Russia’s Fancy Bear targets Linux environments with Drovorub malware
Summary
Unit 26165 of the Russian General Staff Main Intelligence Directorate’s (GRU) 85th Main Special Service Centre, which also goes by the name of Fancy Bear, Strontium and APT28, is using Drovorub – which consists of a kernel module rootkit, a file transfer and port forwarding tool, and a command and control (C2) server – to establish direct communications between target environments and its C2 infrastructure, download and upload files, execute arbitrary commands, and port forward network traffic to other hosts on the network. Steve Grobman, CTO at McAfee, described Drovorub – which translates most directly as “woodcutter” – as containing a Swiss-army knife of capabilities allowing an attacker to perform various actions within their target’s systems. “In addition to Drovorub’s multiple capabilities, it is designed for stealth by utilising advanced rootkit technologies that make detection difficult,” said Grobman. Attackers can launch cyber warfare campaigns to inflict significant damage or disruption and do so without geographic proximity to their target. The objectives of Drovorub were not called out in the report, but they could range from industrial espionage to election interference.” The agencies said that although there are a number of detection techniques that can be effectively used to identify Drovorub (detailed in full in its advisory, along with Snort and Yara rules), its kernel module poses a challenge to large-scale detection because it hides its artefacts from widely used tools for at-scale live response.