Hlavní obsah

„This is a paid engagement“: Attackers attempt to ensnare Seznam journalist

Foto: Profimedia.cz

Attackers targeted a Seznam Zprávy reporter in a spear-phishing attack, intending to steal data and take control of his computer. (Stock photo)

Seznam Zprávy reports on a cyberattack targeting its reporter Lukáš Valášek. Under the pretext of paid lecture work, hackers tried to lure him into running malicious code that could have wiped his computer and monitored his work.

Článek

Redakce vydává anglickou verzi investigativního textu o sofistikovaném kybernetickém útoku na reportéra Seznam Zpráv.

Journalists’ work inboxes are inundated every day with spam and fraudulent messages. But this email was different. It marked the start of an attack targeting a member of Seznam Zprávy’s investigative team, which uncovers corruption and spying scandals.

If the attackers, posing as academics, had succeeded, the journalist would have installed malicious code that would have stolen data and passwords from his computer. What’s more, the attackers would have gained remote control of his laptop and been able to closely monitor what he was working on.

But that didn’t happen. Instead, Seznam Zprávy is running a report on how the attackers operate, and how they try to manipulate recipients into infecting their own computers. The report reveals details of the operation, for the purposes of which the hackers registered a number of internet domains. It is likely, however, that there are more targets of similar attacks. Previous attacks have already caused significant financial damage worldwide.

An offer that can’t be refused

It all began with an email intended to reel me in. It arrived in my work inbox from a sender who introduced herself as Emily Tan, human resources manager at PSB Academy, a private school in Singapore.

„We are coordinating a series of guest lectures for our students, and I would like to invite you to take part,“ wrote „Emily“ in the message, which featured the official logo of the Asian educational institution in the header.

It was obvious, however, that „Emily“ had prepared and was trying to flatter me. Her true intentions didn’t become fully apparent until later.

„Your work as an investigative reporter at Seznam Zpravy, particularly your reporting on political corruption and conflicts of interest, offers students a clear view of how rigorous journalism holds public figures to account. We are especially interested in the craft behind it: working with documents, verifying facts, and handling sources responsibly,“ the email continued.

At the end, she dropped the bait. „It is a paid engagement. If this is of interest, I would be glad to share further details,“ „Emily“ concluded the mail.

Foto: Seznam Zprávy

Emily in Singapore writes. The email that started the whole thing.

Nine-day old email address

I occasionally receive email offers for lectures or teaching gigs, but they’re usually from the Czech Republic or some other European countries. Singapore, nearly 10,000 kilometres away, is out of the way, which is why this grabbed my attention. And I quickly spotted a few red flags.

The email came from the address info@hr-psb.eu. The European registry shows that someone with the email address suhaahaashid630@gmail.com registered the corresponding domain as recently as the middle of July. Just nine days before „Emily“ used it to send me the offer.

Foto: Seznam Zprávy

The domain registry shows that „Emily“ set up the email account just before she sent the invitation from it.

So I also inquired about Emily Tan in Singapore itself. And discovered that, though the school itself existed, no such person worked there.

„That person is not an employee of PSB Academy. For your information, our email domain is @psb-academy.edu.sg,“ wrote Eleanor Wong, spokesperson for PSB Academy, emphasising that their emails come from an address with the Singapore country code ‚sg‘ rather than the European ‚eu‘.

We’ll pay you up to 3,500 dollars

I decided to continue corresponding with the sham „Emily“, with the intention of mapping this targeted cyberattack more closely. „Thanks so much for the offer. I’d love to hear the details,“ I wrote, asking whether she planned to invite me directly to Singapore, or for whom I was actually supposed to deliver the lecture.

„Emily“ gradually sent me a total of 22 emails, which showed the sophistication of the entire operation aimed at gaining access to the data on my computer. Not once did „Emily“ pressure me in any way. But with each message she increased the likelihood that she would actually convince me to open the door to my computer for the attackers myself.

Foto: Seznam Zprávy

„A short presentation and up to USD 3,500 is yours.“

„Emily“ responded to my questions in a long message, in which she described the activities of the PSB Academy and emphasised that, since they are still putting together the schedule for the coming academic year, they would be happy to accommodate me. She added that we would start with an online lecture, so I wouldn’t have to leave Prague, but that further collaboration was also an option. Only at the end of the email did a casual offer follow: a lecture usually lasts 45 to 75 minutes, and I would be paid up to USD 3,500.

„As a natural next step, I would welcome a short introductory call to discuss any remaining questions and find an approach that works well for you,“ „Emily“ concluded the message, immediately sending a link to the commonly used Calendly service, where I was to book a date for the online meeting at my convenience.

Duplicitous duck

Going by the time options listed, „Emily“ would have needed to be remarkably dedicated to her job. For example, there were even slots available at 10 p.m. Prague time, which is 4 a.m. in Singapore.

In the end, I chose a more acceptable morning slot. But I still had no idea how „Emily“ and I would connect. The link to the web app didn’t arrive until a few hours before the scheduled time. „Emily“ encouraged me to call her via the U.S. website StreamYard, which is actually used to host online webinars. The app, which has a duck in its logo, doesn’t require installation on a computer – everything runs in a web browser.

Foto: Seznam Zprávy

An invitation to a video call? In fact a link to a fake website.

Once again, however, I was stopped in my tracks by the domain through which I was meant to join the meeting with „Emily“. That domain doesn’t actually belong to StreamYard at all. „Emily“ directed me to an address that a layperson might mistake for the real „streamyard.com“, instructing me instead to click on „streamyard.host07eu.com“.

