ELITE OFFENSIVE SECURITY COMPANYTOSHKENT / UZBEKISTAN

Hiylaqush cyber operation

Research into malware distributed through Telegram in the Uzbek segment and its digital traces.

Operation “Birinchi hiylaqush”

*We traced the earliest signs of this malware, which spread widely through Telegram in the Uzbek segment, to December 14, 2023. Aware of Telegram’s popularity in Uzbekistan, cybercriminals targeted various government organizations, distributing malware to their groups and employees’ Telegram profiles under different disguises, names and scenarios.

We continue to observe these malicious programs in public groups and Telegram channels, along with the spread of new variants. This research was presented at the annual “Central Eurasian Information Security and Cybersecurity Summit” in 2024. It included information about several malware programs and the cybercriminal groups operating them.

The malware detected in the first quarter of 2024 was used in targeted attacks under the following names.

The detected malware was found to fall mainly into two types: “Stealer” and “RAT” families. We will examine the analysis of the “Stealer” malware step by step below.

Once running on Windows, the malware used the system’s Defender antivirus settings to exclude itself from scans, using “PowerShell” commands to execute the following in the background.

Next, the malware disabled all security monitoring modules of the system’s Defender antivirus, allowing it to operate freely on the system afterward.

After taking control of the security state of the system and Defender, the malware distracted the user by displaying a “fake” message to mislead the user into believing the application had encountered an error (0xc000007b runtime error) was preventing it from launching.

After completing all the necessary steps, the malware identified the user’s system using “wmic”, a tool for managing and retrieving system information through a CLI – (Command Line Interface).

The malware makes several changes to the system’s “registry” and begins reading existing data.

In subsequent steps, the malware downloads several modules into the system’s “TEMP” directory. These modules later perform other tasks on the system.

The modules and their individual functions are shown below.

The analysis results, including examination of the collected module samples, showed that the malware was “Blank grabber”. “Blank Grabber” was initially “Blank” was the alias of the hacker who developed it. It was published as open-source software on GitHub and later “Astounding” (BlackForums administrator) and other developers supported and developed it further. Written in Python, its simple interface made it accessible even to inexperienced cybercriminals, contributing to its widespread use. There is no definitive information on which hacking group first used it, as its open-source availability enabled use by many attackers. Our research identified several modified variants of this malware circulating in Uzbekistan.

The family of the next malware tool in the cybercriminal arsenal can be identified quickly, although tracking and detecting it can be more difficult. “Blank grabber” — unlike it, DC RAT — Dark Crystal RAT (remote access trojan) is purchased for a fee and requires a server and domain to operate.

This image shows the domain used to operate “DC Rat”. According to domain research on the CYBER-BRO CTI cyber intelligence platform, it was found to belong to the major cybercriminal group “NyashTeam”.

Once on the system, the malware stole all saved login credentials, confidential information, application data, and cryptocurrency wallet data through a Telegram bot.

On cybercriminal forums, the malware was offered separately as “M.a.a.S” — malware as a service; it was found to have been on sale since 2019.

Below you can see the interface of this RAT tool and infected computers in Uzbekistan and other countries.

NyashTeam” and the cybercriminals it serves were linked to over 500 identified domains and servers.

NyashTeam” sold and serviced a modified version of “DCRAT” for cybercriminals. Any cybercriminal could purchase this malware and distribute a ready-made “virus” to monitor, control and modify the computers of individuals and organisations. We identified one such cybercriminal in 2023 , in December, and prevented large-scale cyberattacks targeting Uzbekistan across multiple sectors. A brief account follows.

Identifying cybercriminals usually requires a combination of measures. Alongside technical knowledge, social and psychological research can be useful. Small, publicly available malware of this kind is generally used by individual cybercriminals or small groups. Major hacking groups carrying out targeted attacks do not use this type of arsenal. For this reason, our specialists were able to access the computer of a member of “Nyashteam”. Further details are available in the presentation published at “CYBERKENT v2”.

The device in this image was identified when cybercriminals encountered CYBER-BRO specialists’ pre-arranged “trap”. The cybercriminals accessed the “trap” computer, they also infect their own computers. This enabled our specialists to obtain data from the cybercriminals’ computers, information about affected countries and organizations, stolen data and several other malware samples. The information obtained indicates that the cybercriminals had been active in Uzbekistan for a long time. Further details on the data, affected organizations and scale of damage will be available in our subsequent research reports.

The group “NyashTeam” supplied cybercriminals with “DCRAT”. This image was taken from the program operator’s computer (January 2024). We named this operator “Sleeping Bear” and the operation “First Trickster”. A year later, recently (on July 22), F6 (formerly F.A.C.C.T), a cybersecurity company, announced that domains in Russia belonging to “Nyashteam” had been successfully shut down.

For more information and to view the presentation, follow the link.

Cyber Threat Intelligence Platform

Dark Web monitoring

Data offered for sale on the Dark Web is monitored and collected through trusted bots or specialised networks. Information stolen by hacker groups is identified and reported before it is offered for sale or becomes widely available.

Hacker Group Infiltration

In some cases, CTI platforms establish direct contact with hacker group members through trusted intermediaries or infiltrated channels. These contacts provide access to previously unpublished information and help prevent its public disclosure.

Commercial Threat Intelligence Feeds

Data is collected through multiple channels across the internet and monitored continuously. OSINT covers open sources, including forums, blogs, social media and messages. The Dark Web and Deep Web include private forums and data marketplaces. Honeypots monitor hacker group activity through purpose-built decoy systems. Malware sources include databases such as VirusTotal, Hybrid Analysis and others. Threat information for the UZ segment is also obtained through exchange mechanisms such as STIX/TAXII, MISP and AlienVault OTX. Analytical tools support information exchange through log and event analysis using SIEM and other cloud systems.

Explore our reports on Uzbekistan’s internet segment.

CYBER-BRO SECURITY

Download and read our first public report on threats identified through CTI.

Any organisation can request CITIZENSEC cyber intelligence findings in the sample format shown below.

CYBER-BRO / INCIDENT RESPONSE

Experiencing an incident?

Briefly describe the situation. We will review your request and contact you to agree the next steps.

Do not submit passwords or confidential files. We will agree a secure way to exchange evidence separately.

Privacy policy