Murky Waters: How the MuddyWater Hackers Attacked a Turkish Military Electronics Manufacturer

Murky Waters: How the MuddyWater Hackers Attacked a Turkish Military Electronics Manufacturer

Iranian pro-government hackers are facing major issues. Throughout the spring, unknown individuals published "secret leaks" in Telegram—information about Iran-linked APT groups— OilRig and MuddyWater — their tools, victims, and connections. But not all of them. In April, specialists from Group-IB discovered a leak of email addresses from the Turkish corporation ASELSAN A.Ş, which produces tactical military radios and electronic defense systems for the Turkish armed forces. Anastasia Tikhonova, head of the Group-IB Threat Research team, and Nikita Rostovtsev, a junior analyst at Group-IB, described the attack on ASELSAN A.Ş and identified a potential participant. MuddyWater.

Exposure via Telegram

The leak of Iranian APT groups began when someone named Lab Dookhtegan revealed the source codes of six tools from APT34 (also known as OilRig and HelixKitten), disclosed the IP addresses and domains involved in operations, and provided data on 66 hacker victims, including companies like Etihad Airways and Emirates National Oil. Lab Dookhtegan also leaked data about the group’s past operations and information about employees of the Iranian Ministry of Information and National Security, who are allegedly linked to the group’s operations. OilRig is an Iran-linked APT group that has existed since around 2014 and targets government, financial, and military organizations, as well as energy and telecommunications companies in the Middle East and China.

After the exposure of OilRig, the leaks continued—information about the activities of another pro-government group from Iran, MuddyWater, appeared on the dark web and Telegram. However, unlike the first leak, this time the published materials did not include source codes but rather dumps containing screenshots of source code from command servers, as well as IP addresses of past hacker victims. This time, the hackers known as Green Leakers claimed responsibility for the leak concerning MuddyWater. They own several Telegram channels and websites on the dark web, where they promote and sell data related to MuddyWater's operations.

Cyber spies from the Middle East

MuddyWater — is a group that has been active since 2017 in the Middle East. For example, specialists from Group-IB note that from February to April 2019, hackers conducted a series of phishing campaigns targeting government and educational organizations, financial, telecommunications, and defense companies in Turkey, Iran, Afghanistan, Iraq, and Azerbaijan.

Group members use a backdoor of their own development based on PowerShell, which is named POWERSTATS. It can:

  • collect data on local and domain accounts, available file servers, internal and external IP addresses, OS name and architecture;
  • perform remote code execution;
  • upload and download files via C&C;
  • detect the presence of debugging tools used in the analysis of malicious files;
  • disable the system if analysis tools for malicious files are found;
  • delete files from local disks;
  • take screenshots;
  • disable protective measures of Microsoft Office products.

At some point, the attackers made a mistake, allowing researchers from ReaQta to obtain the final IP address, which was located in Tehran. Considering the targets attacked by the group, as well as its tasks related to cyber espionage, specialists suggested that the group represents the interests of the Iranian government.

Indicators of AttacksC&C:

  • gladiyator[.]tk
  • 94.23.148[.]194
  • 192.95.21[.]28
  • 46.105.84[.]146
  • 185.162.235[.]182

Files:

  • 09aabd2613d339d90ddbd4b7c09195a9
  • cfa845995b851aacdf40b8e6a5b87ba7
  • a61b268e9bc9b7e6c9125cdbfb1c422a
  • f12bab5541a7d8ef4bbca81f6fc835a3
  • a066f5b93f4ac85e9adfe5ff3b10bc28
  • 8a004e93d7ee3b26d94156768bc0839d
  • 0638adf8fb4095d60fbef190a759aa9e
  • eed599981c097944fa143e7d7f7e17b1
  • 21aebece73549b3c4355a6060df410e9
  • 5c6148619abb10bb3789dcfb32f759a6

Turkey under fire

On April 10, 2019, specialists from Group-IB discovered a leak of email addresses from the Turkish company ASELSAN A.Ş — the largest military electronics company in Turkey. Its products include radars and radio-electronic means, electro-optics, avionics, unmanned systems, ground, naval, and weapon systems, as well as air defense systems.