At that moment, the corresponding domain, host07eu.com, had been online for less than three weeks. When I clicked on the link in a special environment isolated from my data, I anticipated an attempt to infect my computer with a virus.

Fake call, real virus

It turned out, however, that the attack was aimed much further. The link got past antivirus scans without any problems. And waiting for me there was a well-crafted copy of the real StreamYard website’s interface. I chose a username and clicked the „Join“ button. For a moment, it looked like I was actually going to see „Emily“.

But then the app displayed a pre-programmed error: a problem with my connection. The attackers were taking a slow and more subtle approach.

Foto: Seznam Zprávy

A video call? Actually, a fake website designed to trick visitors into installing malicious code on their own computers.

„We see that you have connected, but unfortunately the system indicates that your connection has very high latency, so we are unable to see or hear you properly,“ „Emily“ immediately wrote, seeking intensify my potential anxiety that the scheduled meeting wasn’t going to plan.

„If possible, could you please try reconnecting using a different browser, or preferably through the desktop application? This usually resolves the issue,“ the fake school employee wrote, continuing to guide me.

It was becoming clear what would happen next: an attempt to subtly trick me into disabling my security settings and installing a video-calling program on my computer that was in fact a package containing malicious code designed to steal my data.

Foto: Seznam Zprávy

How „Emily“ subtly guided me toward installing malicious code on my own computer.

When I played along with the scenario and wrote „Emily“ that I was unable connect in any browser and asked if she could send me a link to download the app, she sent me a broken link that led to the website of the real company, StreamYard.com. It couldn’t have worked in any case – the company doesn’t offer a desktop app.

„Emily“ had most likely calculated that by that point I’d be sufficiently frazzled from yet another setback. It was tens of minutes past the time I was meant to connect with her and her colleagues on a call to discuss the terms under which they would pay me the promised amount.

Only then did „Emily“ redirect me once again to a fake web interface for a video-calling app, from which I could click through to download a program. At the same time, the website prompted me to disable my operating system’s security features immediately after downloading and to run the file.

I downloaded it in an environment isolated from my data. I tested it and found that it passed with ease through standard antivirus programs. For security reasons, however, I did not run the program myself.

A few clicks from hacking and infiltration

It wasn’t until Seznam experts activated the software in their lab that things started to happen. It was confirmed that I wouldn’t have been able to make a call using the downloaded program. Instead, the malicious code would have tried to gain access to my passwords, social media accounts, content management system, email and chat apps. It would also copy and send to its operators any documents I had stored on my computer.

The program attempts to mask its activity so that it isn’t detected by antivirus software. As a bonus, in the next step, it secretly installed a tool for remote computer administration. „Emily“ could thus monitor what I was working on over the long term – and even take control of my computer herself.

„This software attempts to steal data and establish persistent access to the computer. If anything, it falls into the category of espionage tools,“ said Martin Doleček, Seznam’s director of information security.

I sent „Emily“ one last email. I asked who she really was and why she was trying to access my data. I never received a reply. At the same time, I reported the attack to law enforcement. An analysis by Seznam’s experts confirmed that I had been the target of what is called spear-phishing.

„Criminals and sophisticated attackers (especially state-sponsored hacker groups) use it to gain access to a victim’s network, whether for the purpose of espionage or to cause damage,“ says the National Cyber and Information Security Agency (NÚKIB).

China has employed spear-phishing in Czechia

• The National Cyber and Information Security Agency warned against this technique in 2020.

• In 2018, Czech universities were the target of a similar attack. „The goal was to steal research data, unpublished results or the know-how of research groups. The attackers were interested in data from various fields, such as medicine, engineering and the humanities. These were well-prepared attacks in which the attackers demonstrated knowledge of the Czech university environment,“ NÚKIB reported.

• As early as 2015, spear-phishing had already proven successful in Ukraine, for example, where attackers managed to temporarily shut down the power grid for a quarter of a million people.

• Recently, attackers linked to Chinese Communist intelligence were caught carrying out spear-phishing attacks in the Czech Republic. Seznam Zprávy reported that they attacked the European Values Center for Security Policy, a non-profit that has long focused on Chinese influence. The hackers used the identity of a real AP journalist.

However, identifying the perpetrators will be difficult. Cyber experts typically attempt to do so by linking the malicious code or internet domains used to previous attacks. In this case, however, the attackers registered the domains right before the attack and are also concealing their identities in other ways.

„This involves a completely fabricated environment, including web domains, which the attackers abandon after a certain period of time or following an attack, and then create new ones,“ Doleček said.

However, the malicious code bears the hallmarks of a tool that security experts have named Storm and which the U.S. cybersecurity firm Varonis drew attention to in April.

It is, however, common for such pre-built tools to be rented out in the dark corners of the web for specific attacks. Last September, cryptocurrency expert Zac Cole described a similar attempt, also employing a fake StreamYard page. In his case, the attacker eventually admitted to him that he was renting the tool for $3,000 a month. The attacker was likely using it to try to steal cryptocurrency from Cole.

As a reporter for Seznam Zprávy, I was most likely not the only target of the ongoing attack. I managed to identify six domains that attackers were using to lure victims into downloading malicious code via fake video calls. They all share a common owner, hidden behind a proxy service based in Iceland. Iceland possesses some of the strictest privacy laws and is beyond the reach of Czech law enforcement agencies.

Doporučované