Threat Intelligence, Critical Infrastructure Security

Sophisticated backdoor targets Belarusian military

Threat actors have sought to compromise Belarusian Special Operations Command personnel and unmanned aerial vehicle specialists with the highly sophisticated SSH-Tor backdoor as part of a cyberespionage campaign that builds upon the Sandworm-linked Army+ campaign last December, reports The Cyber Express.

Attacks involved the distribution of a ZIP archive with an LNK file masquerading as a Belarusian military PDF document that facilitated the execution of a PowerShell script, which ensures stealth and persistence in targeted systems, an analysis from Cyble Research and Intelligence Labs showed.

XML files from the ZIP archive allowed the creation of scheduled tasks launching OpenSSH for Windows to disable passwords and the execution of an altered Tor client that established a concealed .onion address.

Such a backdoor was noted by researchers to have permitted total remote and covert access via SSH, SFTP, RDP, and SMB. Moreover, the lack of lateral movement or secondary payloads indicates reconnaissance operations, researchers added.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds