BTC $58270.6324
ETH $3301.4664
BNB $400.6794
SOL $110.0515
XRP $0.5824
ADA $0.6271
AVAX $39.6830
DOGE $0.0970
TRX $0.1429
wstETH $3808.1443
DOT $8.3586
LINK $19.1334
WETH $3305.4834
MATIC $1.0428
UNI $11.0186
WBTC $57881.0446
IMX $3.3465
ICP $13.0316
BCH $301.2119
LTC $74.8427
CAKE $3.2026
ETC $28.3635
FIL $7.9610
LEO $4.4139
RNDR $7.4060
KAS $0.1700
HBAR $0.1136
DAI $1.0002
ATOM $11.3163
INJ $41.0291
VET $0.0502
TON $2.1419
OKB $51.8401
STX $3.2222
LDO $3.5190
FDUSD $0.9951
XMR $138.3902
XLM $0.1221
ARB $1.8935
NEAR $3.9358
TIA $16.9317
GRT $0.2829
WEMIX $2.2582
ENS $22.5313
MKR $2167.8555
APEX $2.4646
THETA $1.9298
BTC $58270.6324
ETH $3301.4664
BNB $400.6794
SOL $110.0515
XRP $0.5824
ADA $0.6271
AVAX $39.6830
DOGE $0.0970
TRX $0.1429
wstETH $3808.1443
DOT $8.3586
LINK $19.1334
WETH $3305.4834
MATIC $1.0428
UNI $11.0186
WBTC $57881.0446
IMX $3.3465
ICP $13.0316
BCH $301.2119
LTC $74.8427
CAKE $3.2026
ETC $28.3635
FIL $7.9610
LEO $4.4139
RNDR $7.4060
KAS $0.1700
HBAR $0.1136
DAI $1.0002
ATOM $11.3163
INJ $41.0291
VET $0.0502
TON $2.1419
OKB $51.8401
STX $3.2222
LDO $3.5190
FDUSD $0.9951
XMR $138.3902
XLM $0.1221
ARB $1.8935
NEAR $3.9358
TIA $16.9317
GRT $0.2829
WEMIX $2.2582
ENS $22.5313
MKR $2167.8555
APEX $2.4646
THETA $1.9298
  • Catalog
  • Blog
  • Tor Relay
  • Jabber
  • One-Time notes
  • Temp Email
  • What is TOR?
  • We are in tor
  • Updated PowerLess backdoor is actively storming Israeli organizations

    Iranian cybercriminals Educated Manticore are improving their tools and methods with each new attack.

    Researchers at Check Point have linked an Iranian state-owned hacking group to a new wave of phishing attacks targeting Israel in a recent report. The purpose of the malicious campaign was to deploy an updated version of the Windows backdoor called PowerLess.

    Check Point tracks these intruders under the alias of the mythical creature "Educated Manticore". The group, according to the researchers, shows “strong overlaps” in methods and tools with the APT35 hacker group (aka Charming Kitten, Cobalt Illusion, ITG18, Mint Sandstorm, TA453 and Yellow Garuda).

    “Like many other actors, Educated Manticore has adopted the latest trends and started using ISO images and possibly other archive files to start infection chains,” the Check Point report says.

    The chain of attacks documented by the researchers begins with an ".iso" disk image file with an Iraq-themed decoy in its name. After opening the image and running the executable inside, a malicious loader is dropped into memory, which eventually launches the PowerLess implant.

    The ISO file acts as a conduit for displaying a decoy document written in Arabic, English, and Hebrew, and is intended to display academic content about Iraq from a legitimate non-profit organization called the Arab Science and Technology Foundation (ASTF), indicating that the research the community may also have been the target of this malicious campaign.

    The PowerLess backdoor, previously documented by Israeli Cybereason in February 2022, has the ability to steal data from web browsers and apps, take screenshots, record audio, and log keystrokes.

    “While the updated PowerLess payload is similar in many ways to the old version, its loading mechanisms have been greatly improved through the use of rarely seen in the wild (ITW) techniques, such as the use of .NET binaries created in mixed mode with assembly code,” says in a Check Point message.

    “PowerLess communication with the C2 server is Base64 encoded and encrypted after receiving the key from the server. To mislead researchers, attackers add three random letters to the beginning of each blob,” the experts added.

    The researchers also said they found two other archive files already used in another attack chain that overlaps with the above pattern. Further analysis showed that the chains of infection arising from these archived files ended with the execution of a PowerShell script designed to download two more malicious files from a remote server and then run them.

    Check Point experts noted that the Educated Manticore group continues to evolve, improving their toolkits and attack methods. In particular, attackers have begun to use the now popular trends to use ISO images to avoid detection.

    Author DeepWeb
    Grixba and VSS Copying Tool - the latest weapon in cyberspace
    Lazarus Group expands DreamJob campaign to Linux users

    Comments 0

    Add comment