Skip to content

ESET Threat Report: Infostealers using AI & banking malware creating deepfake videos to steal money

  • ESET has released its latest Threat Report, which summarizes threat landscape trends seen in ESET telemetry and from the perspective of ESET experts, from December 2023 through May 2024.
  • Infostealers started to impersonate generative AI tools such as Midjourney, Sora, and Gemini. 
  • New mobile malware GoldPickaxe is capable of stealing facial recognition data to create deepfake videos.
  • RedLine Stealer saw several detection spikes in ESET H1 2024 telemetry, caused by campaigns in Spain, Japan and Germany.
  • Balada Injector, a gang notorious for exploiting WordPress plugin vulnerabilities, continued to run rampant in the first half of 2024, compromising over 20,000 websites as ESET telemetry detected 400,000 hits.

BRATISLAVAJune 27, 2024 — ESET has released its latest Threat Report, which summarizes threat landscape trends seen in ESET telemetry and from the perspective of both ESET threat detection and research experts, from December 2023 through May 2024. These past six months painted a dynamic landscape of Android financial threats, malware going after victims’ mobile banking funds – be they in the form of “traditional” banking malware or, more recently, cryptostealers. Infostealing malware can now be found impersonating generative AI tools, and new mobile malware GoldPickaxe is capable of stealing facial recognition data to create deepfake videos used by the malware’s operators to authenticate fraudulent financial transactions. Video games and cheating tools used in online multiplayer games were recently found to contain infostealer malware such as the RedLine Stealer, which saw several detection spikes in H1 2024 in ESET telemetry.

“GoldPickaxe has both Android and iOS versions and has been targeting victims in Southeast Asia through localized malicious apps. As ESET researchers investigated this malware family, they discovered that an older Android sibling of GoldPickaxe, called GoldDiggerPlus, has also tunneled its way to Latin America and South Africa by actively targeting victims in these regions,” explains Jiří Kropáč, Director of ESET Threat Detection.

In recent months Infostealing malware also began to utilize the impersonation of generative AI tools. In H1 2024, Rilide Stealer was spotted misusing the names of generative AI assistants, such as OpenAI’s Sora and Google’s Gemini, to entice potential victims. In another malicious campaign, the Vidar infostealer was lurking behind a supposed Windows desktop app for AI image generator Midjourney – even though Midjourney’s AI model is only accessible via Discord. Since 2023, ESET Research has increasingly seen cybercriminals abusing the AI theme – a trend that is expected to continue.

Gaming enthusiasts who ventured out of the official gaming ecosystem were attacked by infostealers, as some cracked video games and cheating tools used in online multiplayer games were recently found to contain infostealer malware such as Lumma Stealer and RedLine Stealer. RedLine Stealer saw several detection spikes in H1 2024 in ESET telemetry, caused by campaigns in Spain, Japan, and Germany. Its recent waves were so significant that RedLine Stealer detections in H1 2024 surpassed those from H2 2023 by a third.

Balada Injector, a gang notorious for exploiting WordPress plug-in vulnerabilities, continued to run rampant in the first half of 2024, compromising over 20,000 websites and racking up over 400,000 hits in ESET telemetry for the variants used in the gang’s recent campaign. On the ransomware scene, former leading player LockBit was knocked off its pedestal by Operation Chronos, a global disruption conducted by law enforcement in February 2024. Although ESET telemetry recorded two notable LockBit campaigns in H1 2024, these were found to be the result of non-LockBit gangs using the leaked LockBit builder.

The ESET Threat Report features news about recently released deep-dive investigation into one of the most advanced server-side malware campaigns, which is still growing – Ebury group, with their malware and botnet. Over the years, Ebury has been deployed as a backdoor to compromise almost 400,000 Linux, FreeBSD, and OpenBSD servers; more than 100,000 were still compromised as of late 2023.