While studying one of the new samples of the POWERSTATS malware, Group-IB experts identified that the MuddyWater group used a license agreement between Koç Savunma, a manufacturer of information and defense technology solutions, and the Tubitak Bilgem information security and advanced technology research center as a lure document. The contact person representing Koç Savunma was Tahir Taner Tımış, who served as Programs Manager at Koç Bilgi ve Savunma Teknolojileri A.Ş. from September 2013 to December 2018. He later joined ASELSAN A.Ş.

Sample of the lure documentMurky Waters: How the MuddyWater Hackers Attacked a Turkish Military Electronics Manufacturer
After the user activates the malicious macros, a POWERSTATS backdoor is downloaded to the victim's computer.

Thanks to the metadata of this lure document (MD5: 0638adf8fb4095d60fbef190a759aa9e) the researchers were able to find three additional samples containing identical values, including creation date and time, username, and a list of macros present:

  • ListOfHackedEmails.doc (eed599981c097944fa143e7d7f7e17b1)
  • asd.doc (21aebece73549b3c4355a6060df410e9)
  • F35-Specifications.doc (5c6148619abb10bb3789dcfb32f759a6)

Screenshot of identical metadata from various lure documents Murky Waters: How the MuddyWater Hackers Attacked a Turkish Military Electronics Manufacturer

One of the discovered documents named ListOfHackedEmails.doc contains a list of 34 email addresses associated with the domain @aselsan.com.tr.

Group-IB specialists checked the email addresses against publicly available leaks and found that 28 of them had been compromised in previously detected leaks. A mix of accessible leaks revealed around 400 unique logins related to this domain, along with associated passwords. It is possible that the attackers used this publicly available data to target ASELSAN A.Ş.

Screenshot of the document ListOfHackedEmails.doc Murky Waters: How the MuddyWater Hackers Attacked a Turkish Military Electronics Manufacturer

Screenshot of the list of over 450 discovered login-password pairs in public leaks Murky Waters: How the MuddyWater Hackers Attacked a Turkish Military Electronics Manufacturer
Among the discovered samples was a document titled F35-Specifications.doc, referring to the F-35 fighter jet. The lure document consists of the specifications of the F-35 multirole stealth bombers, detailing aircraft features and pricing. The topic of this lure document directly relates to the U.S. refusal to deliver F-35s after Turkey's purchase of the S-400 systems and the threat of transmitting F-35 Lightning II information to Russia.

All the gathered data indicated that the main target of the MuddyWater cyberattacks were organizations located in Turkey.

Who are Gladiyator_CRK and Nima Nikjoo?

Earlier, in March 2019, malicious documents were discovered, created by a Windows user under the alias Gladiyator_CRK. These documents also spread the POWERSTATS backdoor and connected to a C&C server with a similar name. gladiyator[.]tk.

It is possible that this was done after March 14, 2019, when user Nima Nikjoo posted on Twitter attempting to decode obfuscated code related to MuddyWater. In the comments of this tweet, the researcher stated that he could not share indicators of compromise for this malware, as this information is confidential. Unfortunately, the post has since been deleted, but traces of it remain online:

Murky Waters: How the MuddyWater Hackers Attacked a Turkish Military Electronics Manufacturer
Murky Waters: How the MuddyWater Hackers Attacked a Turkish Military Electronics Manufacturer
Nima Nikjoo is the owner of the Gladiyator_CRK profile on Iranian video hosting sites dideo.ir and videoi.ir. On this site, he showcases PoC exploits to disable antivirus software from various vendors and bypass sandboxes. Nima Nikjoo describes himself as a specialist in network security, as well as a reverse engineer and malware analyst, working at MTN Irancell, an Iranian telecommunications company.

