Site navigation

Kaspersky Uncovers Mass ‘Spyware Campaign’

Graham Turner

,

Spyware campaign
The cybersecurity company has uncovered a new piece of malware that has targeted more than 35,000 computers across 195 countries.

Dubbed “PseudoManuscrypt” – for its similarities with the advanced persistent threat (APT) group Lazarus’ Manuscrypt malware – the newly discovered malware contains advanced spying capabilities and has been seen targeting both government organisations and industrial control systems (ICS).

Industrial organisations are some of the most coveted targets for cybercriminals – both for financial gain and intelligence gathering. 2021 saw significant interest in industrial organisations from well-known APT groups like Lazarus and APT41.

From January 20 to November 10, 2021, PseudoManuscrypt was blocked on more than 35,000 computers in 195 countries. Many of the targets were industrial and government organisations, including military-industrial enterprises and research laboratories.

7.2% of attacked computers were part of ICSs, with engineering and building automation representing the most affected industries.

PseudoManuscrypt is initially downloaded on targets’ systems via fake pirated software installer archives, some of which are for ICS-specific pirated software. It is likely these fake installers are offered via a Malware-as-a-Service (MaaS) platform.

In some cases, PseudoManuscrypt was installed via the infamous Glupteba botnet. After initial infection, a complicated infection chain is initiated that eventually downloads the main malicious module.

Two variants of this module have been identified. Both are capable of advanced spyware capabilities, including logging keystrokes, copying data from the clipboard, stealing VPN (and potentially RDP) authentication credentials and connection data, copying screenshots, etc.


Recommended


The attacks show no preference for particular industries, however, the large number of engineering computers attacked, including systems used for 3D and physical modelling and digital twins, suggest that industrial espionage may be one objective.

Oddly enough, some of the victims share ties with the victims of the Lazarus campaign ICS CERT previously reported on, and data is sent to the attackers’ server over a rare protocol using a library that has previously only been used with APT41’s malware. Nevertheless, given the large number of victims and the lack of an explicit focus, Kaspersky does not link the campaign to Lazarus or any known APT threat actor.

“This is a highly unusual campaign, and we are still piecing together the various information we have. However, one fact is clear: this is a threat that specialists need to pay attention to,” comments Vyacheslav Kopeytsev, security expert at Kaspersky.

He adds: “It has been able to make its way onto thousands of ICS computers, including many high-profile organisations. We will be continuing our investigations, keeping the security community apprised any new findings.”

To stay safe from PseudoManuscrypt, Kaspersky offers organisations the following advice:

  • Install endpoint protection software on all servers and workstations
  • Check that all endpoint protection components are enabled on all systems and that a policy is in place which requires the administrator password be entered in the event someone attempts to disable the software.
  • Check that Active Directory policies include restrictions on user attempts to log in to systems. Users should only be allowed to log in to those systems which they need to access to perform their job responsibilities.
  • Restrict network connections, including VPN, between systems on the OT network; block connections on all those ports that are not required for the continuity and safety of operations.
  • Use smart cards (tokens) or one-time codes as the second authentication factor when establishing a VPN connection. In cases where this is applicable, use the Access Control List (ACL) technology to restrict the list of IP addresses from which a VPN connection can be initiated.
  • Train employees of the enterprise in working with the internet, email and other communication channels securely and, specifically, explain the possible consequences of downloading and executing files from unverified sources.
  • Use accounts with local administrator and domain administrator privileges only when this is necessary to perform job responsibilities.
  • Consider using Managed Detection and Response class services to gain quick access to high-level knowledge and the expertise of security professionals.

Get the latest news from DIGIT direct to your inbox

Our newsletter covers the latest technology and IT news from Scotland and beyond, as well as in-depth features and exclusive interviews with leading figures and rising stars.

We will keep you up to date on the pivotal issues impacting the sector and let you know about key upcoming events to ensure that you don’t miss out on what’s going on across the Scottish tech community.

Click here to subscribe.

Graham Turner

Sub Editor

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data