Skip to content

ESET Research: Iran-aligned Ballistic Bobcat targets businesses in Israel with a new backdoor

  • ESET Research have discovered a new backdoor, Sponsor, deployed by the Iran-aligned Ballistic Bobcat APT group. 
  • Sponsor was deployed to at least 34 victims in Brazil, Israel, and the United Arab Emirates; we have named this activity the Sponsoring Access campaign.
  • Ballistic Bobcat engaged in scan-and-exploit behavior, as opposed to a targeted campaign against preselected victims. The victims comprise diverse business verticals.
  • The Sponsor backdoor uses configuration files stored on disk. These files are discreetly deployed by batch files, and deliberately designed to appear innocuous, in an attempt to evade detection by scanning engines.

BRATISLAVA, MONTREAL — September 11, 2023 — ESET researchers have discovered a campaign by the Ballistic Bobcat group, which is using a novel backdoor that ESET has named Sponsor. Ballistic Bobcat, previously tracked by ESET Research as APT35/APT42 (also known as Charming Kitten, TA453, or PHOSPHORUS), is a suspected Iran-aligned, advanced, persistent threat group that targets education, government, and healthcare organizations, as well as human rights activists and journalists. It is most active in Israel, the Middle East, and the United States. Its aim is cyberespionage, and a significant majority of the 34 victims were located in Israel, with only two located in Brazil and the UAE. In Israel, automotive, manufacturing, engineering, financial services, media, healthcare, technology and telecommunications verticals have been attacked.

For 16 of the 34 victims of the newly discovered campaign, named Sponsoring Access, it appears that Ballistic Bobcat was not the only threat actor with access to their systems. This may indicate, along with the wide variety of victims and the apparent lack of obvious intelligence value of a few victims, that Ballistic Bobcat engaged in scan-and-exploit behavior, as opposed to a targeted campaign against preselected victims.

Thus, Ballistic Bobcat continues to look for targets of opportunity with unpatched vulnerabilities in internet-exposed Microsoft Exchange servers. “The group continues to use a diverse, open-source toolset supplemented with several custom applications, including the newly discovered Sponsor backdoor. Defenders would be well advised to patch any internet-exposed devices and remain vigilant for new applications popping up within their organizations,” says ESET researcher Adam Burgher, who discovered the Sponsor backdoor and analyzed the latest Ballistic Bobcat campaign.

The Sponsor backdoor uses configuration files stored on disk. These files are discreetly deployed by batch files, and deliberately designed to appear innocuous, in an attempt to evade detection by scanning engines. Ballistic Bobcat deployed the new backdoor in September 2021, while it was wrapping up the campaign documented in CISA Alert AA21-321A and the PowerLess campaign.

During the pandemic, Ballistic Bobcat was targeting COVID-19-related organizations, including the World Health Organization and Gilead Pharmaceuticals, and medical research personnel.

For more technical information about Ballistic Bobcat and its Sponsoring Access campaign, check out the blogpost, “Sponsor with batch-filed whiskers: Ballistic Bobcat’s scan and strike backdoor,” on WeLiveSecurity. Make sure to follow ESET Research on Twitter (today known as X) for the latest news from ESET Research.

Geographical distribution of entities targeted by Ballistic Bobcat with the Sponsor backdoor

 

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

SEC Cyber Reporting Requirements: Tailoring Your Security Strategy

The Securities and Exchange Commission (SEC) has made a significant stride in promoting transparency in the corporate sector. It has introduced new regulations obligating publicly traded companies to reveal significant cybersecurity incidents, offering investors a more transparent view of their cybersecurity risk management, strategy, and governance. Aimed at fostering informed investment decisions, the new SEC cyber reporting requirements mark a turning point in how public companies handle cybersecurity risks.

The SEC Rules Unraveled

At the heart of these rules is a requirement for public companies to announce material cybersecurity incidents within four business days of identifying their material nature. Materiality is discerned based on factors like the incident’s scale and character, repercussions on company operations, and possible effects on financial standing.

Additionally, these rules compel public companies to provide more comprehensive information about their cybersecurity risk management, strategy, and governance.

Disclosure Obligations for Public Companies

After determining a cybersecurity incident is material:

  • Companies must disclose on Item 1.05 of Form 8-K the incident’s nature, scope, and timing along with its impact on the company’s operations and financial health within 4 business days. Details regarding compromised data and ongoing or completed remediation efforts should also be included.
  • Registrants must provide details on Form 10-K (Regulation S-K Item 106) that discuss how they assess, identify, and manage material risks from cybersecurity threats. Details on board oversight of risks from cybersecurity threats and management’s role in assessing and managing them must also be included .
  • Foreign private issuers are required to provide similar disclosures for material cybersecurity incidents and to detail cybersecurity risks management, strategy, and governance on Form 20-F.

The new regulations will be enacted in December or 30 days after publication in the Federal Register. Smaller companies will be allowed an additional 180 days to submit their Form 8-K disclosures.

Additionally, disclosures may be delayed if the United States Attorney General determines that immediate disclosure would pose significant national security or public safety risks and notifies the Commission of this in writing.

Tailoring Your Security Strategy for Optimal Compliance

These technologies and frameworks can provide a multi-layered approach for compliance:

Network Access Control: Your First Line of Defense

In the face of the SEC’s new regulations, the implementation of Network Access Control (NAC) can be a game-changer. NAC solutions provide real-time visibility of all devices connected to the network, along with their user credentials and activities. By enforcing strong access policies, a NAC can ensure only authorized users and devices gain access to critical data, keeping potential threats at bay while aligning with the SEC’s push for improved cybersecurity risk management.

Trust but Verify: Leveraging the Zero Trust Framework

Additionally, adopting a zero trust framework provides a structured and secure approach to compliance. Zero trust operates the belief that no user or device – whether inside or outside the network should be trusted by default. Each access request is verified before access is granted, significantly reducing the risk of breaches while allowing easier compliance with SEC regulations.

Passwordless Authentication: The Future of Secure Access

Password-based systems have long been a weak link in the cybersecurity chain. By making the move towards passwordless authentication, companies can address this issue head-on. Replacing easily cracked, often forgotten passwords for stronger alternatives like biometrics, hardware tokens, or one-time passcodes, offer a user-friendly approach that bolsters security measures while meeting SEC directives.

Closing Thoughts

As we embrace the digital era, public companies face escalating cybersecurity risks. The new SEC cyber reporting requirements shine light on the traditionally opaque world of cyber risk in public companies, while increasing critical transparency with investors. By leveraging a multi-layered security approach, companies can secure an effective path to compliance while mitigating malicious threats.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Portnox
Portnox provides simple-to-deploy, operate and maintain network access control, security and visibility solutions. Portnox software can be deployed on-premises, as a cloud-delivered service, or in hybrid mode. It is agentless and vendor-agnostic, allowing organizations to maximize their existing network and cybersecurity investments. Hundreds of enterprises around the world rely on Portnox for network visibility, cybersecurity policy enforcement and regulatory compliance. The company has been recognized for its innovations by Info Security Products Guide, Cyber Security Excellence Awards, IoT Innovator Awards, Computing Security Awards, Best of Interop ITX and Cyber Defense Magazine. Portnox has offices in the U.S., Europe and Asia. For information visit http://www.portnox.com, and follow us on Twitter and LinkedIn.。

ESET 全球支援服務於 SC Awards 2023 榮獲「最佳客戶服務獎」

全球領先的資訊安全公司 ESET 宣布,於 SC Awards 2023 榮獲「最佳客戶服務獎」。SC Awards 是資訊安全領域最具威望和競爭力的獎項,表彰在資訊安全方面推動創新和取得成功的解決方案、企業和人員。該獎項肯定了 ESET 在提供頂尖客戶支援和服務方面的成就,超越期望,確保企業能夠抵禦當今的網絡威脅。

