Leery Turtle Threat Report
2020-05-06 • Cyberstruggle •
https://cyberstruggle.org/delta/LeeryTurtleThreatReport_05_20.pdf
Attachments
The Leery Turtle report profiles a financially motivated APT active since at least late 2017 against cryptocurrency exchange businesses worldwide. The group performs reconnaissance against technical and executive staff, sends decoy emails with benign attachments to identify likely openers, then uses spear-phishing that impersonates services such as Google Drive and OneDrive and spoofs coworker email identities. A typical attack delivers a password-protected PDF with an LNK shortcut disguised as the password file; the shortcut launches mshta to retrieve VBS payloads from attacker infrastructure, gather host information, and install persistence through a Startup-folder shortcut. The campaign relies on staged VBS downloaders, bit.ly redirection, server-side checks for MSHTA user agents, and C2 responses that deliver second-stage scripts.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | mail.gdriveupload.info | 2020-05-06 | 2022-01-13 |
| DOMAIN | mail.googleupload.info | 2020-05-06 | 2022-01-13 |
| DOMAIN | att.gdrvupload.xyz | 2020-05-06 | 2022-01-13 |
| DOMAIN | drivegooglshare.xyz | 2020-05-06 | 2021-05-24 |
| DOMAIN | drivegoogle.publicvm.com | 2019-07-09 | 2021-05-24 |
| IPv4 | 203.144.133.42 | 2020-05-06 | 2020-09-18 |
| DOMAIN | microsoft-update10v.amazonaws1.… | 2020-05-06 | 2020-08-18 |
| DOMAIN | check.onedrvdn.co | 2020-05-06 | 2020-08-18 |
| DOMAIN | support.gdrvcheck.co | 2020-05-06 | 2020-08-18 |
| DOMAIN | scloud.wechart.org | 2020-05-06 | 2020-08-18 |
| DOMAIN | gdocs.googleupload.info | 2020-05-06 | 2020-08-18 |
| DOMAIN | gbackup.gogleshare.xyz | 2019-07-09 | 2020-08-18 |
| DOMAIN | drive.gogleshare.xyz | 2019-07-09 | 2020-08-18 |
| DOMAIN | googldocs.org | 2019-07-09 | 2020-08-18 |
| DOMAIN | drivelnk.liveonedrvshare.xyz | 2020-05-06 | 2020-05-06 |
| DOMAIN | drive.googleupload.info | 2020-05-06 | 2020-05-06 |
| DOMAIN | start.showprice.xyz | 2019-07-09 | 2020-05-06 |
| DOMAIN | iellsfileshare.sharedrivegght.x… | 2019-07-09 | 2020-05-06 |
| DOMAIN | docs.googlefiledrive.com | 2019-07-09 | 2020-05-06 |