Skip to content

Turla Crutch attacks Ministry of Foreign Affairs in an EU country, misuses Dropbox in cyber-espionage, ESET discovers

BRATISLAVA, MONTREAL – ESET researchers discovered a previously undocumented backdoor and document stealer used for cyber-espionage. ESET has been able to attribute the program, dubbed Crutch by its developers, to the infamous Turla APT group. It was in use from 2015 until at least early 2020. ESET has seen Crutch on the network of a Ministry of Foreign Affairs in a country of the European Union, suggesting that this malware family is only used against very specific targets. These tools were designed to exfiltrate sensitive documents and other files to Dropbox accounts controlled by Turla operators.

“The main malicious activity is exfiltration of documents and other sensitive files. The sophistication of the attacks and technical details of the discovery further strengthen the perception that the Turla group has considerable resources to operate such a large and diverse arsenal,” says Matthieu Faou, an ESET researcher who investigates the Turla APT group. “Furthermore, Crutch is able to bypass some security layers by abusing legitimate infrastructure – here, Dropbox – in order to blend into normal network traffic while exfiltrating stolen documents and receiving commands from its operators.”

In order to have a rough idea of the working hours of the operators, ESET exported those hours at which they uploaded ZIP files to the Dropbox accounts they operate. For this, researchers collected 506 different timestamps ranging from October 2018 to July 2019, as this should show when the operators were working and not when the victims’ machines were active. The operators are likely to operate in the UTC+3 time zone.

Working hours of Crutch operators based on the uploads to Dropbox zone.

ESET Research was able to identify strong links between a Crutch dropper from 2016 and Gazer. The latter, also known as WhiteBear, is a second-stage backdoor used by Turla in 2016-2017.

Turla has been an active cyber-espionage group for more than 10 years. It has compromised many governments, especially diplomatic entities, all around the world, operating a large malware arsenal that ESET has documentedoverthelast few years.

For more technical details on how Turla Crutch attacks and collects sensitive information, read the blog post Turla Crutch: Keeping the ‘back door’ open on WeLiveSecurity. Make sure to follow ESET Research on Twitter for the latest news from ESET Research.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

Emotet botnet hits quiet patch before Black Friday – the calm before the storm?

Most wanted botnets – Emotet, Trickbot and Qbot. What are this terrible trio up to, and how do you stay safe?

Emotet and holidays like Black Friday are good pals. That’s because Emotet’s seasonal specialty is filling your inbox with holiday “deals” that aim to compromise your machine, steal valuable data and account credentials and open it up to subsequent attacks from other malicious actors.

This year, we saw Emotet flooding inboxes with malicious emails in monthly campaigns running from August to October – campaigns that reached into the low tens of thousands of detections in ESET telemetry:

Figure 1: Monthly Emotet campaigns detected in ESET telemetry

Right around Halloween, and leading up to Black Friday, Emotet went quiet. It’s suspected by ESET researchers that Emotet’s operators are taking a little downtime before roaring the spam engine back to life for 2020’s Black Friday and the following pre-Christmas period.

While Emotet’s writers have, in the past, placed a rude comment or two about ESET in their malware binaries, ESET protection has not been outdone. Dealing with Emotet’s attacks can be as simple as being cautious, by not clicking on links in emails, avoiding the “Enable Content” button in documents that arrive as attachments of suspicious, yet legitimate-looking, emails and using security software like ESET Internet Security that protects you when you accidentally click.

The other specials Emotet likes to offer are its friends, Qbot and Trickbot. Emotet is known to serve up both Trickbot and Qbot malware to its victims. Both these malevolent families are more than happy to help themselves to victims’ sensitive information, credentials and other valuable data, and often finish their nasty business by installing ransomware such as Ryuk or Conti.

Let’s see how busy Trickbot and Qbot – Emotet’s friends – have been in the past few months:

While Trickbot’s detection numbers remain in the hundreds – likely due to the recent disruption efforts – Qbot has been quite busy, with detection numbers for the malware reaching the low thousands from August to October. In fact, following Halloween, Emotet detection numbers subsided, while Qbot detection numbers kept their former levels. That would suggest that Qbot is also using other distribution channels to get into potential victims’ inboxes.

How to stay safe from malicious bots Emotet and its buddies don’t just flood your inbox with dangerous malspam, but they also go after other devices in your network. Trickbot, for example, has been using hacked routers for a long time for command and control. Therefore, it is important to review the security settings of all your home devices.

  1. You can find some practical tips on how to configure your home router securely here.
  2.  If you use child trackers and watches, smart doorbells, smart security cameras or smart home hubs, you can read up on the privacy and security considerations surrounding their use here.
  3. If you want to test your mettle against phishing emails or malspam, you can find a few options here.
  4. Finally, don’t forget to protect all your devices with security solutions like ESET Mobile Security for Android, ESET Internet Security for Windows or ESET Cyber Security for macOS. These offer multilayered protection that can detect and block Emotet’s efforts, whether fingerprinting victims’ machines, spreading laterally in a network or downloading payloads such as Trickbot and Qbot.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

Deal or no deal – what to watch out for this Black Friday and Cyber Monday

In a year like no other, it is likely that 2020’s Black Friday and Cyber Monday deals will be more frenzied than ever. With many industries, particularly retail, crippled by pandemic lockdowns and distancing restrictions, the upcoming weekend presents an opportunity to recoup some losses. The pandemic has accelerated the already growing increase in online shopping, with e-commerce sales expected to reach $4.2 trillion by the end of 2020 (Statista).

Although many physical stores will be closed or keeping the usual crowds of shoppers to a minimum – the online space will be just as jam-packed as ever with offers and sales. This makes it the perfect breeding ground for cyber-attacks and scams, from phishing emails to suspicious social media ads. For many, mobile devices have become the primary method for online shopping, so it is vital that consumers are protected across all technologies.

Here are ESET’s top five tips for what to watch out for and to stay safe this Black Friday and Cyber Monday:

  1. Stick to what you know – If you see an offer in a promotional email or an online ad that seems too good to be true, then it probably is! Finding an item immediately from an unrecognized vendor with the best price can be a red flag. If you’re unsure about a website, then don’t click on the link – head separately to the website of the organization the sender is claiming to represent to find out if the offer is legitimate.
  2.  Look-alikes and fake websites – Look for the padlock and, on a desktop device, the https:// at the beginning of the website address. These indicate that communication between you and the site is encrypted and any data you send can’t be seen by anyone intercepting the traffic.
  3.  Dodgy incoming information – Suspicious texts with malicious links, elaborate phishing emails and fraudulent banking notifications are all techniques used by online scammers. In addition, be wary of threatening messages that try to get you to hand over sensitive information, such as bank details.
  4.  Passwords and PINs – It can feel a bit like beating a dead horse, but strong, unique passwords are the foundation of a positive online shopping experience. Avoid creating accounts with retailers unless absolutely necessary, and make sure to use a secure payment method, like Apple Pay, Android Pay or PayPal, to avoid linking your primary bank account. You can also take this one step further and enable two-factor authentication where possible, adding an extra layer of security to your transactions.
  5.  Software safety first – Keep your devices and operating systems uptodate, and have security software installed and fully operational on all devices. Software updates fix known vulnerabilities, so be sure to install them when prompted. Security software products, such as ESET Internet Security or ESET Mobile Security, include extra features, like Banking & Payment Protection, to keep you safe while shopping online, which can take the stress out of your shopping spree.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

Greycortex is a top-rated company among the 50 most successful tech companies in the Deloitte Technology fast 50 CE

Brno, November 19, 2020

GREYCORTEX has won second place in the Rising Stars category in the prestigious ratings organized by Deloitte, where many Czech tech companies strove to be nominated as the fastest-growing tech company in the Deloitte Technology Fast 50 CE. The Tech Stars, Rising Stars, and Impact Stars categories present both the maturest and newest fast-growing companies in the Central European region as well as those companies that have had a revolutionary social or environmental impact on the market.

Petr Chaloupka, CEO at GREYCORTEX, said: “I am very pleased to have achieved international success in the 21st year of the Deloitte Technology Fast 50 CE competition and to have won second place in the Rising Stars category. In this category, seven out of 10 places were occupied by Czech companies, showing that the Czech Republic is still a cradle of technological innovation and that we have a good standing in this international competition. I wish to congratulate all the other companies and wish them success in further building their internationally competitive status”.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About GREYCORTEX
GREYCORTEX uses advanced artificial intelligence, machine learning, and data mining methods to help organizations make their IT operations secure and reliable.

MENDEL, GREYCORTEX’s network traffic analysis solution, helps corporations, governments, and the critical infrastructure sector protect their futures by detecting cyber threats to sensitive data, networks, trade secrets, and reputations, which other network security products miss.

MENDEL is based on 10 years of extensive academic research and is designed using the same technology which was successful in four US-based NIST Challenges.

About Deloitte Technology Fast 50 CE
Deloitte Technology Fast 50 CE is a program that identifies and rewards the 50 fastest-growing tech companies in the Central Europe region based on revenue growth over a four-year period.

IDC MarketScape names ESET as a Major Player for second year in a row

BRATISLAVA – For the second year in a row, ESET, a global leader in cybersecurity, has been recognized as a Major Player in mobile threat management in the IDC MarketScape: Worldwide Mobile Threat Management Software 2020 Vendor Assessment (Doc #US46092220, September 2020).*

The assessment evaluates the enterprise market for mobile threat management software products, helping organizations to identify vendors with strong offerings and well-integrated business strategies.

According to the report, “ESET is strong in the areas of threat research, especially around Android malware identification and behavior detection.” As IDC further notes, “Organizations looking to consolidate security products and operations around a unified endpoint security model should also consider ESET for its broader portfolio of endpoint and security management tools on top of MTM.”

In 2020, mobile security has become a greater priority than ever before, as huge numbers of organizations have deployed large-scale remote working, while threat actors have increased their attempts exponentially. As they are separated from the office, more employees are using their mobile devices as a regular part of everyday work, and it is vital that these devices are protected. Businesses should ensure that all endpoints are secured with software such as ESET Endpoint Security for Android, which protects against a wide range of threats with its multilayered defense.

This is more than relevant today, as for many, a significant challenge in contending with mobile threats is managing all of the devices within an organization. As each employee may have multiple mobile devices, overseeing the software on each and every device can be a time-consuming task. However, offerings such as ESET Security Management Center** – which is automatically included in all ESET endpoint protection licenses – can streamline the process, providing a single pane of glass from which to manage all machines on a network.

Zuzana Legáthová, Analyst Relations Manager at ESET, commented: “As one of the IT industry’s most important vendor assessment tools, IDC MarketScape’s continued recognition of ESET as a Major Player is a great testament to the strength of ESET’s mobile security offerings. ESET’s improved performance compared to last year’s assessment is a confirmation of our ever-growing capabilities in the increasingly important space of mobile threat management software. Businesses across the globe can depend on ESET’s expertise to keep their devices safe and secure, and being named as a Major Player in Mobile Threat Management by IDC Marketscape is an important validation of this.”

* The first recognition was given in IDC MarketScape: Worldwide Mobile Threat Management Software 2018–2019 Vendor Assessment, Doc #US44521018, December 2018.

** will be renamed to ESET PROTECT

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

×

Hello!

Click one of our contacts below to chat on WhatsApp

×