Iranian hackers targeting telcos and ISPs using upgraded malware
New report shines a light on Lyceum cyberespionage group
The group is known as Lyceum, but also goes by Hexane or Spirlin, has operated since 2017 and been linked to malicious campaigns targeting Middle Eastern oil and gas companies.
Between July and October this year, Lyceum carried out attacks on Internet providers and telecommunications organizations in Israel, Morocco, Tunisia, and Saudi Arabia, according to researchers from Accenture’s Cyber Threat Intelligence (ACTI) group and Prevailion’s Adversarial Counterintelligence Team (PACT). In addition, the APT is responsible for a malicious campaign against an unnamed African country’s foreign affairs department.
“Telecommunications companies and ISPs are high-level targets for cyber espionage threat actors because once compromised, they provide access to various organizations and subscribers in addition to internal systems that can be used to leverage malicious behavior even further,” said security researchers.
Shark backdoor is a 32-bit executable file written in C# and .NET, and it executes commands and exports data from infected systems. Milan is a 32-bit remote access trojan (RAT) that can retrieve data from the compromised system and send it to servers derived from domain-building algorithms (DGAs).
2021 state of email security report: Ransomware on the rise
Securing the enterprise in the COVID worldFree download
Both backdoors communicate via DNS and HTTPS with the command and control (C2) servers. Shark also uses a DNS tunnel.
Researchers said they also identified beaconing from a reconfigured or a new Lyceum backdoor in late October 2021.
“The observed beacons were seen egressing from a telecommunications company in Tunisia as well as an MFA in Africa,” they said.
Researchers added that the URL syntax of the newly reconfigured backdoor is like those generated in the newer version of Milan. However, because the URL syntax is configurable, the Lyceum operators likely reconfigured the Milan URL syntax to circumvent intrusion detection systems (IDS) and intrusion prevention systems (IPS) encoded to detect the previous Milan beacon syntax.
Researchers said Lyceum is updating its backdoors in light of recent public research into its activities to stay ahead of defensive systems.
“The group has continued its targeting of companies of national strategic importance. Lyceum will likely continue to use the Shark and Milan backdoors, albeit with some modifications, as the group has likely been able to maintain footholds in victims’ networks despite public disclosure of IOCs associated with its operations,” they added.
Modern governance: The how-to guide
Equipping organisations with the right tools for business resilienceFree Download
Cloud operational excellence
Everything you need to know about optimising your cloud operationsWatch now
A buyer’s guide to board management software
How the right software can improve your board’s performance
The real world business value of Oracle autonomous data warehouse
Lead with a 417% five-year ROIDownload now