The Espionage Arsenal of Nazar's Backdoor
- Actor Motivations: Espionage,Exfiltration
- Attack Vectors: Keylogger,Malware,Spyware
- Attack Complexity: Medium
- Threat Risk: Unknown
Threat Overview
The Nazar APT's backdoor, showcases a suite of espionage tools used for malicious activities. It employs a passive approach, utilizing the discontinued Packet Sniffer SDK (PSSDK) for communication. Key capabilities include a keylogger that saves data in %WINSYSDIR%\report.txt, system shutdown through an OLE object, screen capture saved in %CWD%\z.png, audio recording saved as %WINSYSDIR%\music.mp3, and enumeration of drives, files, and installed programs with results stored in %WINSYSDIR%. Additionally, it can remove files, list devices, perform a ping operation, and gather OS information. This malware is specifically designed for espionage, indicating a focus on data extraction and system information discovery.
Extracted IOCs
- 2fe9b76496a9480273357b6d35c012809bfa3ae8976813a7f5f4959402e3fbb6
Tip: 1 related IOCs (0 IP, 0 domain, 0 URL, 0 email, 1 file hash) to this threat have been found.
Overlaps
Source: Checkpoint - May 2020
Detection (one case): 2fe9b76496a9480273357b6d35c012809bfa3ae8976813a7f5f4959402e3fbb6
Source: Epicturla - April 2020
Detection (one case): 2fe9b76496a9480273357b6d35c012809bfa3ae8976813a7f5f4959402e3fbb6
Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.
FAQs
The Nazar APT and EYService Backdoor
Cybersecurity researchers recently analyzed a piece of malicious software to understand exactly how it operates. They successfully decoded the specific commands the malware uses, revealing a hidden toolkit designed to quietly spy on and manipulate infected computers.
The malware belongs to a highly capable hacking group known as the Nazar APT. The specific tools used by this group were originally uncovered during a massive 2017 leak of cyber espionage materials, linking them to sophisticated, global hacking operations.
The primary goal of this malware is stealthy surveillance and data theft. The program acts as a hidden backdoor, allowing attackers to secretly record audio, capture screenshots, log what a user types, and create a complete inventory of the files and software on the infected machine.
The provided report focuses on the technical capabilities of the malware rather than identifying specific victims. However, tools of this sophistication are typically deployed by advanced groups to target high-value organizations for espionage purposes.
Attackers planted a hidden "backdoor" program on victim computers that passively listens for remote commands. Once commanded, it uses a series of hidden files to activate the computer's microphone, take pictures of the screen, and record keystrokes, saving all this data into hidden text, audio, and image files to be stolen later.
Groups using deep surveillance tools like this are typically looking to steal sensitive communications, trade secrets, or strategic internal data. Any organization or individual that holds valuable, confidential information would be an attractive target for this type of intelligence-gathering operation.
Organizations should update their security systems to hunt for the specific files and network behaviors associated with this threat. Because the malware uses an outdated piece of software to sniff network traffic, organizations can configure their defenses to flag that specific, unusual network activity.
This appears to be a highly targeted threat rather than a widespread issue affecting everyday consumers. The use of specialized, stealthy tools tied to an advanced persistent threat (APT) group indicates focused espionage campaigns against specific, chosen targets.