For more information, check out the ESET Threat Report H1 2024 on WeLiveSecurity.com. Make sure to follow ESET Research on Twitter (today known as X) for the latest news from ESET Research.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

Kaseya DattoCon Europe: Why quality matters

Opting for cheap cybersecurity solutions could prove more costly than you think.

In the highly competitive world of managed service providers (MSPs), business leaders make tough decisions on how to balance costs and revenues to maximize profits without decreasing quality. In such a world, a low-cost security service seems like a gift from heaven which businesses ought to accept to cut their costs.

But there are certain hidden costs of doing business in areas where such trade-offs between price and quality can become harmful. And cybersecurity is one of those areas.

Participating at the Kaseya DattoCon Europe 2024 conference focusing on MSPs, I had a chance to speak with several MSP representatives on this topic. Time and time again, I heard from them that their budgets were so tight that they opted for a cheaper solution despite the risks of being breached during more elaborate cyberattacks. A penny saved is a penny earned, right?

Well, let me show you why this is not a good idea.

What are your chances

It is true that free antivirus solutions can deflect some simple attacks, but unfortunately, the days when simple viruses were among the few threats to businesses are long gone. While some threat actors are status driven, most remain driven by financial gain (93% of all attacks), and money is the all-powerful motivator for improving their tools and techniques.

This is the reason 66% of organizations worldwide fell victim to ransomware attacks between March 2022 and March 2023, according to a survey published by Statista among cybersecurity leaders at global organizations.

Another more advanced threat causing headaches for business owners all around the world is the exploitation of software vulnerabilities. Currently, MITRE ATT&CK’s List of Common Vulnerabilities and Exposures (CVE) has documented more than 237,000 of them.

A 2024 Ponemon Institute report found that only 38% of respondents are confident that their organizations are effective at detecting and responding to an exploit of a known vulnerability. Almost half of respondents (47%) said it takes at least a month to more than six months for their organizations to respond to a critical software vulnerability.

Due to the manner of their business, MSPs should be also concern themselves with cloud attacks. In 2022, nearly 50 percent of respondents globally stated that their company confronted unplanned expenses in order to fix security gaps due to cloud attacks, and 15 percent of respondents registered a decrease in new sales.

So, if you think that your clientele encountering more advanced cyberattacks is just a “theoretical threat” and “something like that can’t happen to them on my watch,” think again.

Possible loses

Now, let’s take a look at the financial aspects of deploying a high-quality cybersecurity solution. Something I heard particularly from smaller and medium-sized MSPs trying to make every penny count was that they aim to save as much money as possible.

However, my response was that by investing a few thousand euros more now, they could save hundreds of thousands of euros in the long run.

To drive this point home, the costs of a breach are not small. IBM Security studied 553 organizations impacted by data breaches that occurred between March 2022 and March 2023, and found that the average total cost of a data breach reached $4.45 million in 2023.

Only a third of companies discovered the data breach by themselves, which really highlights the importance of high-quality support, particularly threat detection—especially considering that the costs were nearly $1 million higher in cases where attackers disclosed a breach.

At ESET we believe in a prevention-first approach, which means mitigating a threat before it can do any harm. Catching malware activity within business systems is nice, but it often also means that the malware has already caused complications, such as business disruptions and revenue losses from system downtime, lost customers, and reputation damage. In the aforementioned IBM study, these additional costs reached an average of $1.3 million.

In the U.S. alone, the cost of cybercrime in general reached $320 billion in 2023 and is projected to reach $1.82 trillion by 2028.

These worrying trends expose the claim that smaller businesses are not interesting for cybercriminals as a myth. Quite the opposite, threat actors are well aware of smaller and medium-sized businesses’ (SMBs) weaknesses. This year, 56% of SMBs have already faced at least one cyberattack and 78% are concerned that a severe cyberattack could drive them out of business.

There is a price for deploying a lower-quality product and you probably don’t want to pay it.

