PowerMagic is Part of a Malware Framework Used Against Ukraine

russia ukraine cyberattacks

In the midst of the ongoing conflict between Russia and Ukraine, several organizations operating in Donetsk, Lugansk, and Crimea have been targeted by a new modular framework known as CommonMagic, as part of an active campaign. The organizations targeted include those in the government, agriculture, and transportation sectors. These attacks were detected by a Russian cybersecurity company in October 2022, which has been monitoring the activity cluster under the name "Bad Magic."

It is believed that the attacks began with a spear-phishing campaign, or similar methods, that employed booby-trapped URLs leading to a malicious ZIP archive located on a compromised web server. This archive contains a decoy document and a malicious LNK file that, when opened, installs a backdoor called PowerMagic.

The backdoor is written in PowerShell and establishes contact with a remote server, allowing arbitrary commands to be executed and results to be exfiltrated to cloud services like Dropbox and Microsoft OneDrive. PowerMagic is also used to deploy the CommonMagic framework, which is a collection of executable modules designed to interact with the command-and-control (C2) server, encrypt and decrypt C2 traffic, and execute plugins. Two plugins that have been discovered so far allow for the capture of screenshots and the gathering of files of interest from connected USB devices.

It is worth noting that the researchers have found no evidence linking this operation and its tools to any known threat actor or group. The campaign may have gone unnoticed for over a year and a half. While the malware and techniques used in the CommonMagic campaign may not be considered highly advanced, the use of cloud storage as the command-and-control infrastructure is noteworthy. This highlights how geopolitics can influence the cyberthreat landscape.

Overall, this attack highlights the need for increased vigilance in the face of evolving cyber threats, especially in regions where geopolitical tensions may exacerbate such threats. Organizations should remain alert to the possibility of spear-phishing campaigns and similar methods, and be prepared to respond promptly and effectively to any suspected incidents of cyberattacks.

March 27, 2023
Loading...

Cyclonis Backup Details & Terms

The Free Basic Cyclonis Backup plan gives you 2 GB of cloud storage space with full functionality! No credit card required. Need more storage space? Purchase a larger Cyclonis Backup plan today! To learn more about our policies and pricing, see Terms of Service, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.