The enemy of my enemy is not my friend... A tale of APT’s thievery

No ratings

Presented at RootedCON 2020 by

APT actors are extremely active in Middle East and their operations have often gone unnoticed. The area is becoming more and more attractive for APT groups, both locals and foreigners.Called to investigate some of those cases, we have discovered new groups as well as faced well known actors we met in other "battlefields".Spear phishing, watering hole attacks and targeted strategies are found in abundance in those cases, but we have also unearthed customized Trojans, infostealer and advanced password dumpers making the investigative scenario often complicated to solve and the removal of the threat very challenging.However, in my ten years in Incident Response investigating in the Middle East, I rarely stumble upon something completely new... but last year me and my team went through an absolutely challenging, I would say "crazy", case.In short, two APT actors, with different origin and interests, successfully attacked a diplomatic environment and started to exfiltrate data.All of a sudden, the less capable of the two, generated some noise by attempting to transfer several gigabytes of documents and was detected.The Victim discovered the breach and asked for support from my team.At the very beginning we focused on the initial alert.We scoped the attack and its magnitude, but while we were attempting to build a proper timeline and to mitigate the threat, we noticed some odds.In fact, through the malware analysis we noticed malware belonging to a different APT group, but sharing the same C2s of the malware identified in the initial machines detected...It was the first time we found an attacker exploiting another attacker's infrastructure for his own purposes and leveraging on that infrastructure to transfer data back and forth a compromised environment.The level of sophistication of the second attacker was way above the first and the initial mitigation was not completely eradicating him, so he come back another time before being expelled.The most successful way to fight those threats is to know them and to anticipate their moves based on patterns that could be recognizable, once the investigator has gained experience and applies the proper methodologies to measure, identify and strategically operate to expel them.The presentation aims to show most relevant techniques and tools used by the adversaries operating in the environment. The presentation will discuss also the investigative approach and the remediation techniques adopted to remove those threats.