Deploying high-end technology is not window dressing

At present, many MSPs are given solutions for free, which keeps them in vendors’ ecosystems. But they pay a price in terms of poor operability and performance. For example, representatives at some bigger MSPs I spoke with said that they weren’t happy with the quality of the telemetry they could gather from clients’ endpoints.

On the other hand, ESET products were praised for their automation and seamless operation without disruptions. Our protection for businesses, ESET PROTECT, enables operating on a single unified cybersecurity platform, which makes the lives of MSP admins easier. “It simply works,” I heard from our customers, which is feedback we have been receiving since we launched our MSP program in 2013.

“We’ve picked up customers of all shapes and sizes over the last 20 years. But from an antivirus and endpoint security point of view, once we’d settled on ESET, the products evolved as we have. The relationships we’ve been able to garner and build with the Support Teams, the Sales Teams, the PreSales Executives, with everybody at ESET are long-standing,” said Andrew Owens, Head of Sales, Risc IT Solutions.

Check out how the ESET MSP Program elevates Risc IT Solutions’ business growth here:

And there is another aspect of investing in a high-quality security solution – vendors’ experiences and reliability. For example, ESET is a global leader in digital security with more than 30 years of experience, having more than 1 billion protected internet users, 13 global Research & Development (R&D) centers, and more than 600 R&D experts. The quality of our protection has been repeatedly acknowledged in numerous comparatives over the years.

What about the reliability of cheap or free products? Let’s put it this way: there is a reason many of them don’t appear among the recognized comparative tests and analyses.

Benefits of ESET MSP program:

Leading cybersecurity technology –ESET PROTECT offers multilayered security technology combining machine learning, AI, a cloud reputation system, and human expertise. With ESET PROTECT, MSPs can offer flexible subscription solutions, providing security for all major platforms.

Multiple capabilities in one package – Decrease the attack surface with modern endpoint protection, server protection, threat hunting, mobile threat defense, cloud app protection, Vulnerability & Patch Management, and much more.

Flexibility – With daily billing and monthly invoicing, customers pay for what they really use: no flat rates, with no long-term commitment. Flexible management allows users to upgrade subscriptions and adjust seat counts on their own.

Unified ecosystem – With ESET’s cloud-first ESET PROTECT Platform, users have a complete overview of all their clients from a single pane of glass, allowing them to see and manage clients in one place.

Automation – ESET PROTECT automation features, such as Dynamic Groups, were designed to save IT admins time and help them avoid portal fatigue.

Integrations – ESET actively cooperates with the major RMM and PSA players to create best-of-breed, in-depth integrations.

As you can see, this is not just a simple protection of businesses’ endpoints against simple viruses but a robust solution covering a huge threat landscape. And all of these are offered for a fair price. If you are not sure about the ESET MSP program value, just check the prices for all these capabilities on the cybersecurity market when offered as standalone products.

You have only one reputation

A vision of having a free cybersecurity solution that covers all business needs while saving some money may be intriguing but is far from reality. While cyberthreats are becoming more sophisticated, IT processes are getting more complicated, and a proper cybersecurity solution should address both problems at once.

Failing to do so leads to business losses, disruptions, and losing clients. Remember, you have only one reputation, which is worth more than savings on a cybersecurity product.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

Locked Shields 2024: Ancient inspiration deployed for today’s complex digital battlegrounds

 

Is it strange that cybersecurity companies would be called to share their expertise in a military simulation of today’s digital battlespace? The answer seems to be a resounding no.

However, despite being civilian organizations that don’t drill cyber-military scenarios, full-stack cybersecurity companies consider every day to be the real thing, with malware researchers, threat monitoring analysts, and product R&D teams alternating in various combinations to help set up and test our clients’ IT security and monitor for and deter threats. To be successful, our teams must master an agile phalanx-like approach to protect the collective of online users.

