 


      src="https://www.fireeye.com/content/dam/fireeye-www/blog/images/unc215-israel/fig2.png" alt="" />
 
 Figure 2: Two FOCUSFJORD samples
    configured to proxy C2 traffic


 


  Concealing C2 Infrastructure


 

UNC215 made technical modifications to their tools to limit outbound
  network traffic and used other victim networks to proxy their C2
  instructions, likely to minimize the risk of detection and blend in
  with normal network traffic. The following are examples of HYPERBRO
  and FOCUSFJORD samples capable of acting as proxies to relay
  communications to their C2 servers. We do not have enough context
  about the following samples to attribute all of them to UNC215, though
  they are representative of activity we have seen from the group.


 
 

While hunting for FOCUSFJORD samples, we found a sample of a new
  malware (MD5: 625dd9048e3289f19670896cf5bca7d8) that shares code with
  FOCUSFJORD, but is distinct. However, analysis indicates that it only
  contains functions to relay communications between another FOCUSFJORD
  instance and a C2 server (Figure 2, Network A). We suspect this type
  of malware was used in the aforementioned operation. The actors
  stripped out unnecessary FOCUSFJORD capabilities, possibly to reduce
  the likelihood it would be detected by security controls. Figure 3
  contains the data structure as it is being sent from a FOCUSFJORD
  sample configured to communicate with another FOCUSFJORD victim.


 


      src="https://www.fireeye.com/content/dam/fireeye-www/blog/images/unc215-israel/fig3.png" alt="" />
 
 Figure 3: Two FOCUSFJORD samples
    configured to proxy C2 traffic


 


  FOCUSFJORD Changes


 

We have observed numerous variants of the FOCUSFJORD malware family
  since 2017. The authors have added new communications protocols, an
  updated loading mechanism, and expanded the number of supported
  configurations in newer versions. Version numbers indicate that the
  malware undergoes frequent changes and maybe supported by a team of
  developers. Many of these variants contain or remove functionality
  depending on the operator’s unique requirements at the time, which may
  suggest that multiple operators have access to the source code or a
  builder, or that a close relationship exists between the developers
  and operators. 


 

FOCUSFJORD samples can be configured with up to 13 unique registry
  values which allow operators to control and organize compromised
  hosts. In addition to specifying details related to the loading and
  persistence mechanisms and C2 communications, there are two keys which
  allow the operator to add additional context about the victim: 


 
 

It is not clear how or if UNC215 uses these configuration parameters
  to organize and track large numbers of compromised hosts. We observed
  different console values within the same network, identical console
  values using different C2 addresses, and identical console values
  targeting different countries. Some FOCUSFJORD samples from 2018 and
  2020 use the same console values despite the significant gap in time
  (See Table 1).


 
 
   
     
   
              width="120" valign="top">

139.59.81.253

        width="132" valign="top">

Israel


   
              width="120" valign="top">

139.59.81.253

        width="132" valign="top">

Israel


   
              width="120" valign="top">

139.59.81.253

        width="132" valign="top">

Israel


   
              width="120" valign="top">

139.59.81.253

        width="132" valign="top">

Kazakhstan


   
              width="120" valign="top">

159.89.168.83

        width="132" valign="top">

Iran


   
              width="120" valign="top">

103.59.144.183

        width="132" valign="top">

Unknown


   
              width="120" valign="top">

178.79.177.69

        width="132" valign="top">

UAE


   
              width="120" valign="top">

138.68.154.133

        width="132" valign="top">

UAE


   
              width="120" valign="top">

138.68.154.133

        width="132" valign="top">

Unknown


   
              width="120" valign="top">

206.189.123.156

        width="132" valign="top">

Israel (Gov), UAE


   
              width="120" valign="top">

206.189.123.156

        width="132" valign="top">

Israel (IT)


   
              width="120" valign="top">

206.189.123.156

        width="132" valign="top">

Israel (IT)


   
              width="120" valign="top">

159.65.80.157

        width="132" valign="top">

Unknown


   
              width="120" valign="top">

159.65.80.157

        width="132" valign="top">

Unknown


   
              width="120" valign="top">

159.65.80.157

        width="132" valign="top">

Unknown


   
              width="120" valign="top">

128.199.44.86

        width="132" valign="top">

Unknown


   
     
   
     
   
     


