/?pid=new-iranian-wiper-malware-discovered-21336

Updated:06:16 PM EDT Oct 02


this is ggmania.com subsite New Iranian wiper (malware) discovered - TechAmok

New Iranian wiper (malware) discovered - [security]
04:27 PM EST - Dec,04 2019 - post a comment

IBM X-Force, the company's security unit, has published a report of a new form of "wiper" malware connected to threat groups in Iran and used in a destructive attack against companies in the Middle East. The sample was discovered in a response to an attack on what an IBM spokesperson described as "a new environment in the [Middle East]-not in Saudi Arabia, but another regional rival of Iran." Dubbed ZeroCleare, the malware is "a likely collaboration between Iranian state-sponsored groups," according to a report by IBM X-Force researchers. The attacks were targeted against specific organizations and used brute-force password attacks to gain access to network resources. The initial phase of the attacks was launched from Amsterdam IP addresses owned by a group tied to what IBM refers to as the "ITG13 Group"-also known as "Oilrig" and APT34. Another Iranian threat group may have used the same addresses to access accounts prior to the wiper campaign. In addition to brute force attacks on network accounts, the attackers exploited a SharePoint vulnerability to drop web shells on a SharePoint server. These included China Chopper, Tunna, and another Active Server Pages-based webshell named "extensions.aspx," which "shared similarities with the ITG13 tool known as TWOFACE/SEASHARPEE," the IBM researchers reported. They also attempted to install TeamViewer remote access software and used a modified version of the Mimikatz credential-stealing tool-obfuscated to hide its intent-to steal more network credentials off the compromised servers. From there, they moved out across the network to spread the ZeroCleare malware.

ZeroCleare, like the Shamoon wiper, uses the legitimate RawDisk software driver from EldoS to gain direct access to disk drives and write data. Since the EldoS driver is not signed, however, ZeroCleare uses a vulnerable but signed driver from a version of Oracle's VirtualBox virtual machine software to bypass signature checking of the driver-allowing it to attack 64-bit versions of Windows. The VBoxDrv driver, which passes Microsoft's Driver Signature enforcement, is loaded by an intermediary executable-in the IBM X-Force detected cases, the file was named soy.exe. After loading the vulnerable VirtualBox driver, the malware exploits a bug in the driver to load the unsigned EldoS driver. On 32-bit Windows systems, which lack Driver Signature Enforcement, the malware can dispense with the workaround and run the EldoS driver directly. The payload of the malware is called ClientUpdate.exe. Using the EldoS driver, it overwrites the Master Boot Record and disk partitions of the infected machine.

Short overview of recent news articles

Frankenstein - Official Trailer (2025) Guillermo del Toro, Oscar (Oct,02 2025 )

iPhone 17 Pro Max vs 16 Pro Max / Pixel 10 Pro XL / Galaxy S25 Ultra (Oct,02 2025 )

iOS 26.0.1 is Out! - What's New? (Sep,30 2025 )

NEW! 2026 Audi Q3 2.0 TFSI (265hp) vs. e-hybrid (272hp)| 0-100 km/h (Sep,30 2025 )

Samsung One UI 8.5 Hands on - I Was Wrong (Sep,29 2025 )

iPhone Air Teardown - What is 3D Printed Titanium? (Sep,28 2025 )

Nvidia Wouldn't Send Me This $30,000 GPU - H200 Holy $H!T (Sep,28 2025 )

The Astronaut - Official Trailer (2025) Kate Mara, Laurence (Sep,27 2025 )

iPhone 17 Durability Test -- What Scratches are Permanent? (Sep,25 2025 )

iPhone 17 Pro Max vs. Galaxy S25 Ultra Drop Test! (Sep,23 2025 )

Race Highlights: A Swing In The Drivers' Title Fight? | 2025 (Sep,21 2025 )

BYD Yangwang U9 Hits 496.22 KM/H - EV Supercar Speed Record (Sep,21 2025 )

I'm FIRST to Unbox The World's Biggest TV (Sep,21 2025 )

Samsung Begins Rollout of Android 16 to Rest of Lineup (Sep,21 2025 )

iOS 26 Now Available, with Visual Intelligence (Sep,21 2025 )

Apple's iPhone 17 Series is Nearly Hack-Proof (Sep,21 2025 )

Qualifying Highlights - 2025 Azerbaijan Grand Prix (Sep,21 2025 )

iPhone 17 Pro vs Samsung S25 Ultra Camera Comparison! (Sep,20 2025 )

iPhone Air Durability test -- I AM SHOCKED (Sep,20 2025 )

Microsoft warns Office 2016/2019 users to switch to the cloud as (Sep,15 2025 )

Get Windows 11 25H2 Right Now (Sep,15 2025 )

iPhone 17 Pro VS iPhone 16 Pro VS iPhone 15 Pro VS iPhone 14 Pro (Sep,14 2025 )

What's the AMD Alternative to an RTX 5070? (Sep,11 2025 )

Apple got my wife, they might get me next... (Sep,10 2025 )

Which Phone Has The Fastest Wi-Fi 7? (Sep,09 2025 )

Apple Event - September 9 (Sep,09 2025 )

Ferrari F430 *MANUAL* with TUBI EXHAUST SCREAMING on the AUTOBAHN! (Sep,08 2025 )

AMD Adrenalin 25.9.1 Driver (Sep,08 2025 )

Google Brings AI Text Tools to its Keyboard (Sep,08 2025 )

The Fastest Lap In F1 History: Max Verstappen's Pole Lap | 2025 (Sep,06 2025 )

You can't download and install Windows 11 25H2 yet as Microsoft (Sep,06 2025 )

A House of Dynamite - Official Teaser (2025) Rebecca Ferguson, Greta (Sep,04 2025 )

RTX 5060 Ti 16GB + Ryzen 5 5600 : Test in 17 Games (Sep,04 2025 )

BUGONIA Trailer 2 (2025) Emma Stone, Jesse Plemons (Sep,02 2025 )

Huawei unveils world-leading AI supercharged hard drive to power (Sep,02 2025 )

AM4 Lives: AMD Ryzen 5 5500X3D CPU Review & Benchmarks (Sep,01 2025 )

I was wrong, iPhone IS better than Android...- 30 Day iPhone (Aug,29 2025 )

303KM/H BMW X5 M50i GPOWER SOUNDS LIKE THUNDER (Aug,29 2025 )

NVIDIA GeForce 581.15 WHQL drivers (Aug,29 2025 )

Apple Intelligence vs Galaxy AI / Google Pixel AI / Xiaomi HyperAI - (Aug,28 2025 )

The Woman in Cabin 10 - Official Trailer (Aug,28 2025 )

YANGWANG U9 Breaks Global EV Top Speed Record (Aug,28 2025 )

AMD B850 Motherboard Roundup: Sub $200 Models (Aug,26 2025 )

Gamers Nexus: Our Channel Could Be Deleted (Aug,25 2025 )

2025 Audi A5 E-Hybrid 299HP "250KMH is back!!" // REVIEW on (Aug,24 2025 )

I Can't Stop You From Buying This... But I'll Try - GeForce RTX (Aug,23 2025 )

NVIDIA GeForce 581.08 WHQL Driver (Aug,23 2025 )

Murcielago with flames chasing an F1 car on highway (2025) (Aug,21 2025 )

Windows 11 24H2 Security Update Causes SSD/HDD Failures and (Aug,18 2025 )

Samsung Galaxy Z Fold 7 - Tips, Tricks & Hidden Features! (Aug,17 2025 )

>> News Archive <<

TechAmok - Privacy Policy        loading time:0.01secs