Operation Rusty Flag – A Malicious Campaign Against Azerbaijanian Targets | Deep Instinct

Deep Instinct Threat Lab uncovered a Rust-based malware campaign targeting Azerbaijanian targets, delivered through multiple initial access vectors and featuring novel Rust implants. The operation appears not to be linked to any known actor and includes a false-flag element tying it to the Storm-0978 campaign, with MSI dropper activity hosted on Dropbox. #Rust #RustImplant #Storm0978 #Azerbaijan #LNKVector #OfficeVector #Dropbox #MSIWrapper

Keypoints

  • The Deep Instinct Threat Lab uncovered a Rust-based operation targeting Azerbaijanian targets.
  • The campaign uses at least two initial access vectors: a malicious LNK file and an Office document vector.
  • The Rust implant is delivered via MSI installers hosted on Dropbox, with an XML for a scheduled task and a decoy file.
  • A modified document lure previously used by Storm-0978 is identified as a potential false flag in this operation.
  • The Rust implant sleeps for 12 minutes to hinder analysis, then collects system information and exfiltrates data over a hardcoded port 35667.
  • The campaign is not attributed to a known threat actor, and it demonstrates Rust malware’s evasion and stealth capabilities.

MITRE Techniques

  • [T1082] System Information Discovery – The malware executes systeminfo.exe to gain information about the infected computer. (‘The malware executes systeminfo.exe to gain information about the infected computer’)
  • [T1016] System Network Configuration Discovery – Gain detailed information about the network interfaces on the system. (‘Gain detailed information about the network interfaces on the system’)
  • [T1033] System Owner/User Discovery – Gain user, group, and privileges information for the users. (‘Gain user, group, and privileges information for the users’)
  • [T1087] Account Discovery – Gain information about local or domain accounts on a system. (‘Gain information about local or domain accounts on a system’)
  • [T1057] Process Discovery – Gain a list of currently running processes, including detailed information about each one. (‘Gain a list of currently running processes, including detailed information about each one’)
  • [T1053] Scheduled Task/Job – Create a scheduled task using the xml file. (‘Create a scheduled task using the xml file’)
  • [T1132] Data Encoding – Encrypted communication. (‘Encrypted information sent to the C2. A tool for decrypting the information is provided in our Git.’)

Indicators of Compromise

  • [IP] 78.135.73[.]140 – Observed as the attacker/C2-related address associated with the campaign
  • [SHA256] 463183002d558ec6f4f12475cc81ac2cb8da21549959f587e0fb93bd3353e13e – Archive containing malicious Office file
  • [SHA256] edc531d255b9ae8ae6902dc676f24e95a478576cad297e08e2bbc0b8fe03e4ce – Malicious Office file
  • [SHA256] 1546bb5bfc25741434148b77fe51fed7618432a232049b3f6f7210e7fb1f3f0e – MSI file from hxxps://t[.]ly/8CYQW
  • [SHA256] 387304b50852736281a29d00ed2d8cdb3368d171215f1099b41c404e7e099193 – SangforUD.EXE Rust implant
  • [SHA256] 0742cd9b92661f23f6b294cc29c814de027b5b64b045e4807fc03123b153bcd5 – Decoy PDF file
  • [SHA256] 04725fb5a9e878d68e03176364f3b1057a5c54cca06ec988013a508d6bb29b42 – Malicious LNK file
  • [SHA256] 35f2f7cd7945f43d9692b6ea39d82c4fc9b86709b18164ad295ce66ac20fd8e5 – MSI file from LNK vector
  • [SHA256] 5327308fee51fc6bb95996c4185c4cfcbac580b747d79363c7cf66505f3ff6db – WinDefenderHealth.EXE Rust implant
  • [SHA256] e508cafa5c45847ecea35539e836dc9370699d21522839342c3f3573bf550555 – Decoy JPEG file

Read more: https://www.deepinstinct.com/blog/operation-rusty-flag-a-malicious-campaign-against-azerbaijanian-targets