April 15, 2020 By David Bisson 2 min read

Security researchers discovered an attack campaign in which APT41 distributed the Speculoos backdoor by exploiting CVE-2019-19781.

Palo Alto Networks’ Unit 42 discovered the Speculoos backdoor while investigating an attack campaign from APT41 that targeted a variety of organizations in North America, South America and Europe. The campaign exploited CVE-2019-19781, a vulnerability affecting certain Citrix appliances that enabled a malicious actor to remotely execute arbitrary commands. This vulnerability first garnered public attention in mid-December 2019 and received a permanent fix by the end of January 2020. It’s around that time when this campaign began.

Upon successful implementation, the backdoor payload connected to its command-and-control (C&C) server and completed a TLS handshake. At that point, the malware fingerprinted the system and sent this information back to its C&C server. Once it received a response, Speculoos entered into a loop for the purpose of receiving commands such as instructions to create a remote shell, kill a process and/or delete a file, among other functionality.

A Look at APT41’s Other Attack Activity

This isn’t the first time that APT41 has garnered the attention of the security community. Back in August 2019, for instance, FireEye released a report in which it detailed the threat group’s efforts to perpetrate digital espionage using non-public malware against financial organizations.

In March 2020, FireEye detailed the attack campaign discussed by Unit 42 above. That operation lasted until March 11, although FireEye observed a lull in APT41’s activity during the last week of January.

Defending Against the Speculoos Backdoor Campaign

Security professionals can defend their organizations against the Speculoos backdoor campaign uncovered by Unit 42 by using thoughtful prioritization when it comes to their patch management programs. As part of this effort, teams need to prioritize applications that are critical to the business and those that would cause the greatest disruption if they were attacked.

Infosec personnel should also consider using threat intelligence to learn about the tactics, techniques and procedures (TTPs) of attack groups like APT41. This information can then help them spot instances of lateral movement and other malicious activity when they’re in motion.

More from

Another category? Why we need ITDR

5 min read - Technologists are understandably suffering from category fatigue. This fatigue can be more pronounced within security than in any other sub-sector of IT. Do the use cases and risks of today warrant identity threat detection and response (ITDR)? To address this question, we work backwards from the vulnerabilities, threats, misconfigurations and attacks that IDTR specializes in providing visibility into. As identity threat detection and response (ITDR) technology evolves, one of the most common queries we get is: “Why do we need…

On holiday: Most important policies for reduced staff

4 min read - On Christmas Eve, 2023, the Ohio State Lottery had to shut down some of its systems because of a cyberattack. Around the same time, the Dark Web had a “Leaksmas” event, where cyber criminals shared stolen information for free as a holiday gift. In fact, the month of December 2023 saw more than 2 billion records breached and 1,351 disclosed security incidents, according to research from IT Governance — an increase of 332% and 187%, respectively, over the month of…

How I got started: Incident responder

3 min read - As a cybersecurity incident responder, life can go from chill to chaos in seconds. What is it about being an incident responder that makes people want to step up for this crucial cybersecurity role?With our How I Got Started series, we learn from experts in their field and find out how they got started and what advice they have for anyone looking to get into the field.In this Q&A, we spoke with IBM’s own Dave Bales, co-lead X-Force Incident Command…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today