Nazar APT's Complex Cyber Toolkit: From Keylogging to Passive Backdoors
- Actor Motivations: Espionage,Exfiltration
- Attack Vectors: Backdoor,Dropper,Keylogger,Malware,Spyware
- Attack Complexity: Medium
- Threat Risk: High Impact/Low Probability
Threat Overview
The Nazar APT, active since at least 2010, employs a modular toolkit for cyber espionage. Its main dropper registers multiple DLLs as OLE controls in the Windows registry using 'regsvr32.exe'. It includes a service disguised as 'svchost.exe' for persistence, and uses custom and repurposed libraries for various functionalities like keylogging, audio capture, and screen capture. Nazar's droppers, built with Chilkat's 'Zip2Secure', are often misidentified by antivirus software. A notable feature is EYService, a passive backdoor listening on UDP port '1234', enabling commands like ping response, victim info requests, and file downloads. Additionally, it uses a packet sniffer for potentially sophisticated command-and-control activities. The report, however, does not specify targeted countries or sectors.
Detected Targets
| Type | Description | Confidence |
|---|---|---|
| Region | Iran | Verified |
Extracted IOCs
- 6b3116580d29020b9c259877ac18a7fd
- a9ff31c8db6d4e70829bf5db062d1b9c
- c1ab32afb0e2d7b7b1cad3fb831e9373
- 05122010cde4dcd1b4cd55de7b7d442efda19976
- 48f99144bb9fdf379926e85fbe3caa462089f397
- 79f2b98821c1e2717a0495e6c5c76a0147b21aae
- 0091e2101f00751c4020ef8e115cfe12a284c9abacc886f549b40a62574a7510
- 048208864c793a670159723b38c3ea1474ccc62e06b90833bdf1683b8026e12f
- 0c09fedc5c74f90883cd3256a181d03e4376d13676c1fe266dbd04778a929198
- 1110c3e34b6bbaadc5082fabbdd69f492f3b1480724b879a3df0035ff487fd6f
- 1c02043ca00d087f1aac0337f89bf205985e1f20641bf043c9b7b99e0c9dc002
- 2fe9b76496a9480273357b6d35c012809bfa3ae8976813a7f5f4959402e3fbb6
- 4d0ab3951df93589a874192569cac88f7107f595600e274f52e2b75f68593bca
- 5a924dec60c623cf73f5b8505e11512ad85e62ac571a840ab0ff48d4a04b60de
- 6b8ea9a156d495ec089710710ce3f4b1e19251c1d0e5b2c21bbeeab05e7b331f
- 75e4d73252c753cd8e177820eb261cd72fecd7360cc8ec3feeab7bd129c01ff6
- 839c3e6ba65e5d07a2e0c4dd4a2c0d7ae95a266431dd3f8971b8a37d17b1ddf6
- 8fb9a22b20a338d90c7ceb9424d079a61ca7ccb7f78ffb7d74d2f403ae9fbeec
- 967ac245e8429e3b725463a5c4c42fbdf98385ee6f25254e48b9492df21f2d0b
- c84100d52c09703e32951444bd7ba4e22c5d41193e7420aacbbc1f736f4c4e1f
- d34a996826ea5a028f5b4713c797247913f036ca0063cc4c18d8b04736fa0b65
- d9801b4da1dbc5264e83029abb93e800d3c9971c650ecc2df5f85bcc10c7bd61
- eb705459c2b37fba5747c73ce4870497aa1d4de22c97aaea4af38cdc899b51d3
Tip: 23 related IOCs (0 IP, 0 domain, 0 URL, 0 email, 23 file hash) to this threat have been found.
Overlaps
Source: Checkpoint - May 2020
Detection (16 cases): 0091e2101f00751c4020ef8e115cfe12a284c9abacc886f549b40a62574a7510, 048208864c793a670159723b38c3ea1474ccc62e06b90833bdf1683b8026e12f, 0c09fedc5c74f90883cd3256a181d03e4376d13676c1fe266dbd04778a929198, 1110c3e34b6bbaadc5082fabbdd69f492f3b1480724b879a3df0035ff487fd6f, 2fe9b76496a9480273357b6d35c012809bfa3ae8976813a7f5f4959402e3fbb6, 4d0ab3951df93589a874192569cac88f7107f595600e274f52e2b75f68593bca, 5a924dec60c623cf73f5b8505e11512ad85e62ac571a840ab0ff48d4a04b60de, 6b8ea9a156d495ec089710710ce3f4b1e19251c1d0e5b2c21bbeeab05e7b331f, 75e4d73252c753cd8e177820eb261cd72fecd7360cc8ec3feeab7bd129c01ff6, 839c3e6ba65e5d07a2e0c4dd4a2c0d7ae95a266431dd3f8971b8a37d17b1ddf6, 8fb9a22b20a338d90c7ceb9424d079a61ca7ccb7f78ffb7d74d2f403ae9fbeec, 967ac245e8429e3b725463a5c4c42fbdf98385ee6f25254e48b9492df21f2d0b, c84100d52c09703e32951444bd7ba4e22c5d41193e7420aacbbc1f736f4c4e1f, d34a996826ea5a028f5b4713c797247913f036ca0063cc4c18d8b04736fa0b65, d9801b4da1dbc5264e83029abb93e800d3c9971c650ecc2df5f85bcc10c7bd61, eb705459c2b37fba5747c73ce4870497aa1d4de22c97aaea4af38cdc899b51d3
Source: Malwarelab - April 2020
Detection (one case): 2fe9b76496a9480273357b6d35c012809bfa3ae8976813a7f5f4959402e3fbb6
Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.
FAQs
Demystifying the Nazar Threat
Cybersecurity researchers uncovered a previously unknown cyber espionage campaign from over a decade ago. By re-examining leaked documents from a group known as ShadowBrokers, researchers found a mislabeled file signature that led them to discover a hidden surveillance toolkit.
The exact identity of the attackers is unconfirmed, but researchers named the group "Nazar." Evidence, such as Farsi language artifacts and specific file paths found in the code, suggests the group is Farsi-speaking, potentially operating an internal monitoring operation.
The primary goal of the attack was covert espionage and surveillance. The malicious toolkit was specifically designed to secretly record audio via microphones, take screenshots, log user keystrokes, and monitor network traffic.
The scope of this campaign was highly targeted rather than a mass-infection event. Historical data shows that the infections were clustered almost entirely on specific machines located in Iran.
While the report does not name specific industries, the victims were highly targeted individuals or systems within Iran. These same systems were also being monitored by foreign intelligence agencies, indicating the victims held significant strategic or political value.
Attackers used setup files designed to look like routine updates to drop various surveillance tools onto a victim's computer. These tools then hid themselves by mimicking normal Windows systems and quietly listened for remote commands over the network to steal information.
The targeted entities were attractive because they likely possessed highly sensitive intelligence. The fact that these same computers were targeted by multiple sophisticated intelligence groups highlights their high-value status.
Organizations should ensure their security systems are actively monitoring for unauthorized software services and silent file modifications. Network defenders should also look for unusual network traffic, especially services silently listening for commands on unexpected ports like UDP 1234.
This was a highly targeted, localized issue and does not represent a widespread threat to the general public. It is an older, specialized intelligence-gathering campaign rather than modern, widespread malware like ransomware.