The global research and analysis team at Kaspersky Labs has revealed the discovery of a sophisticated wiper malware known as StoneDrill. According to the Russia-based research company, the new wiper has been developed in the same style as Shamoon (also known as Disttrack), a wiper took down roughly 35,000 computers in an oil and gas company in the Middle East in 2012.
p
This attack left 10% of the world’s oil supply potentially at risk. However, the incident was one of a kind, and after it the actor essentially went dark. In late 2016 it returned in the form of Shamoon 2.0 — a far more extensive malicious campaign using a heavily updated version of the 2012 malware. StoneDrill also features advanced anti-detection techniques and espionage tools in its arsenal. In addition to targets in the Middle East, one target has also been discovered in Europe, where wipers used in the Middle East have not previously been spotted in the wild, said the Kaspersky Lab team.
p
The company says it’s not yet known how StoneDrill is disseminated, but once on the attacked machine it injects itself into the memory process of the user’s preferred browser. During this process, it uses two high-end anti-emulation techniques aimed at fooling security solutions installed on the victim machine. The malware then starts destroying the computer’s disk files. So far, at least two targets of the StoneDrill wiper have been identified, one based in the Middle East and the other in Europe, the company confirmed.
p
Moreover the team uncovered a backdoor, which has apparently been developed by the same code writers and used for espionage purposes. Experts discovered four command and control panels which were used by attackers to run espionage operations with help of the StoneDrill backdoor against an unknown number of targets. Furthermore, the malware also appears…