The new computer could be infected before the first entry of the employee and the installation of the antivirus. The spy group GOFFEE has built backdoors into the corporate ISO-images of Windows, and in the internal storage of the Russian company replaced the executable files 7-Zip and Git. A rare scheme of long-term consolidation was revealed by specialists of the Laboratory of Digital Forensics and Research of malicious code F6.
F6 has been tracking the activity of GOFFEE, also known as Paper Werewolf, since 2022. The group attacks Russian state institutions and organizations from the spheres of VPC, IT, logistics, media, telecommunications, construction, energy, education, industry, tourism and finance. The main goal of the campaigns remains cyber espionage, and the characteristic feature is the desire to maintain inconspicuous access to the victim's infrastructure for as long as possible.
By the beginning of the investigation, the attackers had long controlled many devices, knew the architecture of the network well and had high privileges. GOFFEE used its own development tools, including public project-based solutions, and complicated the analysis through obfuscation. The attackers also used various techniques to counter forensic analysis.
GOFFEE's initial access was obtained through phishing emails with malicious archives and bait documents. The mailing lists were masked under reports from state structures, contractors and counterparties. In the investigated attack, the group loaded the QwakMyAgent agent from the controlled domains through the staff component of Windows mshta.exe. The backdoor provided full control over the computer and allowed additional tools to be delivered.
At first, malicious files were placed on the temporary storage services of BashUpload, DropMeFiles and GoFile. GOFFEE then switched to its own resources, and later began to deliver the tools through the installed backdoors. Infected local network devices were also turned into command servers. The approach reduced the number of computers directly accessing the group's external infrastructure and helped to hide malicious traffic among conventional network connections.
During the development of the attack on the GOFFEE network, copies of CMD and PowerShell, PsExec, Windows printing service vulnerability, as well as RDP, SSH and WinRM connections were used. Built-in utilities sc.exe, reg.exe, curl.exe and certutil.exe helped to manage malicious services, modify the registry and download files. To automatically start backdoors, the attackers created system services and used uncommon parameters of the AutodialDLL, Print\Monitors and Command Processor\AutoRun registry.
The modified versions of 7-Zip and Git retained their original functionality and did not cause obvious suspicion. Employees independently downloaded programs from trusted corporate storage and launched malicious code. The 7-Zip archive allowed to cover a wide range of users, and Git was designed primarily for developers and employees of the IT service.
The attackers changed three installation images of different versions of Windows. In each image, GOFFEE added a backdoor WFS.exe and a script to SetupComplete.cmd. When installing Windows, the files were copied to the computer, after which the script created a system service to run the malware. The backdoor started working until the first user login and installing security solutions. The choice of different images allowed the infection of servers and workstations, including the newly deployed domain controllers and backup servers.
GOFFEE collected credentials from the memory of the lsass.exe process and regularly copied the Active Directory NTDS.dit database. In the services based on Bitrix, the attackers implemented a module that secretly recorded logins and passwords entered during authorization. At the workstations, the group searched for Telegram and stole the service directory of the messenger, gaining access to personal correspondence and corporate chats of IT specialists.
The attackers closely followed the actions of the administrators. After launching the legitimate PCENableAdvancedAudit.cmd scenario, for GOFFEE logging configuration, borrowed the file name and run method to distribute the new backdoor. The malicious task of the CryptSvc planner looked like part of the normal work of the IT service. The files also copied the names and descriptions of legitimate services, received timestamps of neighboring components and were hidden in the directories of application programs. To destroy the traces, the group cleared the Prefetch directory, where Windows stores information about running applications.
On key devices GOFFEE placed several backdoors with different start-up mechanisms. F6 detected the remote access agent lonelymine, SSH backdoors ElfDoor, BindSycler and SWATSSHD, Mythic agents, and the modified Neo-reGeorg tunnel. The distributed domain network allowed you to assign a separate command server to most malware. The stolen information was transmitted through backdoors, the rclone utility and the Mega cloud storage.