The phalanx, an ancient box-like formation that enabled classical Greek heavy infantry – composed of citizen-soldiers – to rapidly form ranks into a tight defensive structure of overlapping shields, is a well-chosen muse for Locked Shields, the annual cyber-wargaming event organized by the NATO Cooperative Cyber Defense Centre of Excellence. Locked Shields, and the phalanx that inspired it, is the perfect bridge to connect today’s digital present to the analog past, demonstrating that Trojan horses and other ancient battle tactics are still relevant in today’s battlespace.

Our forces and kit

On April 24-25, more than 60 ESET system engineers, security monitoring analysts, malware researchers and analysts, and communications specialists formed ranks with defenders from the Slovak and Hungarian militaries and the private and academic sectors to defend our assigned battlespace, within a virtual nation named Berylia, against massive cyberattacks designed to cripple the country and create public unrest.

Underpinned by this year’s Locked Shields theme “Collaboration is our protection,” our citizen-soldiers used their skills, experience, and tool sets to achieve fourth place out of 18 teams. To give a further sense of scale, the simulation brought together over 4,000 participants from 39 countries to deliver the largest Locked Shields event yet.

Along with our on-loan cyber warriors and their significant professional experience, ESET brought several pieces of critical kit to the simulated battlespace:

Setting up defenses

Team Berylia was given a few windows of time to explore the virtual battlespace and calibrate tools before the hostilities began. This meant establishing the processes of:

  • Deploying ESET endpoint security solutions, the ESET Inspect agent, and other security agents.
  • Setting up and configuring the IT systems Team Berylia would use to manage the power grid, gas distribution, air defense, satellite, 5G, and situational awareness systems, to name a few.
  • Calibrating ESET Inspect detections to Berylia’s network, thus reducing noise and giving our defenders the time to allocate threat monitoring and remediation capacity where the battle dictated.

Based on our experience with providing detection and response services to our customers, we also established other proven processes and tools, deployed across critical areas, that tremendously helped us during the execution phase.

Communication and legal support

The exercise included elements that strongly correlated with a security vendor’s business-as-usual operations. For example, ESET and others supplied communications experts who were tasked with preparing reports, such as the SITREP (situation report), used to help defenders keep track of the cyber situation and the status of all capabilities, and the Cyber Threat Intelligence report (CTIREP), which provides an evidence-based analysis of emerging threats.

In parallel, the legal team managed cooperation agreements between infrastructure operators in Berylia, and their cross-border allies, to share electricity and provided counsel to ensure defensive operations remained adherent to international law.

What we learned about ourselves and our tools

We successfully rebuffed the network attacks on the firewall and against the following systems: air defense, gas distribution, and power grid. In addition, the defenders quickly hunted down most of the pre-planted backdoors, both known and custom, severely limiting the usefulness of this attack vector for the Lock Shields’ (aggressor) red team. Unfortunately, a simulated thunderstorm took down our power grid.

But fortune smiles upon the prepared. Our communications and legal teams, and power grid operators, were able to mitigate the impact in a great demonstration of teamwork and coordinated operations between multiple (defender) blue teams. This was proof that a phalanx can still be deployed, even in the modern hybrid battlespace. Cooperation with the friendly neighboring teams happened in two key ways:

  • First, quick communication, legal analysis, and agreements with neighboring power suppliers allowed electricity supply to be restored.
  • Second, we provided these neighbors with threat intelligence derived from the attacks we had already experienced.

Prevention first

This collaborative defense approach was backed by the sharing of indicators of compromise (IoCs) via the Malware Information Sharing Platform (MISP) server, which provided mutually enriching data points for threat hunting by all blue teams.

In short, this cyber-battle simulation was an intensively immersive experience for all the technologists involved, be it threat analysts trying to understand tactics to anticipate the next stages of an attack or engineers configuring cyber defenses. Locked Shields is proof that our experts, well versed in operations on the digital front lines, could drop the normal constraints of cybersecurity for businesses and partner with both national and European defense structures when called upon.

