ZeroHour
Palo Alto Unit 42published ()ingested Kaoru Hayashi

Tracking Elirks Variants in Japan: Similarities to Previous Attacks

mediumThreat actor exploited in the wildimportance 44CVE-2011-0611
AI summary · glm-5.3-flash

Unit 42 links new Elirks backdoor variants attacking Japanese organizations to 2012 Taiwan attacks, delivered via spear-phishing PDFs exploiting Adobe Flash CVE-2011-0611.

Unit 42 analyzed new Elirks backdoor variants found in an attack on a Japanese business, noting strong similarities to 2012 attacks on Taiwanese ministries. The backdoor retrieves its C2 address from attacker-created accounts on Japanese blog and SNS services. Recent deliveries used an airline e-ticket lure named "E-TKT" with a PDF exploiting Adobe Flash CVE-2011-0611. Shared infrastructure and tactics with the Scarlet Mimic campaign suggest possible ongoing cyber espionage across East Asia.

  • Elirks retrieves C2 addresses from attacker-controlled accounts on Japanese blog and SNS services.
  • Recent Japanese attack uses an "E-TKT" lure similar to 2012 Taiwan airline-themed phishing.
  • Shares malware, delivery style, and aviation interest with the Scarlet Mimic campaign.
  • Palo Alto Networks customers are protected via WildFire and PAN-DB classifications.

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2011-0611
Remote Code Execution in Adobe Flash Player via Crafted Flash Content

Adobe Flash Player contains a flaw tracked as CWE-843 that allows remote attackers to execute arbitrary code or crash the application (denial of service) by inducing it to load specially crafted Flash content. Exploitation requires only that a victim's Flash runtime process a malicious SWF file — for example embedded in a document or served by a website — with no authentication involved; related reporting from this era describes waterhole attacks in which compromised websites served Flash exploits to targeted users. A successful attack yields code execution with the privileges of the user running Flash, which for browser-plugin deployments typically means the logged-in desktop user. Anyone running affected Adobe Flash Player is affected; CISA's listing does not enumerate specific vulnerable versions, and the product line is end-of-life. Exploitation is confirmed: the flaw was added to CISA's KEV catalog on 2022-03-03, EPSS assigns a 99.4% 30-day exploitation probability (100th percentile), and no public proof-of-concept is known.

Do: Because Flash Player is end-of-life and receives no security updates, remove or uninstall it entirely — including browser plugins, standalone runtimes, and any embedded copies — which is also CISA's required action for impacted systems. If removal must be deferred, disconnect affected systems or block untrusted Flash content and audit logs for exploitation, given the confirmed in-the-wild status and ~99% exploitation probability; whether ransomware operators have used this flaw is unknown.

99% KEV
  • Adobe Flash Player
mass≈1B+ historical installs (near-universal browser plugin); current remaining installs unknown

Indicators of compromiseAll →

TypeIndicatorContext
sha2560e317e0fee4eb6c6e81b2a41029a9573d34cebeabab6d661709115c64526bf953a0312a6c4374989cbcca48dc54ddcd3fbd54b48833afda991a6a2dfdea 0e317e0fee4eb6c6e81b2a41029a9573d34cebeabab6d661709115c64526bf95 f18ddcacfe4a98fb3dd9eaffd0feee5385ffc7f81deac100fdbbabf6423
sha256200a4708afe812989451f5947aed2f30b8e9b8e609a91533984ffa55d02e60a28308bbaa9fcb9c60f0b089032ed4fa1cece830a954ad574bd0c2fe1f104 200a4708afe812989451f5947aed2f30b8e9b8e609a91533984ffa55d02e60a2
sha256755138308bbaa9fcb9c60f0b089032ed4fa1cece830a954ad574bd0c2fe1f1049eaffd0feee5385ffc7f81deac100fdbbabf64233dc68 Delivery PDF: 755138308bbaa9fcb9c60f0b089032ed4fa1cece830a954ad574bd0c2fe1f104 200a4708afe812989451f5947aed2f30b8e9b8e609a91533984ffa55d02
sha2568587e3a0312a6c4374989cbcca48dc54ddcd3fbd54b48833afda991a6a2dfdeatags have been created: Elirks Indicators: Executable File: 8587e3a0312a6c4374989cbcca48dc54ddcd3fbd54b48833afda991a6a2dfdea 0e317e0fee4eb6c6e81b2a41029a9573d34cebeabab6d661709115c6452
sha256f18ddcacfe4a98fb3dd9eaffd0feee5385ffc7f81deac100fdbbabf64233dc68e0fee4eb6c6e81b2a41029a9573d34cebeabab6d661709115c64526bf95 f18ddcacfe4a98fb3dd9eaffd0feee5385ffc7f81deac100fdbbabf64233dc68 Delivery PDF: 755138308bbaa9fcb9c60f0b089032ed4fa1cece830a9
Full article723 words · extracted from unit42.paloaltonetworks.com · click to collapse

A recent, well-publicized attack on a Japanese business involved two malware families, PlugX and Elirks, that were found during the investigation. PlugX has been used in a number of attacks since first being discovered in 2012, and we have published several articles related to its use, including an analysis of an attack campaign targeting Japanese companies.

