Rewterz Threat Alert – ZeroCleare Malware Debuts in Middle East Targeting Energy Sector

Thursday, January 9, 2020

Severity

High

Analysis Summary

An overlapping attack activity carried by ITG013 (also known as “APT34” or “Oilrig”) and an unknown, probably Iranian cyber group targeting the energy sector in the Middle East. Further, it is assessed that access to at least one targeted environment was used to conduct a destructive attack using newly identified disk wiper malware, ZeroCleare. The attack timeline may have begun as early as Autumn of 2018 with reconnaissance scanning from various low cost/free VPN providers and gaining access to one of the accounts that was later involved in the attack. Then, in the Summer of 2019, the attackers used a password spray from a system on the local network to gain access to additional accounts, install ASPX webshells, and gain domain administration privileges. Finally, unknown actors spread a destructive wiper ZeroCleare across the target network and executed it. The ZeroCleare disk wiper malware had both x86 and x64 versions to execute across 32-bit and 64-bit operating systems. Interestingly, this malware incorporated the Eldos RawDisk driver, which was previously used in each of the Shamoon attacks, reportedly perpetrated by Iranian-linked threat actors.

Impact

Wipe out data from the infected host

Indicators of Compromise

IP

193[.]111[.]152[.]13

MD5

  • 33f98b613b331b49e272512274669844
  • 69b0cec55e4df899e649fa00c2979661
  • 1a69a02b0cd10b1764521fec4b7376c9
  • 993e9cb95301126debdea7dd66b9e121
  • 1ef610b1f9646063f96ad880aad9569d
  • eaea9ccb40c82af8f3867cd0f4dd5e9d

Remediation

  • Block all threat indicators at your respective controls.
  • Always be suspicious about emails sent by unknown senders.
  • Never click on the links/attachments sent by unknown senders.

Data Sheets

Corporate Brochure


Our Story


Services


Solutions


Managed Security


Upcoming Rewterz Trainings/Events

Rewterz News

  • 10, January 2020 Rewterz Threat Advisory – CVE-2020-1600 – Juniper Networks Junos OS Denial of Service in the RPD daemon
  • 10, January 2020 Rewterz Threat Alert – Bank of America Phishing Campaign
  • 10, January 2020 Rewterz Threat Alert – LiquorBot Botnet
  • 10, January 2020 Rewterz Threat Advisory – CVE-2019-16005 – Cisco Webex Video Mesh Node Command Injection Vulnerability

Copyright © Rewterz. All rights reserved.