ESET 北美區總裁 Brent McCarty 表示:「SC Awards 在資訊安全領域享有全球聲譽,我們很榮幸能夠在今年獲得最佳客戶服務獎。我們的工作就是給客戶帶來安心感,旨在為客戶提供跨時區、渠道和語言的接觸。這個獎項證明了我們的團隊在本地和全球範圍內所做的承諾和傑出工作。」

CyberRisk Alliance 的 SC Media 編輯總監 Tom Spring 表示:「今年的 SC Award 獲獎者體現了我們的行業變動。獲獎者展示了非凡的市場敏捷性,並提供創新的解決方案,幫助客戶在日益複雜的對手和新興威脅面前保持領先地位。所有參與 SC Award 的企業所展示的創新策略和技術,真正體現了今年資訊安全行業的卓越創新。」

ESET 的全球支援服務一直精益求精,以應對日益複雜的資訊安全威脅環境,幫助客戶採用強大的資訊安全策略。我們基於以下一系列服務獲得了獎項:

在客戶需要的時間和地點提供當地易於使用的客戶支援服務。公司擁有 162 個全球合作夥伴,在所需的時區和語言提供客戶服務。例如,在美國,企業客戶與 ESET 位於加利福尼亞州聖地亞哥的本地客戶服務團隊進行交流。
多渠道支援,以符合客戶的偏好。ESET 向企業客戶提供免費的電話、電子郵件和即時聊天支援。ESET 還提供一個網上論壇,客戶可以與 ESET 專家討論熱門話題和新興產品問題。

全面的文件資料,包括 ESET 知識庫文章、ESET 安全論壇中的常見問題文件,以及聚焦部署和維護、用戶情景和故障排除的影片教學。此外,每個產品還提供網上用戶指南,介紹 ESET 產品的安裝、配置和功能概述。這一點得到了 ESET 國際市場的本地化語言支援,包括法語加拿大、西班牙語、德語、日語等(例如,ESET Protect Cloud 提供 21 種語言,Endpoint Antivirus for Windows 提供多達 35 種語言)。
更廣泛的意識和教育資源,包括為員工提供強大的資訊安全意識培訓計劃,以應對資訊安全中的人為因素,以及像 WeLiveSecurity 這樣的公共資源,是全球頂尖的企業資訊安全博客之一,提供 5 種語言的文字和影片內容。

作為第 26 屆活動,2023 年的 SC Awards 備受矚目,每年吸引越來越多的參與者。卓越獎設有 15 個類別,並向資訊安全初創企業、投資者和金融合作夥伴開放參與。數百個卓越獎的入圍作品由來自醫療、金融服務、制造業、咨詢和教育等行業的世界級獨立業界領袖組成的評審團進行評審。

About Version 2

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products. Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

關於ESET
ESET成立於1992年,是一家面向企業與個人用戶的全球性的電腦安全軟件提供商,其獲獎產品 — NOD32防病毒軟件系統,能夠針對各種已知或未知病毒、間諜軟件 (spyware)、rootkits和其他惡意軟件為電腦系統提供實時保護。ESET NOD32佔用 系統資源最少,偵測速度最快,可以提供最有效的保護,並且比其他任何防病毒產品獲得了更多的Virus Bulletin 100獎項。ESET連續五年被評為“德勤高科技快速成長500 強”(Deloitte’s Technology Fast 500)公司,擁有廣泛的合作夥伴網絡,包括佳能、戴爾、微軟等國際知名公司,在布拉迪斯拉發(斯洛伐克)、布裏斯托爾(英國 )、布宜諾斯艾利斯(阿根廷)、布拉格(捷克)、聖地亞哥(美國)等地均設有辦事處,代理機構覆蓋全球超過100個國家。

ESET 全球支援服務於 SC Awards 2023 榮獲「最佳客戶服務獎」

全球領先的資訊安全公司 ESET 宣布,於 SC Awards 2023 榮獲「最佳客戶服務獎」。SC Awards 是資訊安全領域最具威望和競爭力的獎項,表彰在資訊安全方面推動創新和取得成功的解決方案、企業和人員。該獎項肯定了 ESET 在提供頂尖客戶支援和服務方面的成就,超越期望,確保企業能夠抵禦當今的網絡威脅。

