String of fileless malware attacks possibly tied to single hacker group

The attacks use PowerShell and open-source tools like Mimikatz and Meterpreter loaded directly in memory

Several attacks observed over the past few months that rely heavily on PowerShell, open-source tools, and fileless malware techniques might be the work of a single group of hackers.

An investigation started by security researchers from Morphisec into a recent email phishing attack against high-profile enterprises pointed to a group that uses techniques documented by several security companies in seemingly unconnected reports over the past two months.

"During the course of the investigation, we uncovered a sophisticated fileless attack framework that appears to be connected to various recent, much-discussed attack campaigns," Michael Gorelik, Morphisec's vice president of research and development, said in a blog post. "Based on our findings, a single group of threat actors is responsible for many of the most sophisticated attacks on financial institutions, government organizations, and enterprises over the past few months."

The Morphisec investigation started with a phishing email that distributed a Microsoft Word document with malicious macros inside. When opened, the document asked the victim to click on the "Enable Content" button in order to view the supposedly protected content. Doing so allowed the malicious embedded code to execute.

From that point on, the attack used a succession of scripts written in PowerShell, a powerful scripting engine included in Windows, to set up persistence through registry keys and establish a communication channel with the attacker's server.

The attackers then downloaded and executed various open-source tools that allowed them to perform a deeper investigation of the system, steal locally stored Windows credentials, and open reverse shells to their server.

Some of the observed tools included Mimikatz, Lazagne, and Meterpreter, the payload of the popular Metasploit penetration testing framework. These programs were loaded directly into the computer's memory and left no traces on disk.

In February, researchers from Kaspersky Lab reported a string of stealthy, fileless attacks against more than 100 enterprises, banks, and government organizations from around the world. Those attacks used very similar techniques and tools, including PowerShell, Mimikatz, and Meterpreter.

In the attack investigated by Morphisec, the attackers also used a PowerShell script that established a two-way communication channel using DNS TXT records. A similar script was documented by researchers from Cisco Talos in early March in a PowerShell-based attack that they dubbed DNSMessenger.

The fileless malware techniques and DNS communication method were also described by researchers from FireEye in a March report about attacks targeting employees from various U.S. organizations whose jobs involved Securities and Exchange Commission (SEC) filings. FireEye attributed those attacks to a financially motivated attack group that the company has been tracking for a while under the name FIN7.

Previous FIN7 operations used the same malware as a group that Kaspersky tracks as Carbanak and is believed to be responsible for the theft of more than US$500 million from financial organizations and other companies.

The Morphisec researchers couldn't establish the identity of the group but had a brief interaction with one of the attackers.

"It was clear that a person from the other side was waiting to connect on his Meterpreter session," Gorelik said. "During the brief interaction, our researchers tried to identify the actor. The attackers immediately blocked the connection and later shut down the C2 server entirely, thereby losing their foothold in the systems of victims connected to that communication server."

In light of these attacks, organizations, especially those from the financial sector, should ensure that they have monitoring systems in place that can detect dual-use tools like Mimikatz and Meterpreter. They should also monitor for unauthorized PowerShell scripts and code loaded directly in memory that creates no executable files on disk.

Join the newsletter!

Error: Please check your email address.
Rocket to Success - Your 10 Tips for Smarter ERP System Selection
Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Lucian Constantin

IDG News Service
Show Comments

Most Popular Reviews

Latest Articles


PCW Evaluation Team

Matthew Stivala

HP OfficeJet 250 Mobile Printer

The HP OfficeJet 250 Mobile Printer is a great device that fits perfectly into my fast paced and mobile lifestyle. My first impression of the printer itself was how incredibly compact and sleek the device was.

Armand Abogado

HP OfficeJet 250 Mobile Printer

Wireless printing from my iPhone was also a handy feature, the whole experience was quick and seamless with no setup requirements - accessed through the default iOS printing menu options.

Azadeh Williams

HP OfficeJet Pro 8730

A smarter way to print for busy small business owners, combining speedy printing with scanning and copying, making it easier to produce high quality documents and images at a touch of a button.

Andrew Grant

HP OfficeJet Pro 8730

I've had a multifunction printer in the office going on 10 years now. It was a neat bit of kit back in the day -- print, copy, scan, fax -- when printing over WiFi felt a bit like magic. It’s seen better days though and an upgrade’s well overdue. This HP OfficeJet Pro 8730 looks like it ticks all the same boxes: print, copy, scan, and fax. (Really? Does anyone fax anything any more? I guess it's good to know the facility’s there, just in case.) Printing over WiFi is more-or- less standard these days.

Ed Dawson

HP OfficeJet Pro 8730

As a freelance writer who is always on the go, I like my technology to be both efficient and effective so I can do my job well. The HP OfficeJet Pro 8730 Inkjet Printer ticks all the boxes in terms of form factor, performance and user interface.

Michael Hargreaves

Windows 10 for Business / Dell XPS 13

I’d happily recommend this touchscreen laptop and Windows 10 as a great way to get serious work done at a desk or on the road.

Featured Content

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?