ATTENTION! SpiceRAT infrastructure using Uzbekistan state organization names has been identified!
Suspicious domains, fake TLS certificates, and servers related to the SpiceRAT malware have been identified using names of Uzbekistan state organizations and organizations related to state and strategic sectors. Experts note that this infrastructure can be used for cyber espionage and information gathering on organizations.
Recent investigations have revealed a number of suspicious domains and servers created in a manner similar to official internet resources of Uzbekistan state organizations, using the names of Uzbekistan state organizations. Some parts of this infrastructure are linked to the SpiceRAT malware. Additionally, the same TLS certificates, similar web pages, and identical technical settings were found on some servers.
According to the experts' analysis, these technical similarities identified on various servers and domains suggest they may be interconnected.
It should be emphasized that the use of Uzbekistan organization names on the identified domains does not imply that the information systems of these organizations have been compromised. According to the available information, the names of the organizations and internet resources similar to them may have been used by attackers to gain trust and confuse users.
What is SpiceRAT and what danger does it pose?
SpiceRAT is malware that allows remote control of a compromised computer and belongs to the Remote Access Trojan (RAT) category.
This malware has previously been observed in situations related to cyberattacks against state organizations. According to the experts' previous analyses, SpiceRAT can gain access to a user's device by delivering malicious files via email.
After the malware is installed on the device, it can give the attacker the following capabilities:
- Gathering information about the compromised computer;
- Executing various commands remotely;
- Downloading and running additional malicious files;
- Accessing information on the device;
- Establishing a remote connection with the compromised device.
Therefore, SpiceRAT should be viewed not as a simple malware infection of a device or system, but as a serious cybersecurity incident that requires immediate investigation.
Use of Uzbekistan railway system names
One of the notable aspects of the investigated infrastructure is the identification of suspicious domains using names similar to the Uzbekistan railway system.
For example:
azure.uzrailwaystax[.]com
The domain was created in a manner similar to an official internet resource related to the Uzbekistan railway system.
TLS certificates related to this domain were found on several servers. Importantly, some of these servers are also linked to the SpiceRAT infrastructure.
This situation suggests that attackers may be using the same technical resources across different servers.
However, the identification of this domain does not imply that the official information resources of the Uzbekistan railway system have been compromised. According to the available information, this domain may have been used to create a semblance of an official resource and use the organization's name.
How can fake domains be used?
Attackers often register internet addresses that are very similar to the real domain of a well-known organization or government agency.
For example, extra words, characters, or subdomains are added to the real domain name. As a result, the address appears trustworthy at first glance and can deceive the user.
These domains can be used for the following purposes:
1. Conducting Phishing attacks
An email is sent to the user with a request to open a suspicious link from the organization's name.
2. Collecting Login and Passwords
The user may be asked to enter login and password information for an employee, service system, or other resources through a fake website.
3. Distributing Malicious Files
The user may be induced to download malicious files through a page that looks like the organization's official site.
4. Exploiting User Trust
By using the organization's name, logo, and information from the internet, attackers can try to make the fake resource appear real and trustworthy.
Therefore, it is dangerous to judge an internet resource as reliable only based on its external appearance or the organization's name. It is necessary to carefully check the domain name, not open suspicious links, and not enter information like login and passwords into unknown sites.
TLS certificates found on multiple servers
During the investigation, experts found that the same TLS certificate was used on several servers.
The TLS certificate is typically used to encrypt and protect the data exchange between a website and a user. The presence of a lock symbol in the browser may make the user think the site is secure.
However, an HTTPS connection or a lock symbol does not necessarily mean that the site itself is trustworthy.
If an attacker obtains a TLS certificate for their domain, they can also use HTTPS connections. Therefore, the presence of HTTPS on a website does not independently confirm that it is official or secure.
In this situation, the use of the same certificate on different servers helped to identify the technical connection between these servers.
A copy of the RTX Corporation website was also identified
During the investigation, a static web page copied from the homepage of RTX Corporation was also identified on some servers.
No malicious code or login/password fields were found directly on this page. However, experts were concerned that an identical copy of the page was hosted on several servers.
It was found that the page exists on 13 servers based on the calculated hash value.
This situation suggests that the servers may have been created based on the same template or similar configuration.