Screenshot of saved videos in Google search results:

Murky Waters: How the MuddyWater Hackers Attacked a Turkish Military Electronics Manufacturer
Murky Waters: How the MuddyWater Hackers Attacked a Turkish Military Electronics Manufacturer
Later, on March 19, 2019, user Nima Nikjoo changed his username to Malware Fighter on Twitter and deleted related posts and comments. The Gladiyator_CRK profile on the video hosting site dideo.ir was also deleted, as was the one on YouTube, and the profile itself was renamed to N Tabrizi. However, almost a month later (on April 16, 2019), the Twitter account began using the name Nima Nikjoo again.

During the investigation, Group-IB specialists discovered that Nima Nikjoo had already been mentioned in connection with cybercriminal activity. In August 2014, the blog Iran Khabarestan published information about individuals associated with the cybercriminal group Iranian Nasr Institute. One of FireEye's studies stated that Nasr Institute was a contractor for APT33 and participated in DDoS attacks on American banks between 2011 and 2013 as part of a campaign called Operation Ababil.

In this blog, Nima Nikju-Nikjoo was mentioned, who developed malware to spy on Iranians, and his email address is: gladiyator_cracker@yahoo[.]com.

Screenshot of data related to cybercriminals from the Iranian Nasr Institute:

Murky Waters: How the MuddyWater Hackers Attacked a Turkish Military Electronics Manufacturer
Translation of the highlighted text into Russian: Nima Nikjoo — Spyware Developer — Email address:.

As can be seen from this information, the email address is linked to the one used in the attacks and by users Gladiyator_CRK and Nima Nikjoo.

Additionally, a June 15, 2017 article stated that Nikjoo was somewhat careless in publishing links to the Kavosh Security Center in his resume. There is an opinion, evidence that the Kavosh Security Center is state-sponsored by Iran to fund pro-government hackers.

Information about the company where Nima Nikjoo worked:

Murky Waters: How the MuddyWater Hackers Attacked a Turkish Military Electronics Manufacturer
In the LinkedIn profile of Twitter user Nima Nikjoo, his first job is listed as Kavosh Security Center, where he worked from 2006 to 2014. During his time there, he studied various malware and dealt with reverse engineering and obfuscation-related tasks.

Information about the company where Nima Nikjoo worked, on LinkedIn:

Murky Waters: How the MuddyWater Hackers Attacked a Turkish Military Electronics Manufacturer

MuddyWater and inflated self-esteem

Interestingly, the MuddyWater group carefully monitors all reports published about them and messages from cybersecurity experts, even going so far as to initially leave false flags to mislead researchers. For example, their initial attacks misled experts as the use of DNS Messenger was discovered, which was typically associated with the FIN7 group. In other attacks, they embedded Chinese strings into the code.

Furthermore, the group enjoys leaving messages for researchers. For example, they were displeased that Kaspersky Lab ranked MuddyWater 3rd in its threat report for the year. At the same time, someone — presumably from the MuddyWater group — uploaded a PoC exploit that disables Kaspersky Lab's antivirus to YouTube. They also left a comment under the article.

Screenshots of the video demonstrating the disabling of Kaspersky Lab's antivirus and the comment below it:

Murky Waters: How the MuddyWater Hackers Attacked a Turkish Military Electronics Manufacturer
Murky Waters: How the MuddyWater Hackers Attacked a Turkish Military Electronics Manufacturer
It is currently difficult to draw a definitive conclusion about the involvement of 'Nima Nikjoo'. Experts at Group-IB are considering two versions. Nima Nikjoo may indeed be a hacker from the MuddyWater group, who surfaced due to his carelessness and increased online activity. The second possibility is that he was deliberately exposed by other members of the group to divert suspicion from themselves. In any case, Group-IB continues its investigation and will surely report on its findings.

Regarding Iranian APTs, after a series of leaks and disclosures, they are likely facing a serious 'debriefing' — hackers will be forced to significantly alter their toolkit, cover their tracks, and identify possible 'moles' within their ranks. Experts did not rule out that they might even take a timeout, but after a brief hiatus, attacks by Iranian APTs resumed.

Source: habr.com

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster