Operation Daybreak

2016-06-17 Kaspersky

https://securelist.com/operation-daybreak/75100/

Thumbnail for Operation Daybreak

Kaspersky linked Operation Daybreak to ScarCruft based on shared infrastructure and targeting, describing targeted attacks against more than two dozen high-profile victims across Asia, Europe, the Middle East, and the United States. The campaign used a previously unknown Adobe Flash Player exploit, CVE-2016-4171, delivered through a hacked website that performed browser checks before redirecting victims to attacker-controlled infrastructure in Poland. The exploit chain used Base64 and RC4 in JavaScript, randomized encrypted second-stage payloads to frustrate hash-based detection, and three Flash objects before delivering a Korean-language decoy PDF about China and North Korean nuclear issues. A second-stage DLL abused Windows DDE behavior to execute a malicious VBS and install a CAB payload containing multiple DLLs, including cldbct.dll, which connected to webconncheck.myfw[.]us:8080/8xrss.php. The use of rare payloads, invalid Tencent-themed certificates, and multiple zero-day exploit operations shows a focused actor investing in high-value targeted access.

Indicators of Compromise

Type Value First Seen Last Seen
HASH f8a2d4ddf9dc2de750c8b4b7ee45ba3f 2016-06-17 2016-06-17
HASH e51ce28c2e2d226365bc5315d3e5f83e 2016-06-17 2016-06-17
HASH 8844a537e7f533192ca8e81886e70fbc 2016-06-17 2016-06-17
HASH a6f14b547d9a7190a1f9f1c06f906063 2016-06-17 2016-06-17
HASH 3e5ac6bbf108feec97e1cc36560ab0b6 2016-06-17 2016-06-17
HASH 067681b79756156ba26c12bc36bf835c 2016-06-17 2016-06-17
URL http://webconncheck.myfw.us:808… 2016-06-17 2016-06-17
DOMAIN webconncheck.myfw.us 2016-06-17 2016-06-17
DOMAIN reg.flnet.org 2016-06-17 2016-06-17
IPv4 212.7.217.10 2016-06-17 2016-06-17

Related Actors

Related Reports

« Back