Attackers launched a new campaign that leveraged updated downloaders and a backdoor to distribute samples of the Zebrocy malware family.

On August 20, researchers at ESET spotted a new Zebrocy campaign in which the Sednit group targeted embassies of and ministries of foreign affairs in Eastern European and Central Asian countries. The campaign started with a phishing email that contained a malicious attachment. Once opened, this otherwise blank document downloaded a remote template hosted on Dropbox to execute malicious macros and ultimately load the malware.

ESET came across a few surprises along the way. For instance, researchers found that the Sednit group had rewritten its Delphi downloader in Golang for its latest campaign. This downloader had fewer data-gathering capabilities than the group’s previous downloaders. In addition, researchers observed that the backdoor was now written in Golang and no longer in Delphi.

The Slovakian security firm reasoned that Sednit made these changes to help the campaign’s components more effectively evade detection.

A Look at Zebrocy’s History

The Sednit group has been around since at least 2004, making it one of the more longstanding cyberthreats. ESET had a chance to examine the Zebrocy malware in depth in November 2018, when the security firm found several indicators suggesting that a team less experienced than the Sednit core was responsible for developing the threat and its components. Even so, the malware continued to evolve.

In December 2018, for instance, Palo Alto Networks found a new Go variant of the attack tool. In June 2019, Kaspersky Lab observed Zebrocy using a new downloader to target organizations in Germany, the U.K., Iran, Ukraine and Afghanistan.

How to Defend Against Phishing-Borne Threats

Security professionals can help defend their organizations against phishing-borne threats like Zebrocy by using multifactor authentication (MFA) and identity and access management (IAM) to remedy the weaknesses of password-only authentication for work accounts. Companies should also advocate for phishing simulations that can evaluate their organization’s defenses against an email attack campaign.

More from

How Do You Plan to Celebrate National Computer Security Day?

In October 2022, the world marked the 19th Cybersecurity Awareness Month. October might be over, but employers can still talk about awareness of digital threats. We all have another chance before then: National Computer Security Day. The History of National Computer Security Day The origins of National Computer Security Day trace back to 1988 and the Washington, D.C. chapter of the Association for Computing Machinery’s Special Interest Group on Security, Audit and Control. As noted by National Today, those in…

Abuse of Privilege Enabled Long-Term DIB Organization Hack

From November 2021 through January 2022, the Cybersecurity and Infrastructure Security Agency (CISA) responded to an advanced cyberattack on a Defense Industrial Base (DIB) organization’s enterprise network. During that time frame, advanced persistent threat (APT) adversaries used an open-source toolkit called Impacket to breach the environment and further penetrate the organization’s network. Even worse, CISA reported that multiple APT groups may have hacked into the organization’s network. Data breaches such as these are almost always the result of compromised endpoints…

Deploying Security Automation to Your Endpoints

Globally, data is growing at an exponential rate. Due to factors like information explosion and the rising interconnectivity of endpoints, data growth will only become a more pressing issue. This enormous influx of data will invariably affect security teams. Faced with an enormous amount of data to sift through, analysts are feeling the crunch. Subsequently, alert fatigue is already a problem for analysts overwhelmed with security tasks. With the continued shortage of qualified staff, organizations are looking for automation to…

Worms of Wisdom: How WannaCry Shapes Cybersecurity Today

WannaCry wasn't a particularly complex or innovative ransomware attack. What made it unique, however, was its rapid spread. Using the EternalBlue exploit, malware could quickly move from device to device, leveraging a flaw in the Microsoft Windows Server Message Block (SMB) protocol. As a result, when the WannaCry "ransomworm" hit networks in 2017, it expanded to wreak havoc on high-profile systems worldwide. While the discovery of a "kill switch" in the code blunted the spread of the attack and newly…