From a cybersecurity perspective, such repeated technical signs are very important. This is because attackers can change the server's IP address, but the same TLS certificate, domain settings, or web page hash can help identify new servers.
Suspicious infrastructure may exist for a long time
While studying the historical data of DNS and domains, traces related to some domains and subdomains were found dating back to 2022.
This situation does not imply that all servers have been continuously active since 2022.
However, some domains and infrastructure elements were linked to different IP addresses for several years.
Therefore, experts note that this activity may be part of an infrastructure that has been formed and continuously updated over a long period.
Connection between several malware families
During the analysis, it was found that the infrastructure linked to SpiceRAT also has some technical similarities with other malware families.
In particular, information linking some domains and servers related to NodeEdgeRAT and NomadRAT overlapped through general lists or other technical indicators.
This situation does not prove that different malware are controlled by a single attacker. However, it suggests that common infrastructure or technical resources may have been used for several malicious tools.
Such connections are important in analyzing cyberattacks because they can help identify other infrastructure elements related to an attack through a single identified domain or server.
What dangers exist for state organizations?
One of the main risks for state organizations with such infrastructure is the possibility of confusing employees and launching attacks through fake internet resources using the organization's name and reputation.
For example, an employee may be sent a message containing content such as:
- "Your organization's official security service";
- "Electronic document";
- "Important service notification";
- "Confirm account statement"
The link in the message may lead to a fake domain address instead of the real organization's website.
If the user enters login, password, or other service information on such a page, this information can fall into the attacker's hands.
What should organizations focus on now?
The following measures are recommended to strengthen state organizations and critical information infrastructure:
1. Monitoring Suspicious Domains
Internet addresses similar to official domains but not identical to the official ones should be regularly checked.
Particular attention should be paid to domains that have recently been registered and use names similar to the organization's name or activities.
2. Analyzing DNS Queries
It is important to monitor which domains computers on the internal network are querying.
Repeated queries to unknown, newly created, or unrelated domains require additional checks.
3. Checking Devices via EDR/XDR
Malware of RAT type like SpiceRAT can operate secretly within the system.
Therefore, the following should be checked using EDR/XDR tools:
- Unknown processes;
- Unusual network connections;
- Suspicious DLL loads;
- Unknown programs running from user directories;
- Connections to unknown IP addresses.
4. Monitoring Email
Special attention should be paid to messages that appear to be from the organization but come from unknown or suspicious sources.
In particular, emails containing ZIP, RAR, LNK, HTA, EXE, and DLL files should be carefully examined.
5. Not Opening Suspicious Links
Before opening a link received via email, it is necessary to carefully check its domain name. Do not download suspicious files and do not enter your login and passwords into unknown sites.
6. Retrospective Log Analysis
If any of the above indicators are found in the organization's network, it should not be limited to blocking the current connection. It is also necessary to examine previous logs regarding that IP address, domain, TLS certificate, or other indicators.
This allows for determining whether prior access to this infrastructure from the organization's network occurred and assessing the scope of a potential security incident.
Important Note for State Organizations
The identification of domains similar to Uzbekistan state organizations and the information infrastructure does not imply that their information systems have been compromised.
According to the available technical data, some organizations' names have been used in creating fake domains and suspicious internet infrastructure.
Furthermore, the use of such names in this manner can increase the risk of confusing employees and citizens, directing them to fake links, and using phishing, social engineering, and other deception methods.
Therefore, organizations must regularly monitor suspicious domains using their own names, identify them in a timely manner, and take necessary measures.
The analysis of the SpiceRAT-related infrastructure shows that attackers may use methods such as using organization names, creating websites similar to official internet resources, and linking various technical resources together.
Suspicious domains used by Uzbekistan organizations, repeated TLS certificates on multiple servers, identical web page copies, and servers related to SpiceRAT are important indicators that organizations must continuously monitor their external internet infrastructure.
Most importantly, the official name or logo of the organization, as well as the presence of HTTPS and a lock symbol do not guarantee that an internet resource is real and trustworthy.
Dear Organizations and Citizens!
Before opening links received via email or messenger, carefully check the domain name. Do not download suspicious files and do not enter your login and passwords into unknown sites.
Caution in cybersecurity is one of the most important measures to prevent cyberattacks.
BE AWARE!
Do not assume that any internet resource using an official organization name is trustworthy without checking its domain and source.
