DEV-0139 launches targeted attacks against the cryptocurrency industry

2022-12-06 Microsoft

https://www.microsoft.com/en-us/security/blog/2022/12/06/dev-0139-launches-targeted-attacks-against-the-cryptocurrency-industry/

Thumbnail for DEV-0139 launches targeted attacks against the cryptocurrency industry

Microsoft investigated DEV-0139 activity targeting cryptocurrency investment companies through carefully prepared Telegram social engineering. The actor joined VIP cryptocurrency exchange communication groups, impersonated OKX-linked contacts, and moved employees into a secondary chat before sending a weaponized Excel file named OKX Binance & Huobi VIP fee comparision.xls. The macro used VBA UserForm obfuscation to drop VSDB688.tmp, retrieve a PNG from od.lk, and extract logagent.exe, a malicious wsock32.dll, and an XOR-encoded backdoor for DLL side-loading and remote access. Microsoft also connected the technique to a CryptoDashboardV2 MSI variant that side-loaded DUser.dll via TPLink.exe, indicating repeated use of DLL proxying against cryptocurrency-sector targets.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN strainservice.com 2022-12-01 2023-10-26
HASH 8400f2674892cdfff27b0dfe98a2a77… 2022-12-06 2022-12-06
HASH d021d412be456a6f78a0052a1f0e355… 2022-12-06 2022-12-06
URL https://od.lk/d/d021d412be456a6… 2022-12-06 2022-12-06
IPv4 198.54.115.248 2022-12-06 2022-12-06
HASH e5980e18319027f0c28cd2f581e75e7… 2022-12-01 2022-12-06
HASH a2d3c41e6812044573a939a51a22d65… 2022-12-01 2022-12-06
HASH abca3253c003af67113f83df2242a70… 2022-12-01 2022-12-06

Related Actors

Related Reports

« Back