HomeCyber BalkansDarkBlinders Hackers Leverage Fake Meeting App to Deploy Backdoor and Steal Government...

DarkBlinders Hackers Leverage Fake Meeting App to Deploy Backdoor and Steal Government Data

Published on

spot_img

DarkBlinders Hackers Utilize Fake Meeting Application in Cyberespionage Campaign Targeting Israel and Iraqi Kurdistan

In a burgeoning cyberespionage campaign, the hacking group known as DarkBlinders has been reported to deploy a fake video meeting application. This operation not only leverages GitHub repositories but specifically aims at targets within Israel and the Kurdistan Region of Iraq. The implications of this initiative are far-reaching, raising serious concerns about cybersecurity in these regions.

According to comprehensive investigations conducted by Dream researchers, the operation was observed between August and October 2026. This investigation confirmed that breaches occurred in a government cloud environment in Kurdistan, as well as targeting a high-profile individual in Israel associated with the security sector. The significance of this attack underlines a troubling trend where state actors and government officials are increasingly becoming cybersecurity targets.

Mechanisms of Attack: Credential Theft and Data Exfiltration

The research team recovered critical tasks related to the operation, which revealed that DarkBlinders was engaged in credential theft, leading to the exfiltration of at least 1 GB of sensitive government cloud data. This data breach provided direct insight into the far-reaching impacts of this campaign.

To execute their nefarious intentions, the hackers utilized various strategies that combine government webmail impersonation along with fraudulent cloud-sharing pages, all while deploying an application named StarkMeet, which serves as a decoy meeting client. An elaborate phishing infrastructure mimicked the online presence of credible entities, such as Kuwait’s Ministry of Foreign Affairs and the Gulf Cooperation Council Secretariat General. This indicates a broader interest in diplomatic targets that go beyond the two identified victims, highlighting the campaign’s strategic scope.

Technical Components: StarkMeet and Malware Infiltration

StarkMeet’s unsigned Inno Setup installer masquerades as a legitimate application, displaying an interface that seemingly allows users to engage in virtual meetings. However, attempts to join an actual meeting reliably trigger a fixed connection error, a tactic likely designed to keep users engaged while their devices are compromised.

Although the researchers did not retrieve the original delivery message, the method of distribution remains a matter of speculation. Nevertheless, the installer deposits malicious components under the directory %LOCALAPPDATA%\Microsoft\RuntimeBroker, effectively concealing its presence from users. This sophisticated arrangement allows the malware to persist even after StarkMeet is uninstalled.

In a technical twist, a legitimate Microsoft executable named vshost.exe is renamed to RuntimeBroker.exe, which subsequently loads RuntimeBroker.dll using an AppDomainManager mechanism—further complicating detection efforts. The use of the MicrosoftRuntime value in the current user’s Windows registry ensures ongoing persistence, while a GitHub token embedded within the malware establishes a connection to a repository named PeakyBlindersTeam/myLic.

This repository collects significant information, including usernames, machine names, domains, and the status of anti-analysis measures. Such detailed reports enable the hackers to assess potential targets before advancing to subsequent stages of their attack.

Targeting and Selective Activation

Dreamgroup’s researchers noted that while approximately ten systems were initially registered, only two victims were reported within the secondary tasking repository. This finding suggests that the attackers employ a selective activation strategy rather than deploying their efforts indiscriminately. Such a method enhances their stealth and effectiveness, making it harder for victims to mount a timely response.

In select cases, operators provided licensing material, with the SHA-256 hash serving as an AES-256-CBC key to decrypt additional malicious components like RuntimeBrokerApi.dll. This layering of tactics showcases a sophisticated approach to cybersecurity, hinting that operators are prepared to adapt their methods in real time.

The backdoor functionality corresponds with a polling mechanism tied to a separate repository named myCode, checking in every 63 seconds. Utilizing an embedded PsProxy.dll, the malware executes PowerShell commands through its internal runspace, further reducing the likelihood of detection.

DarkBlinders has even incorporated a fallback mechanism, allowing it to retrieve GitHub credentials from specially formatted comments, which serves as a means for restoring communications in the event of token revocation.

Attribution and Broader Implications

Researchers have linked this operation to several prior waves of cyberattacks and assessed a medium-to-high confidence level regarding its overlap with known threat actor groups UNC5795 and Dust Specter. Some contextual evidence links this campaign to UNC5187 and possibly to APT34 as well. Notably, indications such as Persian keyboard metadata and Iranian hosting associations provide additional context; however, they do not alone establish definitive attribution or identify specific operators.

The alarming nature of this cyberespionage operation serves as a critical reminder of the vulnerabilities that modern digital infrastructures face. As states and organizations continue to transition toward cloud-based services, the threats posed by groups like DarkBlinders underscore the necessity for robust cybersecurity measures and an ongoing commitment to securing sensitive government data. The implications stretch beyond mere cybersecurity incidents, ultimately impacting diplomatic relationships and national security.

Source link

Latest articles

Midnight Mimosa Malware for Budget Android Devices

Widespread Malware Campaign "Midnight Mimosa" Targets Budget Android Smartphones Recent revelations by security researchers have...

IDC Frontier Ransomware Attack Disrupts 495 Customers

Cyberattack on IDC Frontier Disrupts Services for Nearly 500 Customers On October 7, IDC Frontier...

Iranian VPN-over-DNS Activity Produces 40 Billion DNS Observations Amid Military Conflict

Surge in Suspected Iranian VPN-over-DNS Activity Generates Unprecedented Data Observations A recent investigation has revealed...

When Everything Seems Normal: Why Context, Not More Alerts, is the Next Frontier for Security Operations

The Evolving Landscape of Security Awareness: Beyond the Surface In an ever-evolving cybersecurity landscape, security...

More like this

Midnight Mimosa Malware for Budget Android Devices

Widespread Malware Campaign "Midnight Mimosa" Targets Budget Android Smartphones Recent revelations by security researchers have...

IDC Frontier Ransomware Attack Disrupts 495 Customers

Cyberattack on IDC Frontier Disrupts Services for Nearly 500 Customers On October 7, IDC Frontier...

Iranian VPN-over-DNS Activity Produces 40 Billion DNS Observations Amid Military Conflict

Surge in Suspected Iranian VPN-over-DNS Activity Generates Unprecedented Data Observations A recent investigation has revealed...