Looking back on Locked Shields 2024

With collaboration being the focus of the 15th annual exercise under the theme “Collaboratio tutela nostra est,” or ‘Collaboration is our protection’, ESET supplied the Slovak-Hungarian team with defensive capabilities that contributed to the team’s top three placings in:

  • Cyber threat intelligence
  • Client-side protection
  • Forensics
  • Strategic communications

Taking fourth place out of 18 participating teams, made up of similarly composed cross-country units, the Slovak-Hungarian team successfully achieved its strategic objectives, building not only on expertise and state-of-the-art security technologies but, most importantly, on communication and intensive cooperation between the participants.

Likely considered underdogs by many, we punched well above our weight and tested ourselves and our security technologies to the limit. ESET considers this fertile ground for new ideas and further collaboration experience and a great demonstration of the reasons why we’ve been successful at protecting progress for more than 30 years.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

ESET Research: Arid Viper group targets Middle East again, poisons Palestinian app with AridSpy spyware

  • ESET Research discovered multistage Android malware, which ESET named AridSpy, being distributed via five dedicated websites.
  • ESET detected occurrences of AridSpy in both Palestine and Egypt and attribute it, with medium confidence, to the Arid Viper APT group.
  • AridSpy’s code is, in some cases, bundled into applications that provide legitimate functionality.
  • AridSpy is a remotely controlled Trojan that focuses on user data espionage; it can spy on messaging apps, and exfiltrate content from the device, among other functionalities.

BRATISLAVA, KOŠICEJune 13, 2024 — ESET researchers have identified five campaigns that employ trojanized apps to target Android users. Most likely carried out by the Arid Viper APT group, these campaigns started in 2022, and three of them are still ongoing at the time of publication of this press release. They deploy multistage Android spyware, which ESET has named AridSpy, that downloads first- and second-stage payloads from its Command & Control (C&C) server to assist it in avoiding detection. The malware is distributed through dedicated websites impersonating various messaging apps, a job opportunity app, and a Palestinian Civil Registry app. Often, these are existing applications that have been trojanized by the addition of AridSpy’s malicious code. ESET Research detected the remotely controlled AridSpy Trojan, which focuses on user data espionage, in Palestine and Egypt.

Arid Viper, also known as APT-C-23, Desert Falcons, or Two-tailed Scorpion, is a cyberespionage group known for targeting countries in the Middle East; the group has drawn attention over the years for its vast arsenal of malware for Android, iOS, and Windows platforms.

Three affected apps provided via the impersonating websites are legitimate apps trojanized with AridSpy spyware. These malicious apps have never been offered through Google Play and are downloaded exclusively from third-party sites. To install these apps, the potential victim is asked to enable the non-default Android option to install apps from unknown sources. The majority of the spyware instances registered in Palestine were for the malicious Palestinian Civil Registry app.

“In order to gain initial access to the device, the threat actors try to convince their potential victim to install a fake, but functional, app. Once the target clicks the site’s download button, myScript.js, hosted on the same server, is executed to generate the correct download path for the malicious file,” explains ESET researcher Lukáš Štefanko, who discovered AridSpy, describing how users are infected.

One campaign included LapizaChat, a malicious Android messaging application with trojanized versions of StealthChat: Private Messaging bundled with AridSpy’s malicious code. ESET identified two other campaigns that started distributing AridSpy after LapizaChat, this time posing as messaging apps named NortirChat and ReblyChat. NortirChat is based on the legitimate Session messaging app, while ReblyChat is based on the legitimate Voxer Walkie Talkie Messenger.

On the other hand, the Palestinian Civil Registry app is inspired by an app previously available on Google Play. However, based on our investigation, the malicious app available online is not a trojanized version of the app on Google Play; instead, it uses that app’s legitimate server to retrieve information. This means that Arid Viper was inspired by that app’s functionality but created its own client layer that communicates with the legitimate server. Most likely, Arid Viper reverse engineered the legitimate Android app from Google Play and used its server to retrieve victims’ data. The final campaign ESET identified distributes AridSpy as a job offering app.

