Patchwork : From One Malicious Document to Complete TTPs of a Medium Skilled Threat Actor

No ratings

Presented at FirstConferenceKualaLumpur 2018 by

Patchwork seems to be a capable threat group likely based in Southern Asia. The modus operandi we monitored shows a threat actor without access to zero-day vulnerabilities, but one that focuses on carefully targeting victims and creating convincing lures. Patchwork installs known or custom RAT malware by using weaponized documents with the target's topics of interest. Furthermore, carefully designed phishing websites provide them with credentials for gathering sensitive data from high-value targets, including ranking military officials and individuals in the aerospace, mass media and online retail companies.This topic covers how we discovered a large part of the group's infrastructure as well as multiple lure documents and RAT malware they used—all from one malicious document and the use of threat intelligence and reverse engineering methods.During the investigation, we discovered how the threat actor manages to infect his targets, what tools he uses and how they have evolved. The discussion also details how they deliver spear phishing emails, which RAT tools they use, how they perform phishing and credential harvesting, and which tools they use to monitor and exfiltrate sensitive data.The discussion will cover several chapters: • The start of the investigation • Examples of weaponized delivery documents and their analysis • Backdoors, remote access tools, and how they evolved over time • File stealers and hard disk monitoring tools and their evolution • Analysis and overview of infrastructure • Phishing kits and credential harvesting • Targets and victims • Countermeasures and defense strategies against future attacks • Summary of the tricks involved in all these findingsDuring the presentation, we will share additional details about this threat actor, including the threats, tactics, and procedures (TTP) and various indicators of compromise (IOC). We will also discuss how DFIR practitioners can use these techniques to gather IOCs, facilitating the prevention of future attacks from a similar threat actor.