Back home
中文
H7 / SECURITY RESEARCH NOTES

Suspected HADES Group Launches a Military-Themed Attack Against Ukraine

June 29, 2021 Lieying Lab Comments 0 Comment 1,536 views

Background

Hades is a mysterious APT group. It was first discovered because of its attack on the PyeongChang Winter Olympics in South Korea on December 22, 2017, and Kaspersky later named the group behind that incident Hades. However, the group's attribution has never been conclusively determined. On one hand, the destructive malware (Olympic Destroyer) used in the attack shared similarities with malware used by the North Korean Lazarus group. On the other hand, some US media outlets believed Russian intelligence agencies were behind the incident and had deliberately imitated other groups' techniques to plant false flags and mislead security personnel.

Incident Analysis

Recently, DBAPPSecurity Threat Intelligence Center's Lieying Lab captured a malicious sample. Through tracing and analyzing the sample, we found that it was suspected to be another attack by the Hades group against Ukraine.

Detailed sample information is shown below:

Sample NameПро внесення змін.doc
Sample TypeMicrosoft Word document (.doc)
MD50c6f6079cf6959fb55141c49b62f7308

The decoy document appears blank when opened and displays its content only after macro code is enabled:

2.png

The decoy content is related to the Ukrainian military:

img

The decoy document's content actually came from a foreign website (uteka.ua), which specializes in providing practical information about unresolved and disputed issues to managers, accountants, and other professionals. The original content is shown below:

3.png

The macro code was obfuscated. After deobfuscation, it first changes the document properties to display the decoy content and then creates desktop.ini and C:\ProgramData\pagefile.dll:

img

pagefile.dll is a .NET backdoor that the macro code loads and executes through RegSvcs.exe. It then communicates with the C2 server (mopub[.]space).

img

It can also transmit data through the Referer header.

img

The DLL was obfuscated. Some of its contents can be seen after deobfuscation.

img

Correlation Analysis

Using the DBAPPSecurity Threat Intelligence Center platform to correlate the current sample, we found a strong association between the sample and the Hades group. The attack target, macro-code similarity, and other aspects of this sample all matched “OPERATION TRICKYMOUSE—Attacking Ukraine with a COVID-19 Theme,” which Lieying Lab had previously published.

Both incidents targeted Ukraine:

img

The macro code was also largely identical in data initialization, decryption algorithms, execution functions, and other areas:

img

Both samples used the same method at the beginning of the code to initialize, through a function, the file data that would be saved locally:

img

They then initialized variables in the same way, and the decryption functions were also identical:

img

Finally, the functional logic of the code in the main function was also identical:

img

Previous sample:

img

Defense Recommendations

The DBAPPSecurity APT Attack Early Warning Platform can identify known and unknown threats. It can monitor, capture, and analyze the maliciousness of files or programs in real time and strongly monitor malicious samples such as Trojans associated with every stage, including email delivery, exploitation, installation, implantation, callback, and control.

The platform also performs deep analysis of network traffic using bidirectional traffic analysis, intelligent machine learning, efficient dynamic sandbox analysis, a rich feature library, comprehensive detection strategies, massive threat intelligence, and other capabilities. Its detection capabilities cover the complete APT attack chain, effectively discovering APT attacks, unknown threats, and cybersecurity incidents of concern to users.

DBAPPSecurity Host Guard EDR uses a distributed “platform + endpoint” deployment and dual-engine “process blocking + decoy engine” defenses against known and unknown threats.

IOC

mopub[.]space

0c6f6079cf6959fb55141c49b62f7308

bc9f3ca5f2ff492e8c82c1c6cb244844