{"id":8582,"date":"2017-10-22T21:37:59","date_gmt":"2017-10-23T02:37:59","guid":{"rendered":"https:\/\/www.irandemocratic.org\/public_html\/news\/?p=8582"},"modified":"2017-10-22T21:37:59","modified_gmt":"2017-10-23T02:37:59","slug":"dragonfly-western-energy-sector-targeted-by-sophisticated-attack-group","status":"publish","type":"post","link":"https:\/\/www.irandemocratic.org\/public_html\/news\/8582\/","title":{"rendered":"Dragonfly: Western energy sector targeted by sophisticated attack group"},"content":{"rendered":"<p><span style=\"color: #808000;\"><strong>Resurgence in energy sector attacks, with the potential for sabotage, linked to re-emergence of Dragonfly cyber espionage group<\/strong><\/span><\/p>\n<p><a class=\"user-name ng-binding\" href=\"https:\/\/www.symantec.com\/connect\/user\/symantec-security-response\" target=\"_self\">By Symantec Security Response<\/a> Dec.06, 2016:<\/p>\n<p class=\"ng-scope\">The energy sector in Europe and North America is being targeted by a new wave of cyber attacks that could provide attackers with the means to severely disrupt affected operations. The group behind these attacks is known as Dragonfly. The group has been in operation since at least 2011 but has re-emerged over the past two years from a quiet period <a href=\"https:\/\/www.symantec.com\/connect\/blogs\/dragonfly-western-energy-companies-under-sabotage-threat-energetic-bear\" target=\"_self\">following exposure by Symantec<\/a> and a number of other researchers in 2014. This \u201cDragonfly 2.0\u201d campaign, which appears to have begun in late 2015, shares tactics and tools used in earlier campaigns by the group.<\/p>\n<p class=\"ng-scope\">The energy sector has become an area of increased interest to cyber attackers over the past two years. Most notably,\u00a0<a href=\"http:\/\/www.reuters.com\/article\/us-ukraine-cyber-attack-energy-idUSKBN1521BA\" target=\"_self\">disruptions to Ukraine\u2019s power system<\/a> in 2015 and 2016 were attributed to a cyber attack and led to power outages affecting hundreds of thousands of people. In recent months, there have also been media reports of <a href=\"http:\/\/www.independent.ie\/irish-news\/statesponsored-hackers-targeted-eirgrid-electricity-network-in-devious-attack-36005921.html\" target=\"_self\">attempted attacks on the electricity grids<\/a> in some European countries, as well as reports of <a href=\"https:\/\/www.nytimes.com\/2017\/07\/06\/technology\/nuclear-plant-hack-report.html\" target=\"_self\">companies that manage nuclear facilities in the U.S. being compromised<\/a> by hackers.<\/p>\n<p class=\"ng-scope\">The Dragonfly group appears to be interested in both learning how energy facilities operate and also gaining access to operational systems themselves, to the extent that the group now potentially has the ability to sabotage or gain control of these systems should it decide to do so. Symantec customers are protected against the activities of the Dragonfly group.<\/p>\n<h3 class=\"ng-scope\">Dragonfly 2.0<\/h3>\n<p class=\"ng-scope\">Symantec has evidence indicating that the Dragonfly 2.0 campaign has been underway since at least December 2015 and has identified a distinct increase in activity in 2017.<\/p>\n<p class=\"ng-scope\">Symantec has strong indications of attacker activity in organizations in the U.S., Turkey, and Switzerland, with traces of activity in organizations outside of these countries. The U.S. and Turkey were also among the countries targeted by Dragonfly in its earlier campaign, though the focus on organizations in Turkey does appear to have increased dramatically in this more recent campaign.<\/p>\n<p class=\"ng-scope\">As it did in its prior campaign between 2011 and 2014, Dragonfly 2.0 uses a variety of infection vectors in an effort to gain access to a victim\u2019s network, including malicious emails, watering hole attacks, and Trojanized software.<\/p>\n<p class=\"ng-scope\">The earliest activity identified by Symantec in this renewed campaign was a malicious email campaign that sent emails disguised as an invitation to a New Year\u2019s Eve party to targets in the energy sector in December 2015.<\/p>\n<p class=\"ng-scope\">The group conducted further targeted malicious email campaigns during 2016 and into 2017. The emails contained very specific content related to the energy sector, as well as some related to general business concerns. Once opened, the attached malicious document would attempt to leak victims\u2019 network credentials to a server outside of the targeted organization.<\/p>\n<p class=\"ng-scope\">In July, Cisco blogged about <a href=\"http:\/\/blog.talosintelligence.com\/2017\/07\/template-injection.html\" target=\"_self\">email-based attacks targeting the energy sector using a toolkit called Phishery.<\/a> Some of the emails sent in 2017 that were observed by Symantec were also using the Phishery toolkit (<a href=\"https:\/\/www.symantec.com\/security_response\/writeup.jsp?docid=2017-071414-3257-99\" target=\"_self\">Trojan.Phisherly<\/a>), to steal victims\u2019 credentials via a template injection attack. This toolkit became generally available on GitHub in late 2016,<\/p>\n<p class=\"ng-scope\">As well as sending malicious emails, the attackers also used watering hole attacks to harvest network credentials, by compromising websites that were likely to be visited by those involved in the energy sector.<\/p>\n<p class=\"ng-scope\">The stolen credentials were then used in follow-up attacks against the target organizations. In one instance, after a victim visited one of the compromised servers, <a href=\"https:\/\/www.symantec.com\/security_response\/writeup.jsp?docid=2017-071207-0015-99\" target=\"_self\">Backdoor.Goodor<\/a> was installed on their machine via PowerShell 11 days later. Backdoor.Goodor provides the attackers with remote access to the victim\u2019s machine.<\/p>\n<p class=\"ng-scope\">In\u00a0<a href=\"tel:2014\" target=\"_self\">2014<\/a>,\u00a0Symantec observed the Dragonfly group compromise legitimate software in order to deliver malware to victims, a practice also employed in the earlier 2011 campaigns. In the 2016 and 2017 campaigns the group is using the evasion framework Shellter in order to develop Trojanized applications. In particular,\u00a0<a href=\"https:\/\/www.symantec.com\/security_response\/writeup.jsp?docid=2017-071206-3422-99\" target=\"_self\">Backdoor.Dorshel<\/a> was delivered as a trojanized version of standard Windows applications.<\/p>\n<p class=\"ng-scope\">Symantec also has evidence to suggest that files masquerading as Flash updates may be used to install malicious backdoors onto target networks\u2014perhaps by using social engineering to convince a victim they needed to download an update for their Flash player. Shortly after visiting specific URLs, a file named \u201cinstall_flash_player.exe\u201d was seen on victim computers, followed shortly by the <a href=\"https:\/\/www.symantec.com\/security_response\/writeup.jsp?docid=2017-073103-3836-99\" target=\"_self\">Trojan.Karagany.B<\/a> backdoor.<\/p>\n<p class=\"ng-scope\">Typically, the attackers will install one or two backdoors onto victim computers to give them remote access and allow them to install additional tools if necessary. Goodor, Karagany.B, and Dorshel are examples of backdoors used, along with <a href=\"https:\/\/www.symantec.com\/security_response\/writeup.jsp?docid=2017-073113-4148-99\" target=\"_self\">Trojan.Heriplor<\/a>.<\/p>\n<h3 class=\"ng-scope\">Strong links with earlier campaigns<\/h3>\n<p class=\"ng-scope\">There are a number of indicators linking recent activity with earlier Dragonfly campaigns. In particular, the Heriplor and Karagany Trojans used in Dragonfly 2.0 were both also used in the earlier Dragonfly campaigns between 2011 and 2014.<\/p>\n<p class=\"ng-scope\">Trojan.Heriplor is a backdoor that appears to be exclusively used by Dragonfly, and is one of the strongest indications that the group that targeted the western energy sector between 2011 and 2014 is the same group that is behind the more recent attacks. This custom malware is not available on the black market, and has not been observed being used by any other known attack groups. It has only ever been seen being used in attacks against targets in the energy sector.<\/p>\n<p class=\"ng-scope\">Trojan.Karagany.B is an evolution of <a href=\"https:\/\/www.symantec.com\/security_response\/writeup.jsp?docid=2010-121515-0725-99\" target=\"_self\">Trojan.Karagany<\/a>, which was previously used by Dragonfly, and there are similarities in the commands, encryption, and code routines used by the two Trojans. Trojan.Karagny.B doesn\u2019t appear to be widely available, and has been consistently observed being used in attacks against the energy sector. However, the earlier Trojan.Karagany was leaked on underground markets, so its use by Dragonfly is not necessarily exclusive.<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<div class=\"mh-excerpt\"><p>Resurgence in energy sector attacks, with the potential for sabotage, linked to re-emergence of Dragonfly cyber espionage group By Symantec Security Response Dec.06, 2016: The <a class=\"mh-excerpt-more\" href=\"https:\/\/www.irandemocratic.org\/public_html\/news\/8582\/\" title=\"Dragonfly: Western energy sector targeted by sophisticated attack group\">[&#8230;]<\/a><\/p>\n<\/div>","protected":false},"author":1,"featured_media":8583,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5,54],"tags":[147,183],"class_list":["post-8582","post","type-post","status-publish","format-standard","has-post-thumbnail","category-news","category-world","tag-cyber-attacks","tag-dragonfly-2-0"],"_links":{"self":[{"href":"https:\/\/www.irandemocratic.org\/public_html\/news\/wp-json\/wp\/v2\/posts\/8582","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.irandemocratic.org\/public_html\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.irandemocratic.org\/public_html\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.irandemocratic.org\/public_html\/news\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.irandemocratic.org\/public_html\/news\/wp-json\/wp\/v2\/comments?post=8582"}],"version-history":[{"count":1,"href":"https:\/\/www.irandemocratic.org\/public_html\/news\/wp-json\/wp\/v2\/posts\/8582\/revisions"}],"predecessor-version":[{"id":8584,"href":"https:\/\/www.irandemocratic.org\/public_html\/news\/wp-json\/wp\/v2\/posts\/8582\/revisions\/8584"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.irandemocratic.org\/public_html\/news\/wp-json\/wp\/v2\/media\/8583"}],"wp:attachment":[{"href":"https:\/\/www.irandemocratic.org\/public_html\/news\/wp-json\/wp\/v2\/media?parent=8582"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.irandemocratic.org\/public_html\/news\/wp-json\/wp\/v2\/categories?post=8582"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.irandemocratic.org\/public_html\/news\/wp-json\/wp\/v2\/tags?post=8582"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}