Campaigns abusing corporate trusted infrastructure hunt for corporate credentials on ICS networks | Kaspersky ICS CERT

Anomalous, short-lived spyware campaigns targeted ICS environments, spreading via compromised corporate mailboxes and SMTP-based C2 to harvest credentials. The report reveals thousands of abused corporate email accounts, extensive credential marketplaces, and a pattern of expanding attacks through partner networks. Hashtags: #OriginLogger #AgentTesla #HawkEye #SnakeKeylogger #Azorult #Lokibot

Keypoints

  • Anomalous spyware samples in H1 2021 had limited scope (fewer than 100 machines) and short lifespans (about 25 days), yet accounted for a large share of spyware activity.
  • Most anomalous samples used SMTP-based C2 as a one-way channel, unlike the broader spyware which used FTP/HTTP(s).
  • Threat actors abused corporate email systems to propagate attacks via compromised mailboxes and contact lists, spreading from one industrial enterprise to its partners.
  • Over 2,000 corporate email accounts belonging to industrial companies were abused as C2s, with more than 7,000 credentials stolen overall.
  • Attackers pursued multiple credential targets (banking/financial services, social networks, and corporate network access services such as SMTP/SSH/RDP/VPN).
  • A market ecosystem exists where stolen credentials and access to industrial networks are bought and sold across 25+ marketplaces, with RDP accounts among the most sought after.
  • The study notes regional patterns (Asia/Europe/North America) and potential operator ties to African, Russian, and Turkish-speaking groups, inferred from timelines and locale analyses.
  • Recommended defenses emphasize 2FA, updated endpoint protection, email hygiene, spam folder checks, sandboxing, and testing attachments outbound as well as inbound.

MITRE Techniques

  • [T1071.003] SMTP – C2 over SMTP used as a one-way channel for theft-focused communication; “majority of anomalous samples were configured to connect to a server owned by some victim industrial enterprise” via SMTP-based C2s.
    ‘…majority of “anomalous” samples were configured to connect to a server owned by some victim industrial enterprise.’
  • [T1566] Phishing – Attacks spread via hard-to-detect phishing emails disguised as the victim organizations’ correspondence and abusing corporate email systems to attack through compromised mailboxes.
    ‘…spreading from one industrial enterprise to another via hard-to-detect phishing emails disguised as the victim organizations’ correspondence and abusing their corporate email systems to attack through the contact lists of compromised mailboxes.’
  • [T1027.001] Obfuscated/Compressed Files and Information – Malware hides binary code in application resources (e.g., encoding into images using RGBA channels).
    ‘…encoding a binary into an image using RGBA (Red, Green, Blue, and Alpha channels) to store bytes.’
  • [T1078] Valid Accounts – Credentials stolen and abused to gain access and propagate attacks; widespread use of compromised corporate accounts as C2 and for credential theft.
    ‘We identified over 2,000 abused (i.e., used as C2s by spyware) email accounts… credentials were stolen…’

Indicators of Compromise

  • [IPv4 Address] Infrastructure IPs – 105.112.101.7, 105.112.102.213, and other IPs listed in Appendix I – Indicators of compromise

Read more: https://ics-cert.kaspersky.com/publications/reports/2022/1/19/campaigns-abusing-corporate-trusted-infrastructure-hunt-for-corporate-credentials-on-ics-networks/