According to F6, insufficient attention to the first suspicious events allowed GOFFEE to gain a foothold in the infrastructure for a long time. After a strong consolidation in the infrastructure of conventional monitoring is no longer sufficient. To identify hidden backdoors, companies require constant telemetry collection, regular analysis of anomalies, and proactive threat search.
F6 has been tracking the activity of GOFFEE, also known as Paper Werewolf, since 2022. The group attacks Russian state institutions and organizations from the spheres of VPC, IT, logistics, media, telecommunications, construction, energy, education, industry, tourism and finance. The main goal of the campaigns remains cyber espionage, and the characteristic feature is the desire to maintain inconspicuous access to the victim's infrastructure for as long as possible.
By the beginning of the investigation, the attackers had long controlled many devices, knew the architecture of the network well and had high privileges. GOFFEE used its own development tools, including public project-based solutions, and complicated the analysis through obfuscation. The attackers also used various techniques to counter forensic analysis.
GOFFEE's initial access was obtained through phishing emails with malicious archives and bait documents. The mailing lists were masked under reports from state structures, contractors and counterparties. In the investigated attack, the group loaded the QwakMyAgent agent from the controlled domains through the staff component of Windows mshta.exe. The backdoor provided full control over the computer and allowed additional tools to be delivered.
At first, malicious files were placed on the temporary storage services of BashUpload, DropMeFiles and GoFile. GOFFEE then switched to its own resources, and later began to deliver the tools through the installed backdoors. Infected local network devices were also turned into command servers. The approach reduced the number of computers directly accessing the group's external infrastructure and helped to hide malicious traffic among conventional network connections.
During the development of the attack on the GOFFEE network, copies of CMD and PowerShell, PsExec, Windows printing service vulnerability, as well as RDP, SSH and WinRM connections were used. Built-in utilities sc.exe, reg.exe, curl.exe and certutil.exe helped to manage malicious services, modify the registry and download files. To automatically start backdoors, the attackers created system services and used uncommon parameters of the AutodialDLL, Print\Monitors and Command Processor\AutoRun registry.
The modified versions of 7-Zip and Git retained their original functionality and did not cause obvious suspicion. Employees independently downloaded programs from trusted corporate storage and launched malicious code. The 7-Zip archive allowed to cover a wide range of users, and Git was designed primarily for developers and employees of the IT service.
The attackers changed three installation images of different versions of Windows. In each image, GOFFEE added a backdoor WFS.exe and a script to SetupComplete.cmd. When installing Windows, the files were copied to the computer, after which the script created a system service to run the malware. The backdoor started working until the first user login and installing security solutions. The choice of different images allowed the infection of servers and workstations, including the newly deployed domain controllers and backup servers.
GOFFEE collected credentials from the memory of the lsass.exe process and regularly copied the Active Directory NTDS.dit database. In the services based on Bitrix, the attackers implemented a module that secretly recorded logins and passwords entered during authorization. At the workstations, the group searched for Telegram and stole the service directory of the messenger, gaining access to personal correspondence and corporate chats of IT specialists.
The attackers closely followed the actions of the administrators. After launching the legitimate PCENableAdvancedAudit.cmd scenario, for GOFFEE logging configuration, borrowed the file name and run method to distribute the new backdoor. The malicious task of the CryptSvc planner looked like part of the normal work of the IT service. The files also copied the names and descriptions of legitimate services, received timestamps of neighboring components and were hidden in the directories of application programs. To destroy the traces, the group cleared the Prefetch directory, where Windows stores information about running applications.
On key devices GOFFEE placed several backdoors with different start-up mechanisms. F6 detected the remote access agent lonelymine, SSH backdoors ElfDoor, BindSycler and SWATSSHD, Mythic agents, and the modified Neo-reGeorg tunnel. The distributed domain network allowed you to assign a separate command server to most malware. The stolen information was transmitted through backdoors, the rclone utility and the Mega cloud storage.
According to F6, insufficient attention to the first suspicious events allowed GOFFEE to gain a foothold in the infrastructure for a long time. After a strong consolidation in the infrastructure of conventional monitoring is no longer sufficient. To identify hidden backdoors, companies require constant telemetry collection, regular analysis of anomalies, and proactive threat search.