New Russian Threat Actor Using Graphiron Malware To Steal Data from Ukraine: Symantec

Symantec has spotted a new Russia-linked threat actor Dubbed Graphiron deploying a new information-stealing malware against targeting Ukraine. The malware is attributed to a group known as Nodaria, which is tracked by the Computer Emergency Response Team of Ukraine (CERT-UA) as UAC-0056. 

The Symantec paper is worth your time to read, but here’s the TL:DR:

  • The malware is written in Go and is designed to harvest a wide range of information from the infected computer, including system information, credentials, screenshots, and files.
  • Graphiron is a two-stage threat consisting of a downloader (Downloader.Graphiron) and a payload (Infostealer.Graphiron).
  • The downloader contains hardcoded command-and-control (C&C) server addresses. When executed, it will check against a blacklist of malware analysis tools by checking for running processes.
  • The group’s usual infection vector is spear-phishing emails, which are then used to deliver a range of payloads to targets.

David Maynor, Senior Director of Threat Intelligence at Cybrary:

   “Ukraine has the dubious honor of serving as a canary in a coal mine for tools, techniques, and procedures of Russian attacks. That’s why I pay close attention to CERT-UA for new attacks.”

You should pay attention to this threat actor as well because it is only a matter of time before this group starts going after targets in the west.

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading