DEV-0139

2022-12-06 • MicrosoftDEV-0139 launches targeted attacks against the cr…

Microsoft tracked DEV-0139 as a temporary designation for an emerging cluster of threat activity, its convention for tracking an unknown or developing actor until enough evidence supports converting the label to a named actor. Microsoft documented an attack in which the threat actor joined Telegram groups used by cryptocurrency exchange VIP clients, identified a target investment company, and posed as representatives of a rival exchange to build trust before creating a secondary chat and requesting feedback on exchange fee structures. In October 2022, the actor sent a weaponized Excel file containing accurate fee-comparison data whose macro dropped a second encoded spreadsheet, which downloaded an image file split into a legitimate application, a malicious proxy DLL, and an XOR-encoded backdoor that were combined via DLL side-loading to grant remote access. Microsoft also identified a related MSI installer posing as a cryptocurrency dashboard application using the same DLL side-loading and proxying technique, dated June 2022, suggesting other campaigns run by the same actor using consistent tradecraft against the cryptocurrency industry.

Related Actors

Related Reports

Top Authors

View all reports in this cluster

View all reports in this cluster