Malware Discovered After Residing On The Aviation Sector Unnoticed For 2 Years

The aviation industry is among the marvels of the sky. The industry is worth billions of dollars, has endless list of consumers that are always more than eager to fly, and among the driving gear of the world's economy.

But in terms of cybersecurity, the sector is certainly not the best.

It was discovered that a phishing campaign aimed at the aviation industry may be initiated by a threat actor from Nigeria. This campaign has been going on unnoticed for two years, carrying out small-scale cyberattacks for extended periods of time.

Cisco Talos that discovered it, dubbed the malware attack the "Operation Layover."

"The actor […] doesn't seem to be technically sophisticated, using off-the-shelf malware since the beginning of its activities without developing its own malware," researchers Tiago Pereira and Vitor Ventura wrote in a blog post.

"The actor also buys the crypters that allow the usage of such malware without being detected, throughout the years it has used several different cryptors, mostly bought on online forums."

Aviation RAT
Credit: Cisco Talos

The threat actor is believed to have been active at least since 2013.

They have been launching attacks through emails in order to lure potential victims into opening a link to a VBScript (.vbs ) file hosted on Google Drive. The emails are purposefully crafted using documents centered on the aviation industry, as well as the cargo industry. The document masks itself as a PDF file.

The malicious document, according to Talos' findings, was first seen on December 13, 2019.

When successfully infected a machine, the malware can download multiple RATs (Remote Access Trojans).

"Many actors can have limited technical knowledge but still be able to operate RATs or information-stealers, posing a significant risk to large corporations given the right conditions," the researchers said. "In this case, […] what seemed like a simple campaign is, in fact, a continuous operation that has been active for three years, targeting an entire industry with off-the-shelf malware disguised with different crypters."

The oldest malware sample referring to this campaign's hostname was first seen on September 24, 2016, and was a simple batch file that is part of a malware chain that drops multiple files.

The team at Talos made their discovery following a Microsoft Security Intelligence's research that said a "dynamic campaign targeting the aerospace and travel sectors with spear-phishing emails that distribute an actively developed loader, which then delivers RevengeRAT or AsyncRAT."

[block:block=87]

"Our researchers looked at the domain Microsoft Security Intelligence mentioned, kimjoy[.]ddns[.]net," explained Talos.

In conclusion, the aviation industry may not be the best in protecting its cyber assets.

But the hackers here were also using off-the-shelf malware since the beginning of its activities, either because they think it's no use of using more sophisticated malware, or because of their limited technical knowledge.

However, since the conditions allowed them to, the threat actors managed to remain unnoticed for years.

"These kinds of small operations tend to fly under the radar and even after exposure the actors behind them wont stop their activity. They abandon the C2 hostnames — which in this case are free DNS-based and they may change the crypter and initial vector, but they won't stop their activity. The black market for web cookies, tokens and valid credentials is way too valuable when compared with the economy in their home countries for them to stop," the post continued.