May 14, 2019 By David Bisson 2 min read

An advanced persistent threat (APT) group known as ScarCruft is now using malware to steal information off of Bluetooth devices.

Kaspersky Lab came across the malware during its analysis of ScarCruft’s recent activity. The security firm investigated a multistage binary infection scheme in which the group used an initial dropper that bypassed Windows User Account Control (UAC) to execute the next payload with higher privileges. With the help of public privilege escalation exploit code CVE-2018-8120, the malicious installer created and executed a downloader that connected to a command-and-control (C&C) server and downloaded the next payload: an image file that contained an appended malicious file hidden by steganography. This payload turned out to be ROKRAT, a backdoor known for stealing information.

The research also revealed ScarCruft’s interest in mobile devices. Specifically, Kaspersky Lab came across a piece of malware that used Windows Bluetooth application programming interfaces (APIs) to find information on connected Bluetooth devices. This data included the name, address and class of device as well as whether the device was connected, authenticated and/or remembered.

ScarCruft: An Experienced Threat Actor

ScarCruft has been running APT campaigns for some time now. Back in 2016, for instance, Kaspersky Lab announced that the group was to blame for Operation Daybreak, a campaign that leveraged spear phishing emails and a previously unknown zero-day exploit affecting Adobe Flash Player to conduct targeted attacks.

Approximately two years later, researchers at Palo Alto Networks discovered links between a previously unknown malware family called NOKKI and the threat actor, which also goes by the names Reaper, APT37 and Group123.

How to Defend Against Multistage Binary Infections

Security professionals can help defend against multistage binary infections by conducting phishing simulations to test their email security defenses against social engineering attacks.

Companies should also use a unified endpoint management (UEM) platform to monitor all IT assets — including mobile and internet of things (IoT) devices — for suspicious behavior.

More from

When ransomware kills: Attacks on healthcare facilities

4 min read - As ransomware attacks continue to escalate, their toll is often measured in data loss and financial strain. But what about the loss of human life? Nowhere is the ransomware threat more acute than in the healthcare sector, where patients’ lives are literally on the line.Since 2015, there has been a staggering increase in ransomware attacks on healthcare facilities. And the impacts are severe: Diverted emergency services, delayed critical treatments and even fatalities. Meanwhile, the pledge some ransomware groups made during…

AI and cloud vulnerabilities aren’t the only threats facing CISOs today

6 min read - With cloud infrastructure and, more recently, artificial intelligence (AI) systems becoming prime targets for attackers, security leaders are laser-focused on defending these high-profile areas. They’re right to do so, too, as cyber criminals turn to new and emerging technologies to launch and scale ever more sophisticated attacks.However, this heightened attention to emerging threats makes it easy to overlook traditional attack vectors, such as human-driven social engineering and vulnerabilities in physical security.As adversaries exploit an ever-wider range of potential entry points…

4 trends in software supply chain security

4 min read - Some of the biggest and most infamous cyberattacks of the past decade were caused by a security breakdown in the software supply chain. SolarWinds was probably the most well-known, but it was not alone. Incidents against companies like Equifax and tools like MOVEit also wreaked havoc for organizations and customers whose sensitive information was compromised.Expect to see more software supply chain attacks moving forward. According to ReversingLabs' The State of Software Supply Chain Security 2024 study, attacks against the software…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today