          Registry Key 13


          FOCUSFJORD MD5 Hash


          Related C2


          Suspected Target

helen

        valign="top">

3d95e1c94bd528909308b198f3d47620

helen

        valign="top">

f335b241652cb7f7e736202f14eb48e9

helen

        valign="top">

a0b2193362152053671dbe5033771758

helen

        valign="top">

6a9a4da3f7b2075984f79f67e4eb2f28

helen

        valign="top">

a19370b97fe64ca6a0c202524af35a30

helen

        valign="top">

3c1981991cce3b329902288bb2354728

iceland

        valign="top">

26d079e3afb08af0ac4c6d92fd221e71

iceland

        valign="top">

19c46d01685c463f21ef200e81cb1cf1

iceland

        valign="top">

28ce8dbdd2b7dfd123cebbfff263882c

iceland

        valign="top">

a78c53351e23d3f84267e67bbca6cf07 

iceland

        valign="top">

a78c53351e23d3f84267e67bbca6cf07 

idapro

        valign="top">

a78c53351e23d3f84267e67bbca6cf07 

galway

        valign="top">

04c51909fc65304d907b7cb6c92572cd

galway

        valign="top">

0e061265c0b5998088443628c03188f0

galway

        valign="top">

09ffc31a432f646ebcec59d32f286317

galway

        valign="top">

6ca8993b341bd90a730faef1fb73958b

Helen *

        valign="top">

Unknown

        valign="top">

46.101.255.16

        valign="top">

Iran

Helen *

        valign="top">

Unknown

        valign="top">

178.79.143.78

        valign="top">

Iran

Idapro *

        valign="top">

Unknown

        valign="top">

138.68.154.133

        valign="top">

Iran


 


  Table 1: FOCUSFJORD comparison (note: the *
    entries are from public     href="https://www.kamiran.asia/documents/APT27_HackerTeam_Analyse.pdf">reporting
    and have not been verified by Mandiant)


 


  False Flags


 

Artifacts in UNC215 campaigns often contain foreign language strings
  that do not match the country being targeted and may be intended to
  mislead an analyst examining the malware. Additionally, on at least
  three occasions, UNC215 employed a custom tool associated with Iranian
  actors whose source code was leaked.


 
 

The use of Farsi strings, filepaths containing /Iran/, and web
  shells publicly associated with Iranian APT groups may have been
  intended to mislead analysts and suggest an attribution to Iran.
  Notably, in 2019 the government of Iran   href="https://twitter.com/azarijahromi/status/1206071513222467585">accused
  APT27 of attacking its government networks and released a detection
  and removal tool for HYPERBRO malware.


 


  Tradecraft Mistakes


 

While UNC215 prioritizes evading detection within a compromised
  network, Mandiant identified several examples of code, C2
  infrastructure, and certificate reuse indicating that UNC215 operators
  are less concerned about defenders’ ability to track and detect UNC215 activity.


 
 

Attribution


 

Mandiant attributes this campaign to Chinese espionage operators
  which we track as UNC215 a Chinese espionage operation that has been
  suspected of targeting organizations around the world since at least
  2014. We have low confidence that UNC215 is associated with APT27.
  UNC215 has compromised organizations in the government, technology,
  telecommunications, defense, finance, entertainment, and health care
  sectors. The group targets data and organizations which are of great
  interest to Beijing's financial, diplomatic, and strategic objectives.


 

Outlook and Implications


 

The activity detailed in this post demonstrates China’s consistent
  strategic interest in the Middle East. This cyber espionage activity
  is happening against the backdrop of China’s multi-billion-dollar
  investments related to the Belt and Road Initiative (BRI) and its
  interest in Israeli’s robust technology sector.


 
 

China has conducted numerous intrusion campaigns along the BRI route
  to monitor potential obstructions—political, economic, and
  security—and we anticipate that UNC215 will continue targeting
  governments and organizations involved in these critical
  infrastructure projects in Israel and the broader Middle East in the
  near- and mid-term.


 

MITRE ATT&CK Techniques


 
   
     
   
     
   
     
   
     
   
     
   
     
   
     
   
     
   
     
   
     
   
     
   
     
   
     
   
     
   
     
   
     
   
     
   
     
   
     
   
     
   
     
   
     
   
     
   
     
   
     
   
     
   
     
   
     
   
     
   
     
   
     
   
     
   
     
   
     
   
     
   
     
   
     
   
     
   
     
   
     
   
     
   
     
   
     
   
     
   
     
   
     
   
     
   
     
   
     
   
     
   
     
   
     
   
     
   
     
   
     


          ID


          Technique

T1003.001

          valign="top">

OS Credential Dumping: LSASS Memory

T1007

          valign="top">

System Service Discovery

T1010

          valign="top">

Application Window Discovery

T1012

          valign="top">

Query Registry

T1016

          valign="top">

System Network Configuration Discovery


     

T1021.001

          valign="top">

Remote Services: Remote Desktop Protocol


     

T1027

          valign="top">

Obfuscated Files or Information

T1033

          valign="top">

System Owner/User Discovery

T1055

          valign="top">

Process Injection

T1055.003

          valign="top">

Process Injection: Thread Execution
        Hijacking

T1055.012

          valign="top">

Process Injection: Process Hollowing

T1056.001

          valign="top">

Input Capture: Keylogging

T1057

          valign="top">

Process Discovery

T1059.001

          valign="top">

Command and Scripting Interpreter:
        PowerShell

T1059.003

          valign="top">

Command and Scripting Interpreter: Windows
          Command Shell

T1070.004

          valign="top">

Indicator Removal on Host: File Deletion


     

T1070.006

          valign="top">

Indicator Removal on Host: Timestomp

T1071.001

          valign="top">

Application Layer Protocol: Web Protocols


     

T1078

          valign="top">

Valid Accounts

T1082

          valign="top">

System Information Discovery

T1083

          valign="top">

File and Directory Discovery

T1087

          valign="top">

Account Discovery

T1090

        valign="top">

Proxy

T1095

          valign="top">

Non-Application Layer Protocol

T1098

          valign="top">

Account Manipulation

T1105

          valign="top">

Ingress Tool Transfer

T1112

          valign="top">

Modify Registry

T1113

          valign="top">

Screen Capture

T1115

          valign="top">

Clipboard Data

T1133

          valign="top">

External Remote Services

T1134

          valign="top">

Access Token Manipulation

T1140

          valign="top">

Deobfuscate/Decode Files or Information


     

T1190

          valign="top">

Exploit Public-Facing Application

T1199

          valign="top">

Trusted Relationship

T1202

          valign="top">

Indirect Command Execution

T1213

          valign="top">

Data from Information Repositories

T1482

          valign="top">

Domain Trust Discovery

T1489

          valign="top">

Service Stop

T1497

          valign="top">

Virtualization/Sandbox Evasion

T1497.001

          valign="top">

Virtualization/Sandbox Evasion: System
        Checks

T1505.003

          valign="top">

Server Software Component: Web Shell

T1518

          valign="top">

Software Discovery

T1543.003

          valign="top">

Create or Modify System Process: Windows
        Service

T1547.001

          valign="top">

Boot or Logon Autostart Execution: Registry
          Run Keys / Startup Folder

T1553.002

          valign="top">

Subvert Trust Controls: Code Signing

T1559.002

          valign="top">

Inter-Process Communication: Dynamic Data
        Exchange

T1560

          valign="top">

Archive Collected Data

T1564.003

          valign="top">

Hide Artifacts: Hidden Window

T1569.002

          valign="top">

System Services: Service Execution

T1573.002

          valign="top">

Encrypted Channel: Asymmetric Cryptography


     

T1574.002

          valign="top">

Hijack Execution Flow: DLL Side-Loading


     

T1583.003

          valign="top">

Acquire Infrastructure: Virtual Private
        Server

T1588.003

          valign="top">

Obtain Capabilities: Code Signing
        Certificates

T1608.003

          valign="top">

Stage Capabilities: Install Digital
        Certificate


 

Indicators of Compromise


 

The following indicators have been seen in use with the noted
  malware families, but not all have been confirmed to be used by UNC215.


 
   
     
   
     
   
     
   
     
   
     
   
     
   
     
   
     
   
     
   
     


          Type


          Value


          Description

IP

        valign="top">

85.204.74.143

          valign="top">

HYPERBRO C2

IP

        valign="top">

103.79.78.48

          valign="top">

HYPERBRO C2

IP

        valign="top">

89.35.178.105

          valign="top">

HYPERBRO C2

IP

        valign="top">

47.75.49.32

          valign="top">

HYPERBRO C2

IP

        valign="top">

139.59.81.253

          valign="top">

FOCUSFJORD C2

IP

        valign="top">

34.65.151.250

          valign="top">

FOCUSFJORD C2

IP

        valign="top">

159.89.168.83

          valign="top">

FOCUSFJORD C2

IP

        valign="top">

103.59.144.183

          valign="top">

FOCUSFJORD C2

IP

        valign="top">

141.164.52.232

          valign="top">

FOCUSFJORD C2


 

Detecting the Techniques


 

FireEye detects this activity across our platforms.


