Operation Mermaid: A Decade of Targeted APT Attacks on Government Entities
- Actor Motivations: Espionage,Exfiltration
- Attack Vectors: Downloader,Keylogger,Malware,RAT,Trojan,Phishing,Spear Phishing
- Attack Complexity: Medium
- Threat Risk: High Impact/Low Probability
Threat Overview
Operation Mermaid, an APT campaign active since April 2010, targeted government entities, specifically the Denmark Embassy and the Ministry of Foreign Affairs of Denmark. This six-year operation utilized phishing emails and watering hole attacks to deliver malicious code, evidenced by 284 malicious samples and 35 C&C domains. Analysis revealed the primary aim was data theft from English and Persian speaking countries. The SD RAT malware, disguised as legitimate files, played a key role in these attacks, featuring keylogging and data exfiltration capabilities. Differences in malware versions and tactics, including a unique check for Avast antivirus, suggest evolving strategies to evade detection.
Detected Targets
| Type | Description | Confidence |
|---|---|---|
| Case | Ministry of Foreign Affairs of Denmark The Ministry of Foreign Affairs of Denmark and its overseas representations are in charge of the Danish Realm's foreign policy and relations. Among these tasks are policy towards the Arctic Council, European Union, Nordic Council, development aid, trade policy and legal affairs in relation to the outside world. Ministry of Foreign Affairs of Denmark has been targeted by Mermaid as the main target. | Verified |
| Region | Denmark | Verified |
Extracted IOCs
- bestupdateserver[.]com
- bestwebstat[.]com
- myblog2000[.]com
- short-name[.]com
- updateserver1[.]com
- aj58mail-box@yahoo[.]com
- am54ja@yahoo[.]com
- aminjalali_58@yahoo[.]com
- kamil_r@mail[.]com
- 0096c70453cd7110453b6609a950ce18
- 1a918a850892c2ca5480702c64c3454c
- 1c401190a40bc5c03dc5711c57b4b416
- 260687b5a29d9a8947d514acae695ad4
- 3d186a44960a4edc8e297e1066e4264b
- 6bc1aea97e7b420b0993eff794ed2aeb
- 6e4e52cf69e37d2d540a431f23d7015a
- 7a6e9a6e87e1e43ad188f18ae42f470f
- 83e90ccf2523cce6dec582cdc3ddf76b
- b61b26c9862e74772a864afcbf4feba4
- ffad81c9cc9a6d1bd77b29c5be16d1b0
- 192[.]69.208.202
- 209[.]236.117.65
- 69[.]195.129.72
- hxxp://bestupdateserver[.]com/
- hxxp://updateserver1[.]com
Tip: 25 related IOCs (3 IP, 5 domain, 2 URL, 4 email, 11 file hash) to this threat have been found.
Overlaps
Source: Palo Alto Networks - June 2016
Detection (three cases): bestupdateserver[.]com, bestwebstat[.]com, updateserver1[.]com
Source: Palo Alto Networks - May 2016
Detection (14 cases): 0096c70453cd7110453b6609a950ce18, 1a918a850892c2ca5480702c64c3454c, 260687b5a29d9a8947d514acae695ad4, 6bc1aea97e7b420b0993eff794ed2aeb, 6e4e52cf69e37d2d540a431f23d7015a, 7a6e9a6e87e1e43ad188f18ae42f470f, aj58mail-box@yahoo[.]com, am54ja@yahoo[.]com, aminjalali_58@yahoo[.]com, bestupdateserver[.]com, bestwebstat[.]com, myblog2000[.]com, short-name[.]com, updateserver1[.]com
Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.
FAQs
Operation Mermaid
Security researchers uncovered a long-running cyber espionage campaign dubbed "Operation Mermaid." Over a period of six years, attackers successfully used deceptive emails and compromised websites to secretly install tracking software on targeted computers.
Evidence strongly suggests the attackers are a coordinated group operating out of the Middle East. Clues left behind, such as the use of the Persian language, regional usernames, and specific interest in Middle Eastern news—point directly to that region.
The primary goal of this campaign is intelligence gathering and data theft. The attackers designed their software to secretly record keystrokes, capture copied text, and monitor the daily computer activities of their victims.
The operation was highly focused but sustained over a very long period, remaining active for at least six years. Researchers have identified hundreds of malicious files and dozens of websites used to control the operation during that time.
Yes, the attackers specifically targeted government entities, most notably compromising the Ministry of Foreign Affairs of Denmark. They also focused their efforts on individuals reading specific Kurdish news outlets and targets in English- and Persian-speaking countries.
The attackers sent highly convincing emails with trapped presentation files that tricked users into allowing malicious software to run. They also infected a legitimate news website, turning it into a trap that infected visitors who simply browsed the site.
Government agencies and diplomatic offices hold highly sensitive geopolitical, economic, and strategic information. Stealing this data provides a significant intelligence advantage to the attackers or their sponsoring nation.
This is a highly targeted threat rather than a widespread issue affecting the general public. The attackers took careful measures to control who was infected and altered their software to avoid detection by common security tools.
Organizations should train staff to be highly suspicious of unexpected email attachments, especially presentation files that prompt repeated security warnings. Additionally, security teams should ensure computer protections are fully updated and restrict office documents from launching unknown programs.