“TA453 Targets Religious Figure with Fake Podcast Invite to Deliver New BlackSmith Malware Toolset”

Proofpoint details TA453’s targeting of a prominent religious figure via a fake podcast invitation, introducing a new BlackSmith malware toolkit that includes the AnvilEcho PowerShell trojan for intelligence gathering and exfiltration. The operation consolidates TA453’s capabilities into a single script and relies on social engineering and IRGC-aligned infrastructure to enable persistence and data exfiltration.
#TA453 #BlackSmith #AnvilEcho #IRGC #InstituteForTheStudyOfWar

Keypoints

  • TA453 impersonated the Institute for the Study of War to lure a prominent religious figure.
  • The attack began with benign email interactions to build trust before delivering malicious content.
  • BlackSmith toolkit was delivered via a ZIP file containing a malicious LNK file.
  • AnvilEcho, the PowerShell trojan, consolidates previous malware capabilities into a single script.
  • The malware employs encryption, obfuscation, and complex techniques to evade detection and facilitate intelligence collection.
  • TA453’s activities align with Iranian government interests, particularly the IRGC.

MITRE Techniques

  • [T1566] Phishing – TA453 used a fake podcast invitation to lure the target into clicking malicious links. Quote: β€˜TA453 used a fake podcast invitation to lure the target into clicking malicious links.’
  • [T1086] PowerShell – AnvilEcho is a PowerShell trojan designed for intelligence gathering and exfiltration. Quote: β€˜AnvilEcho is a PowerShell trojan designed for intelligence gathering and exfiltration.’
  • [T1071] Command and Control – Utilized domains like deepspaceocean.info for command and control communications. Quote: β€˜Utilized domains like deepspaceocean.info for command and control communications.’
  • [T1027] Obfuscated Files or Information – Malware uses obfuscation techniques to evade detection, such as hiding payloads in images. Quote: β€˜Malware uses obfuscation techniques to evade detection, such as hiding payloads in images.’
  • [T1003] Credential Dumping – Attempts to gather system information, including antivirus details and user credentials. Quote: β€˜Attempts to gather system information, including antivirus details and user credentials.’

Indicators of Compromise

  • [SHA256] LNK and ZIP hashes – 5dca88f08b586a51677ff6d900234a1568f4474bbbfef258d59d73ca4532dcaf, 5aee738121093866404827e1db43c8e1a7882291afedfe90314ec90b198afb36
  • [File name] Podcast Plan 2024.lnk – LNK file delivering the BlackSmith toolset
  • [File name] Podcast Plan-2024.zip – ZIP archive containing malicious components
  • [Domain] understandingthewar.org – Lure domain used in the phishing chain
  • [Domain] deepspaceocean.info – C2 domain referenced for communications
  • [Domain] d75.site – Storage/decoy domain used in the chain
  • [IP] 54.39.143.120 – C2 hosting infrastructure
  • [IP] 54.39.143.117 – Co-hosted TA453 infrastructure
  • [File name] Beautifull.jpg – Decoy image carrying steganographic payload
  • [File name] mary.dll – Helper/delivery component used by BlackSmith
  • [File name] qemus – AnvilEcho payload (encrypted) referenced in the chain
  • [File name] soshi.dll – Installer component used by BlackSmith
  • [File name] toni.dll – Service for persistence

Read more: https://www.proofpoint.com/us/blog/threat-insight/best-laid-plans-ta453-targets-religious-figure-fake-podcast-invite-delivering