News

Discovered complex backdoor that group of cybercriminals Turla uses since 2014

ESET specialists discovered in the Turla arsenal new powerful instrument that hackers managed to hide for five years, at least since 2014.

Backdoor named LightNeuron compromises Microsoft mailing servers and functions as mail transfer agent, (MTA) that is not typical for such malware.

Researchers note, that, according to their data, LightNeuron is a fisrt backdoor that is specially orientated on Microsoft Exchange. Earlier Turla applied Neuron malware (aka DarkNeuron), that has nothing similar with LightNeuron and was developed with the focus on Microsoft Exchange.

LightNeuron Transport Agent

LightNeuron not just allows attackers to trace events on mailing server, but to integrate in its work and control virtually anything.

“In architecture of mailing server, backdoor can work on same level of trust, as security products, as spam filters. Consequently, this malware gives cybercriminals full control over mailing server, and, by this, on all letters”, – explain ESET specialists.

Hackers can intercept and redirect all mails, edit content of sent and inbox messages or block receiving some mails for users. All these opportunities make LigthNeuron one of the most powerful tools in group’s arsenal.

In addition, backdoor differs as it uses one peculiar C&C mechanism. The case is that attackers never connected Microsoft servers directly.

Instead, they use steganography and mails with attached PDF and JPG files. Inside these letters hackers from LightNeuron team hide commands for LightnNeuron that malware opens and performs. This way of communication with malware significantly complicates its detection, as commands for backdoor might come with ordinary spam that no one pays attention to and does not trace as filters weed it out.

Modified JPG picture with embedded commands for LightNeuron

As reported, LightNeuron is used for attacks until now. ESET experts have already identified three organizations that suffered from it. Analysts not disclose their names, but report that it is some of the Brazilian structures, Ministry of Foreign Affair from Easter Europe and one regional diplomatic organization on the Middle East.

Source: https://www.welivesecurity.com

Polina Lisovskaya

I works as a marketing manager for years now and loves searching for interesting topics for you

Recent Posts

Remove Janorfeb.xyz Pop-up Ads

About Janorfeb.xyz Janorfeb.xyz pop-ups can not open out of nowhere. If you have clicked on…

12 hours ago

Remove Re-captha-version-3-263.buzz Pop-up Ads

About Re-captha-version-3-263.buzz Re-captha-version-3-263.buzz pop-ups can not launch out of the blue. If you have actually…

12 hours ago

Remove Usavserver.com Pop-up Ads

About Usavserver.com Usavserver.com pop-ups can not expose out of the blue. If you have clicked…

12 hours ago

Remove Yourgiardiablog.com Pop-up Ads

About Yourgiardiablog.com Yourgiardiablog.com pop-ups can not expose out of the blue. If you have actually…

12 hours ago

Remove Bihanrit.xyz Pop-up Ads

About Bihanrit.xyz Bihanrit.xyz pop-ups can not launch out of nowhere. If you have actually clicked…

12 hours ago

Remove Thenetaservices.com Pop-up Ads

About Thenetaservices.com Thenetaservices.com pop-ups can not introduce out of the blue. If you have actually…

1 day ago