 
   
     
   
     
   
     
   
     


          Platform(s)


          Detection Name

  • Network Security
  • Email Security

  •            
  • Detection On Demand
  • Malware Analysis

  •            
  • File Protect

             
  • Backdoor.Win32.HyperBro.FEC3

  •          
  • FE_APT_Backdoor_Win32_HYPERBRO_1

  •          
  • FE_Downloader_Win32_FOCUSFJORD_2

  •          
  • FE_Trojan_Raw32_SILKWRAP_1

  •          
  • Trojan.Win32.LuckyMouse.FEC3

  •          
  • FE_Trojan_Raw32_SILKWRAP_1

  •          
  • 33341691_APT.Downloader.Win.FOCUSFJORD

  •          
  • Trojan.Win32.DllHijack.FEC3

  •          
  • FE_Trojan_Raw32_SILKWRAP_1

  •          
  • FE_Autopatt_Win_FOCUSFJORD
  • Trojan.Generic

  •          
  • FE_Tool_Win_Generic_3_FEBeta

  •          
  • FE_Tool_Win32_Generic_3_FEBeta

  •          
  • FE_Trojan_Win_Generic_154_FEBeta

  •          
  • FE_Trojan_Win32_Generic_403_FEBeta

  •          
  • FE_Trojan_Win_Generic_155_FEBeta

  •          
  • FE_Trojan_Win64_Generic_54_FEBeta

  •          
  • FE_APT_Backdoor_Win32_HYPERBRO_2_FEBeta

  •          
  • FE_Trojan_Win32_Generic_404_FEBeta

  •          
  • FE_Trojan_Win32_Generic_406_FEBeta
  • Suspicious
                File Config
  • Suspicious Regkey Added

  •            
  • Suspicious Process Launch Activity
  • Suspicious
                Codeinjection Activity
  • Suspicious Process Delete
              Activity
  • Suspicious Process Hijacking Activity

  •            
  • Suspicious Process Self Deletion Activity

     

Endpoint Security


             
  • Generic.mg.a0b2193362152053

  •          
  • Generic.mg.26d079e3afb08af0

  •          
  • Generic.mg.28ce8dbdd2b7dfd1

  •          
  • Generic.mg.04c51909fc65304d

  •          
  • Generic.mg.0e061265c0b59980

  •          
  • Generic.mg.09ffc31a432f646e

  •          
  • Generic.mg.6ca8993b341bd90a

  •          
  • Generic.mg.0ec4d0a477ba21bd

  •          
  • Generic.mg.04dece2662f648f6

  •          
  • Trojan.GenericKD.43427954

  •          
  • Gen:Variant.Ursu.933105

  •          
  • Trojan.GenericKD.32762213

  •          
  • Trojan.GenericKD.34854595

  •          
  • Gen:Variant.Ursu.256631

  •          
  • Gen:Variant.Doina.16603

  •          
  • Gen:Variant.Doina.13437

Helix


             
  • 1.1.2927.fireeye_intel_hit_ip

  •          
  • 1.1.2928.fireeye_intel_hit_ip

  •          
  • 1.1.2929.fireeye_intel_hit_ip

  •          
  • 1.1.2930.fireeye_intel_hit_ip

  •          
  • 1.1.2947.fireeye_intel_hit_hash

  •          
  • 1.1.2948.fireeye_intel_hit_hash

  •          
  • 1.1.2949.fireeye_intel_hit_hash

  •          
  • 1.1.2950.fireeye_intel_hit_hash

  •          
  • 1.1.1404.windows_methodology_unusual_web_server_child_process

  •          
  • 1.1.3506.windows_methodology_adfind

  •          
  • 1.1.1650.windows_methodology_mimikatz_args

  •          
  • 1.1.1651.antivirus_methodology_mimikatz

  •          
  • 1.1.1652.windows_methodology_invokemimikatz_powershell_artifacts

  •        

Source: UNC215: Spotlight on a Chinese Espionage Campaign in Israel (http://)