Categories: SecurityWorkspace

New Strain Of MiniDuke Malware Now Targets Criminals

MiniDuke, the unusual, highly customized malware that was used to spy on government organisations in 2013, has added new functionality and expanded its target list, according to a report by Kaspersky Labs.

An upgraded version of the code, known as CosmicDuke, has been spotted infecting drug dealers and military contractors as well as the traditional government targets. Researchers at Kaspersky suggest that the malware has been adopted by new users, some of which might actually work for law enforcement agencies.

MiniDuke and its derivatives are interesting because they are decisively old-school: written in Assembler, they use an obfuscated loader, encrypt communications and the downloader code weighs just 20kb.

Ain’t no school like the old school

MiniDuke, originally discovered by Kaspersky Labs in 2013, has been targeting organisations in the US, Ukraine, Belgium, Portugal, Romania, the Czech Republic, Hungary and Ireland. It can be managed through several channels, including automated Twitter accounts which broadcast ‘Command & Control’ codes, and hide update executables inside GIF files.

The malware spreads using social engineering techniques: for example, in Eastern Europe it was found hiding inside customised PDF documents which mentioned subjects like Ukraine’s foreign policy and NATO membership plans.

Eugene Kaspersky said at the time that the complex nature of MiniDuke reminded him of the classic malware created at the end of the 1990s.

Meanwhile the new strain, dubbed ‘CosmicDuke’ has been compiled using a customisable framework called BotGenStudio. It is nowable to steal a much wider variety of data, including files based on extensions and keywords.

The malware has been attacking a wide variety of organisations in the UK, US, Russia, Georgia, Kazakhstan, India, Belarus, Cyprus, Ukraine and Lithuania. Quite surprisingly, in Russia CosmicDuke has been used to target other criminals, namely the illegal sellers of steroids and hormones.

“It’s a bit unexpected – normally, when we hear about APTs [Advanced Persistent Threats], we tend to think they are nation-state backed cyber espionage campaigns,” said Vitaly Kamluk, principal security researcher at Kaspersky.

“But we see two explanations for this. One possibility is that malware platform BotGenStudio used in Miniduke is also available as a so-called ‘legal spyware’ tool, similar to others, such as HackingTeam’s RCS, widely used by law enforcement. Another possibility is that it’s simply available in the underground and purchased by various competitors in the pharma business to spy on each other.”

CosmicDuke can also log keyboard commands, harvest network information, take screenshots, steal address books and passwords and export private keys and certificates.After the data has been accessed, the malware implements several network connections for exfiltration, including FTP and three various variants of HTTP.

Each victim of MiniDuke is assigned a unique ID which allows the pushing of specific updates to an individual machine.

How well do you know network security? Try our quiz and find out!

Max Smolaks

Max 'Beast from the East' Smolaks covers open source, public sector, startups and technology of the future at TechWeekEurope. If you find him looking lost on the streets of London, feed him coffee and sugar.

Recent Posts

Russia Accused Of Cyberattack On Germany’s Ruling Party, Defence Firms

German foreign minister warns Russia will face consequences for “absolutely intolerable” cyberattack on ruling party,…

2 days ago

Alphabet Axes Hundreds Of Staff From ‘Core’ Organisation

Google is reportedly laying off at least 200 staff from its “Core” organisation, including key…

2 days ago

Apple Announces Record Share Buyback, Amid iPhone Sales Decline

Investor appeasement? Apple unveils huge $110 billion share buyback program, as sales of iPhone decline…

2 days ago

Tesla Backs Away From Gigacasting Manufacturing – Report

Tesla retreats from pioneering gigacasting manufacturing process, amid cost cutting and challenges at EV giant

2 days ago

US Urges No AI Control Of Nuclear Weapons

No skynet please. After the US, UK and France pledge human only control of nuclear…

3 days ago