June 29, 2021 Lieying Lab Comments 0 Comment 1,536 views
Background
Hades is a mysterious APT group. It was first discovered because of its attack on the PyeongChang Winter Olympics in South Korea on December 22, 2017, and Kaspersky later named the group behind that incident Hades. However, the group's attribution has never been conclusively determined. On one hand, the destructive malware (Olympic Destroyer) used in the attack shared similarities with malware used by the North Korean Lazarus group. On the other hand, some US media outlets believed Russian intelligence agencies were behind the incident and had deliberately imitated other groups' techniques to plant false flags and mislead security personnel.
Incident Analysis
Recently, DBAPPSecurity Threat Intelligence Center's Lieying Lab captured a malicious sample. Through tracing and analyzing the sample, we found that it was suspected to be another attack by the Hades group against Ukraine.
Detailed sample information is shown below:
| Sample Name | Про внесення змін.doc |
|---|---|
| Sample Type | Microsoft Word document (.doc) |
| MD5 | 0c6f6079cf6959fb55141c49b62f7308 |
The decoy document appears blank when opened and displays its content only after macro code is enabled:

The decoy content is related to the Ukrainian military:

The decoy document's content actually came from a foreign website (uteka.ua), which specializes in providing practical information about unresolved and disputed issues to managers, accountants, and other professionals. The original content is shown below:

The macro code was obfuscated. After deobfuscation, it first changes the document properties to display the decoy content and then creates desktop.ini and C:\ProgramData\pagefile.dll:

pagefile.dll is a .NET backdoor that the macro code loads and executes through RegSvcs.exe. It then communicates with the C2 server (mopub[.]space).

It can also transmit data through the Referer header.

The DLL was obfuscated. Some of its contents can be seen after deobfuscation.

Correlation Analysis
Using the DBAPPSecurity Threat Intelligence Center platform to correlate the current sample, we found a strong association between the sample and the Hades group. The attack target, macro-code similarity, and other aspects of this sample all matched “OPERATION TRICKYMOUSE—Attacking Ukraine with a COVID-19 Theme,” which Lieying Lab had previously published.
Both incidents targeted Ukraine:

The macro code was also largely identical in data initialization, decryption algorithms, execution functions, and other areas:

Both samples used the same method at the beginning of the code to initialize, through a function, the file data that would be saved locally:

They then initialized variables in the same way, and the decryption functions were also identical:

Finally, the functional logic of the code in the main function was also identical:

Previous sample:

Defense Recommendations
The DBAPPSecurity APT Attack Early Warning Platform can identify known and unknown threats. It can monitor, capture, and analyze the maliciousness of files or programs in real time and strongly monitor malicious samples such as Trojans associated with every stage, including email delivery, exploitation, installation, implantation, callback, and control.
The platform also performs deep analysis of network traffic using bidirectional traffic analysis, intelligent machine learning, efficient dynamic sandbox analysis, a rich feature library, comprehensive detection strategies, massive threat intelligence, and other capabilities. Its detection capabilities cover the complete APT attack chain, effectively discovering APT attacks, unknown threats, and cybersecurity incidents of concern to users.
DBAPPSecurity Host Guard EDR uses a distributed “platform + endpoint” deployment and dual-engine “process blocking + decoy engine” defenses against known and unknown threats.
IOC
mopub[.]space
0c6f6079cf6959fb55141c49b62f7308
bc9f3ca5f2ff492e8c82c1c6cb244844