Greenbug's Cyber Espionage Campaign Against South Asian Telecoms
- Actor Motivations: Espionage
- Attack Vectors: Backdoor,Downloader,Trojan,Phishing,Spear Phishing
- Attack Complexity: Medium
- Threat Risk: High Impact/High Probability
Threat Overview
The Greenbug espionage group is conducting an information-gathering campaign against telecommunications companies in South Asia. Using a mix of off-the-shelf tools and living-off-the-land techniques, the group primarily employs email as the initial infection vector. Notable files used for infection are proposal_pakistan110.chm:error.html and GRUNTStager.hta, often delivered through compromised websites via spearphishing. The group aims to gain access to database servers, leveraging tools like Covenant and custom malware like Trojan.Ismdoor. They have been observed using various PowerShell commands, Mimikatz, and Cobalt Strike, alongside multiple webshells. Living-off-the-land utilities such as Plink and Bitvise were used to establish tunnels back to attacker-controlled infrastructure.
Detected Targets
| Type | Description | Confidence |
|---|---|---|
| Sector | Telecommunication | Verified |
Extracted IOCs
- kopilkaorukov[.]com
- vsiegru[.]com
- apps.vvvnews[.]com
- 0644b3ffc856eb54b53338ab8ecd22dd005ee5aacfe321f4e61b763a93f82aea
- 069a29a0642ea5e2034250f5465cb2230edf1b49ad42d16ff4cddfee1f693314
- 071e20a982ea6b8f9d482685010be7aaf036401ea45e2977aca867cedcdb0217
- 16e1e886576d0c70af0f96e3ccedfd2e72b8b7640f817c08a82b95ff5d4b1218
- 2a3f36c849d9fbfe510c00ac4aca1750452cd8f6d8b1bc234d22bc0c40ea1613
- 3c6bc3294a0b4b6e95f747ec847660ce22c5c4eee2681d02cc63f2a88d2d0b86
- 450ebd66ba67bb46bf18d122823ff07ef4a7b11afe63b6f269aec9236a1790cd
- 471dadfe16cf2cf82566d404d2b7d1baf66b72c385ae272dcc743a285113e280
- 4c7813a1f3eb5d5d8b8a1e53af074c96cfc6ddb14b21188fd84970f001bfc0ff
- 53bbc9ebe40725bd74ebf29616f48a8aed0a544dd0e4f40801ac1b522f2cf32f
- 6cb51c7011f27418c772124d4433350a534061f5732c1331f5483d62b42402f7
- 75cee6136011516dfe7bd9e45b25c2cf5d9af149a81fff0b8b3ab157a8cbf321
- 9809aeb6fd388db9ba60843d5a8489fea268ba30e3935cb142ed914d49c79ac5
- 9bf8121e0f3461412dde107c4d1ceb2ed18ec0741f458956830e038fd1be6d44
- 9de28b94aa3f1a849221cf74224554b41a77473c694cadf3f2526ab06480eb85
- abb3ddc945d147a4ed435b71490764bc4a2860f4ad264052f407357911bd6746
- b51eca570abad9341a08ae4d153d2c64827db876ee0491eb941d7e9a48d43554
- b8797931ad99b983239980359ef0ae132615ebedbf6fcb0c0e9979404b4a02a8
- e974237c32f5d28019c5328bd022469236da87eecee19487902133aea89432a0
- ece23612029589623e0ae27da942440a9b0a9cd4f9681ec866613e64a247969d
- ee32bde60d1175709fde6869daf9c63cd3227155e37f06d45a27a2f45818a3dc
- f577fc8f22b6eec782dbcbe54f5a8f3b00e8e6d8dc7aa94b2fffcc2b7ce09c6a
- faba07425c1fa65a9a68a17b99e83663a2a32fbb2a7c3df347b7a7411a7058bc
- fc002268620fa67ffe260ea9f3a6bbad8637f9bef8ae85b8d6061cec0390b9e2
- fd95ffb7c70f828ef021e7dbdaf852f54f385095e7f58607f093096b68f40a32
- 185[.]205.210.46
- 185[.]243.114.247
- 185[.]243.115.69
- 95[.]179.177.157
Tip: 32 related IOCs (4 IP, 3 domain, 0 URL, 0 email, 25 file hash) to this threat have been found.
Overlaps
Source: Palo Alto Networks - July 2020
Detection (three cases): ee32bde60d1175709fde6869daf9c63cd3227155e37f06d45a27a2f45818a3dc, apps.vvvnews[.]com, kopilkaorukov[.]com
Source: Palo Alto Networks - September 2017
Detection (one case): 450ebd66ba67bb46bf18d122823ff07ef4a7b11afe63b6f269aec9236a1790cd
Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.
FAQs
Greenbug Cyber Attacks on South Asian Telecoms
Hackers successfully breached the computer networks of multiple telecommunications companies. Once inside, they remained hidden for months, quietly navigating the networks to steal passwords and gather sensitive information.
The attack was carried out by an espionage group known as "Greenbug." This group has a history of conducting cyber espionage and is known for using custom malware alongside everyday computer administration tools to avoid being caught.
The primary goal of this campaign was information gathering. Specifically, the attackers focused on stealing user credentials so they could log in to the organizations' central database servers and test their access.
The campaign targeted multiple telecommunications organizations across South Asia. In one documented case, the attackers maintained a presence on a victim's network for at least six months, from October 2019 to April 2020.
Yes, the attackers specifically went after companies in the telecommunications sector. Inside those companies, they explicitly targeted database servers and the sensitive records stored within them.
The hackers likely started by sending deceptive emails containing fake "proposal" documents that were actually malicious files. Once an employee opened the file, the hackers gained a foothold and used built-in Windows tools to secretly download more hacking software, steal passwords, and create hidden tunnels to control the network from the outside.
Telecommunications companies manage vast databases. The hackers were specifically trying to reach the database servers, which are highly attractive targets because they centralize a massive amount of valuable organizational information.
Organizations should be highly suspicious of unexpected email attachments, especially those claiming to have an "error" opening. Companies need to monitor their networks for the unauthorized use of normal administrative tools, secure their administrative passwords, and closely watch all traffic attempting to reach their sensitive database servers.
This is a highly targeted espionage campaign. Rather than trying to infect as many people as possible, the Greenbug group focused their efforts and custom techniques specifically on a select group of telecommunications providers in South Asia.