Elirks, less widely known than PlugX, is a basic backdoor Trojan, first discovered in 2010, that is primarily used to steal information from compromised systems. We mostly observe attacks using Elirks occurring in East Asia. One of the unique features of the malware is that it retrieves its C2 address by accessing a pre-determined microblog service or SNS. Attackers create accounts on those services and post encoded IP addresses or the domain names of real C2 servers in advance of distributing the backdoor. We have seen multiple Elirks variants using Japanese blog services for the last couple of years. Figure 1 shows embedded URL in an Elirks sample found in early 2016.

Figure 1 Embedded URLs in Elirks variant

In another sample found in 2014, an attacker used a Japanese blog service. The relevant account still exists at the time of writing this article (Figure 2).

Figure 2 Blog account created by the attacker in 2014

Link to previous attack campaign

Unit 42 previously identified an Elirks variant during our analysis of the attack campaign called Scarlet Mimic. It is years-long campaign targeting minority rights activists and governments. The malware primarily used in this series of attacks was FakeM. Our researchers described the threat sharing infrastructure with Elirks in the report.

As of this writing, we can note similarities between previously seen Elirks attacks and this recent case in Japan.

Spear Phishing Email with PDF attachment

Figure 3 shows an email which was sent to a ministry of Taiwan in May 2012.

Figure 3 Spear Phishing Email sent to a ministry of Taiwan

The email characteristics were bit similar to the recent case (Table 1).

2012 2016
Email Sender Masquerades as an existing bank in Taiwan Masquerade as an existing aviation company in Japan
Email Recipient Representative email address of a ministry of Taiwan, which is publicly available. Representative email address of a subsidiary company, which is publicly available.
Subject “Bank credit card statement” in Chinese “Airline E-Ticket” in Japanese
Attachment PDF file named “Electronic Billing

1015” in Chinese

File named “E-TKT” in Japanese with PDF icon

Table 1 Email characteristics

When a user opened the attached PDF file, the following message is displayed. It exploits a vulnerability in Adobe Flash, CVE-2011-0611 embedded in the PDF and installs Elirks malware on the system.

Figure 4 opening malicious PDF attachment

Airline E-Ticket

Attackers choose a suitable file name to lure targeted individual or organization. In the recent case, the malicious attachment name in the email was reported as “E-TKT”. We found similar file name in the previous attack in Taiwan in August 2012 (Figure 5).

Figure 5 Elirks executable file masquerade as folder of E-Ticket

When opening the file, Elirks executes itself on the computer and creates ticket.doc to deceive users (Figure 6).

Figure 6 doc file created by Elirks

We’ve also seen another file name related to aviation at Taiwan in March 2012. Figure 7 shows PDF file named “Airline Reservation Numbers (updated version).pdf”. When opening the PDF file, it displays the exactly same message with the Figure4, exploits CVE-2011-0611 and installs Elirks.

Figure 7 PDF named “Airline Reservation Number”

Conclusion

Currently, we have found no reliable evidence to indicate the same adversary attacked a company in Japan in 2016 and multiple organizations in Taiwan in 2012. However, we can see some resemblances between the two attacks. In both cases, attackers used the same malware family, crafted spear phishing emails in a similar manner, and seem to be interested in some areas related to aviation. We have been seeing multiple Elirks variants targeting Japan in the last few years, potentially indicating an ongoing cyber espionage campaign. We will keep an eye on the threat actors.

Palo Alto Networks customers are protected from Elirks variant and can gather additional information using the following tools:

  • WildFire detects all known Elirks samples as malicious
  • All known C2s are classified as malicious in PAN-DB
  • AutoFocus tags have been created: Elirks

Indicators:

Executable File:

8587e3a0312a6c4374989cbcca48dc54ddcd3fbd54b48833afda991a6a2dfdea

0e317e0fee4eb6c6e81b2a41029a9573d34cebeabab6d661709115c64526bf95

f18ddcacfe4a98fb3dd9eaffd0feee5385ffc7f81deac100fdbbabf64233dc68

Delivery PDF:

755138308bbaa9fcb9c60f0b089032ed4fa1cece830a954ad574bd0c2fe1f104

200a4708afe812989451f5947aed2f30b8e9b8e609a91533984ffa55d02e60a2

Text extracted automatically; images, tables and formatting may be missing. Original: https://unit42.paloaltonetworks.com/unit42-tracking-elirks-variants-in-japan-similarities-to-previous-attacks/