Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cyberwarfare

APT29 Cyberspies Use Domain Fronting to Evade Detection

The Russia-linked cyber espionage group known as APT29 has been using a technique called “domain fronting” in an effort to make it more difficult for targeted organizations to identify malicious traffic, FireEye reported on Monday.

The Russia-linked cyber espionage group known as APT29 has been using a technique called “domain fronting” in an effort to make it more difficult for targeted organizations to identify malicious traffic, FireEye reported on Monday.

Domain fronting is a censorship bypassing technique that involves disguising traffic to make it look as if it’s going to a host allowed by the censor, such as Google, Amazon or CloudFlare. Open Whisper Systems recently implemented the technique to help Signal users in Egypt and the United Arab Emirates bypass government censorship.

According to FireEye, the technique has been used for at least two years by the threat actor APT29, which is also known as The Dukes, Cozy Bear and Cozy Duke. The group is believed to be behind the recent election-related attacks in the U.S. and a campaign targeting high-profile organizations in Norway.

APT29 has used the Tor anonymity network to communicate with infected machines, which could be considered suspicious by some defenders. In order to disguise Tor traffic as apparently legitimate traffic, the cyberspies used Meek, a Tor plugin that implements domain fronting and allows users to send traffic to Tor inside a harmless-looking HTTPS POST request to google.com.

In its attacks, APT29 used a PowerShell script and a .bat file to install the Tor client and the Meek plugin on the targeted system. They leveraged an exploit involving the Sticky Keys accessibility feature, where they replaced the legitimate executable with the Windows Command Prompt (cmd.exe) file. This provides the attacker a shell that they can use to execute commands with SYSTEM-level privileges, including to add or modify accounts.

The script that executes the Sticky Keys exploit also creates a Windows service named “Google Update” to ensure that the backdoor remains even after the system has been rebooted.

“APT29 adopted domain fronting long before these techniques were widely known,” said FireEye’s Matthew Dunwoody. “By employing a publicly available implementation, they were able to hide their network traffic, with minimal research or development, and with tools that are difficult to attribute. Detecting this activity on the network requires visibility into TLS connections and effective network signatures.”

Related: Cyberspies Launch U.S. Attacks Hours After Trump Elected

Advertisement. Scroll to continue reading.

Related: U.S. Gov’s “GRIZZLY STEPPE” Report Fails to Achieve Purpose

Written By

Eduard Kovacs (@EduardKovacs) is a managing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Understand how to go beyond effectively communicating new security strategies and recommendations.

Register

Join us for an in depth exploration of the critical nature of software and vendor supply chain security issues with a focus on understanding how attacks against identity infrastructure come with major cascading effects.

Register

Expert Insights

Related Content

Application Security

Cycode, a startup that provides solutions for protecting software source code, emerged from stealth mode on Tuesday with $4.6 million in seed funding.

Cybercrime

The changing nature of what we still generally call ransomware will continue through 2023, driven by three primary conditions.

Data Protection

The cryptopocalypse is the point at which quantum computing becomes powerful enough to use Shor’s algorithm to crack PKI encryption.

Cybercrime

A recently disclosed vBulletin vulnerability, which had a zero-day status for roughly two days last week, was exploited in a hacker attack targeting the...

Artificial Intelligence

The CRYSTALS-Kyber public-key encryption and key encapsulation mechanism recommended by NIST for post-quantum cryptography has been broken using AI combined with side channel attacks.

Cyberwarfare

WASHINGTON - Cyberattacks are the most serious threat facing the United States, even more so than terrorism, according to American defense experts. Almost half...

Cyberwarfare

Russian espionage group Nomadic Octopus infiltrated a Tajikistani telecoms provider to spy on 18 entities, including government officials and public service infrastructures.

Cybercrime

Patch Tuesday: Microsoft calls attention to a series of zero-day remote code execution attacks hitting its Office productivity suite.