AridSpy has a feature intended to avoid network detection – specifically C&C communication. It can deactivate itself, as AridSpy states in the code. Data exfiltration is initiated either by receiving a command from the Firebase C& C server or when a specifically defined event is triggered. These events include internet connectivity changes, the app is installed or uninstalled, a phone call is made or received, an SMS message is sent or received, a battery charger is connected or disconnected, or the device reboots.

If any of these events occurs, AridSpy starts to gather various victim data and uploads it to the exfiltration C&C server. It can collect the device location; contact lists; call logs; text messages; thumbnails of photos; thumbnails of recorded videos; recorded phone calls; recorded surrounding audio; malware-taken photos; WhatsApp databases that contain exchanged messages and user contacts; bookmarks and search history from the default browser and Chrome, Samsung Browser, and Firefox apps if installed; files from external storage; Facebook Messenger and WhatsApp communication; and all received notifications, among others.

For more technical information about AridSpy, read the blog post “Arid Viper poisons Android apps with AridSpy.” Make sure to follow ESET Research on Twitter (today known as X) for the latest news from ESET Research.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

Valuable targets attract advanced threat actors. How to defend against quiet and persistent attacks

C-level executives, diplomats, and high-ranking IT managers usually have access to sensitive information, huge amounts of data, finances, or a combination of all these things. And adversaries know it.

Anticipating all the precious data and access rights, cybercriminals and state-sponsored advanced persistent threat groups (APTs) are willing to invest a lot of time and money to orchestrate attacks that could compromise VIP devices and accounts. In this case, backdoors are particularly dangerous, because typically they have the capability to send files to the host computer, execute files and commands there, and exfiltrate (send) files and documents back to the attacker.

One of the latest examples of such an attack features several sophisticated and previously unknown backdoors called LunarWeb and LunarMail, which were recently described by ESET researchers and presented at the ESET World 2024 conference. Using advanced obfuscation techniques, they were deployed to spy on an undisclosed European ministry of foreign affairs. The attack is attributed with medium confidence to the Russia-aligned APT group Turla.

To protect against such attacks, organizations need to be proactive. This means not only training staff and deploying a reliable cybersecurity solution, but also having comprehensive cyberthreat intelligence helping them stay ahead of adversaries.  

 

 

 

 

VIPs are also threatened at home

According to a 2023 study conducted by BlackCloak and Ponemon Institute, senior-level corporate executives are increasingly being targeted by sophisticated cyberattacks. These include email compromise, ransomware, malware infection, doxing, extortion, online impersonation and even physical attacks, such as swatting.

Around 42% of surveyed organizations stated that their senior executive or an executive’s family member was attacked over the past two years. Attackers often went for sensitive company data, including financial information and intellectual property.

Cybercriminals did not hesitate to strike when their targets were the most vulnerable – at home with their loved ones. In one-third of reported cases, hackers reached executives through insecure home-office networks used during remote work.

Business email compromise (BEC) is one of the most used tactics against VIPs. It usually comprises a sophisticated scam targeting individuals performing transfers of funds and seeks to compromise legitimate business email accounts through social engineering and/or computer intrusion techniques.

According to the FBI’s Internet Crime Complaint Center (IC3) annual reports, BEC is among the costliest types of crime. In 2023, IC3 received 21,489 BEC complaints with adjusted losses of over $2.9 billion. Only investment crimes (such as pyramid schemes, real estate investment scams, or cryptocurrency investment scams) accumulated more losses than BEC in that year, with $4.7 billion reported stolen.

The Lunar toolset

ESET research on the Lunar toolset demonstrates how such carefully crafted spying can look.

The initial attack vector is not known, but recovered installation-related components and attacker activity suggest possible spearphishing with a malicious Word document and abuse of both a misconfigured network and the application monitoring software Zabbix.

Once access is gained, the backdoor installation process follows. It consists of dropping both a loader and a blob containing either LunarWeb or LunarMail, as well as setting up persistence.

From that point forward, data exfiltration can start. For example, the LunarWeb backdoor gathers data such as the OS serial name, environment variables, network adapters, a list of running processes, a list of services, or a list of installed security products, and sends them to a C&C server.

LunarWeb communicates with a C&C server using HTTP(S) underneath which is a custom binary protocol with encrypted content. ESET researchers only found LunarWeb deployed on servers, not user workstations.

LunarMail is similar, but instead of HTTP(S) it uses email messages for communication with its C&C server. This backdoor is designed to be deployed on user workstations, not servers – because it is persistent and intended to run as an Outlook add-in.

Staying under the radar

The APT group also has several tricks up its sleeve to conceal the malicious activities of deployed backdoors.  

  • The loader uses RC4, a symmetric key cipher, to decrypt path to the blob and reads encrypted payloads from it.
  • It also creates a decryption key derived from the DNS domain name, which it verifies. Using DNS domain name decryption means that the loader correctly executes only in the targeted organization, which may hinder analysis if the domain name is not known.
  • LunarWeb limits initial contact attempts with the C&C server, assessing the backdoor’s lifespan, and checking C&C server accessibility. If any of the safety conditions fail, LunarWeb self-removes, deleting its files, including the loader and the blob.
  • To hide its C&C communications, LunarWeb impersonates legitimate-looking traffic, spoofing HTTP headers with genuine domains and commonly used attributes. Notable examples of impersonation include Windows services (Teredo, Windows Update) and updates of ESET products.
  • Both LunarWeb and LunarMail can receive commands hidden in images.
  • To exfiltrate stolen data, LunarMail embeds them in a PNG image or PDF document. For PNG files, a template matching the compromised institution’s logo is used.
  • LunarMail deletes email messages used for C&C communications.
  • Both LunarWeb and LunarMail can uninstall themselves.

How to protect VIPs

Being high-priority targets, VIPs should have an adequate high-priority protection in both office and home environments.

  • Educate them and the rest of the staff – Technology alone cannot fully safeguard an organization, and the human element will always play a role. Only 9% of cybersecurity professionals participating on the Ponemon survey were highly confident that their CEO or executives would know how to protect their personal computer from viruses, and only 22% trusted them when it comes to securing personal emails.
  • Secure their remote working – Because many VIPs are targeted in their home environment, it is necessary to secure their corporate devices, personal devices used for work, and home networks. This includes a use of strong passwords or passphrases, 2FA, regular updating, patching, and backing up data.
  • Adopt a zero-trust approach – Take measures to efficiently screen every single point of access, both employee and device – internal and external. Naturally, CEOs and high-ranking managers need a lot of access to perform their duties, but it does not have to be unlimited. Evaluate how much privilege they really need to protect your institution’s data in cases when VIPs’ accounts are compromised.
  • Deploy reliable cybersecurity – As the Lunar toolset shows, current cyberthreats operate above the security threshold of traditional firewalls, and more sophisticated security measures need to be adopted. Protection of C-level officials should include multilayered security and proactive defense benefiting from cyber threat intelligence.

ESET Threat intelligence monitors APT groups such as Turla, observing their tactics, techniques, and procedures (TTPs) in order to help organizations prepare for APTs’ new tricks and to also understand their motives. Thanks to comprehensive ESET reports and curated feeds, organizations can anticipate threats and make faster, better decisions.

Facing the big guns

VIPs are prized trophies for cybercriminals and APTs, be they for financial gain or political reasons. Therefore, they often bring their biggest guns to compromise targets’ accounts and devices.

This means that organizations need to build an awareness culture among their employees and protect their devices with the latest technology. ESET solutions and services can help with that.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.