DEV-0139
2022-12-06 • Microsoft • DEV-0139 launches targeted attacks against the cr…
Microsoft tracked DEV-0139 as a temporary designation for an emerging cluster of threat activity, its convention for tracking an unknown or developing actor until enough evidence supports converting the label to a named actor. Microsoft documented an attack in which the threat actor joined Telegram groups used by cryptocurrency exchange VIP clients, identified a target investment company, and posed as representatives of a rival exchange to build trust before creating a secondary chat and requesting feedback on exchange fee structures. In October 2022, the actor sent a weaponized Excel file containing accurate fee-comparison data whose macro dropped a second encoded spreadsheet, which downloaded an image file split into a legitimate application, a malicious proxy DLL, and an XOR-encoded backdoor that were combined via DLL side-loading to grant remote access. Microsoft also identified a related MSI installer posing as a cryptocurrency dashboard application using the same DLL side-loading and proxying technique, dated June 2022, suggesting other campaigns run by the same actor using consistent tradecraft against the cryptocurrency industry.
-
60
Related Actors
-
690
Related Reports