ESET 北美區總裁 Brent McCarty 表示:「SC Awards 在資訊安全領域享有全球聲譽,我們很榮幸能夠在今年獲得最佳客戶服務獎。我們的工作就是給客戶帶來安心感,旨在為客戶提供跨時區、渠道和語言的接觸。這個獎項證明了我們的團隊在本地和全球範圍內所做的承諾和傑出工作。」

CyberRisk Alliance 的 SC Media 編輯總監 Tom Spring 表示:「今年的 SC Award 獲獎者體現了我們的行業變動。獲獎者展示了非凡的市場敏捷性,並提供創新的解決方案,幫助客戶在日益複雜的對手和新興威脅面前保持領先地位。所有參與 SC Award 的企業所展示的創新策略和技術,真正體現了今年資訊安全行業的卓越創新。」

ESET 的全球支援服務一直精益求精,以應對日益複雜的資訊安全威脅環境,幫助客戶採用強大的資訊安全策略。我們基於以下一系列服務獲得了獎項:

在客戶需要的時間和地點提供當地易於使用的客戶支援服務。公司擁有 162 個全球合作夥伴,在所需的時區和語言提供客戶服務。例如,在美國,企業客戶與 ESET 位於加利福尼亞州聖地亞哥的本地客戶服務團隊進行交流。
多渠道支援,以符合客戶的偏好。ESET 向企業客戶提供免費的電話、電子郵件和即時聊天支援。ESET 還提供一個網上論壇,客戶可以與 ESET 專家討論熱門話題和新興產品問題。

全面的文件資料,包括 ESET 知識庫文章、ESET 安全論壇中的常見問題文件,以及聚焦部署和維護、用戶情景和故障排除的影片教學。此外,每個產品還提供網上用戶指南,介紹 ESET 產品的安裝、配置和功能概述。這一點得到了 ESET 國際市場的本地化語言支援,包括法語加拿大、西班牙語、德語、日語等(例如,ESET Protect Cloud 提供 21 種語言,Endpoint Antivirus for Windows 提供多達 35 種語言)。
更廣泛的意識和教育資源,包括為員工提供強大的資訊安全意識培訓計劃,以應對資訊安全中的人為因素,以及像 WeLiveSecurity 這樣的公共資源,是全球頂尖的企業資訊安全博客之一,提供 5 種語言的文字和影片內容。

作為第 26 屆活動,2023 年的 SC Awards 備受矚目,每年吸引越來越多的參與者。卓越獎設有 15 個類別,並向資訊安全初創企業、投資者和金融合作夥伴開放參與。數百個卓越獎的入圍作品由來自醫療、金融服務、制造業、咨詢和教育等行業的世界級獨立業界領袖組成的評審團進行評審。

About Version 2

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products. Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

關於ESET
ESET成立於1992年,是一家面向企業與個人用戶的全球性的電腦安全軟件提供商,其獲獎產品 — NOD32防病毒軟件系統,能夠針對各種已知或未知病毒、間諜軟件 (spyware)、rootkits和其他惡意軟件為電腦系統提供實時保護。ESET NOD32佔用 系統資源最少,偵測速度最快,可以提供最有效的保護,並且比其他任何防病毒產品獲得了更多的Virus Bulletin 100獎項。ESET連續五年被評為“德勤高科技快速成長500 強”(Deloitte’s Technology Fast 500)公司,擁有廣泛的合作夥伴網絡,包括佳能、戴爾、微軟等國際知名公司,在布拉迪斯拉發(斯洛伐克)、布裏斯托爾(英國 )、布宜諾斯艾利斯(阿根廷)、布拉格(捷克)、聖地亞哥(美國)等地均設有辦事處,代理機構覆蓋全球超過100個國家。