[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)  
  English
* [English](https://unit42.paloaltonetworks.com/digital-quartermaster-scenario-demonstrated-in-attacks-against-the-mongolian-government/)
* [Japanese](https://unit42.paloaltonetworks.com/ja/digital-quartermaster-scenario-demonstrated-in-attacks-against-the-mongolian-government/)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/ "Threat Research")
* [Malware](https://unit42.paloaltonetworks.com/category/malware/ "Malware")  
  [Malware](https://unit42.paloaltonetworks.com/category/malware/)

# Digital Quartermaster Scenario Demonstrated in Attacks Against the Mongolian Government

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 13 min read

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:
  
  * [Bryan Lee](https://unit42.paloaltonetworks.com/author/bryanlee/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:March 14, 2016

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [Malware](https://unit42.paloaltonetworks.com/category/malware/)
  * [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [BBSRAT](https://unit42.paloaltonetworks.com/tag/bbsrat/)
  * [Cmstar](https://unit42.paloaltonetworks.com/tag/cmstar/)
  * [Digital Quartermaster](https://unit42.paloaltonetworks.com/tag/digital-quartermaster/)
  * [Mongolia](https://unit42.paloaltonetworks.com/tag/mongolia/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/digital-quartermaster-scenario-demonstrated-in-attacks-against-the-mongolian-government/?pdf=download&lg=en&_wpnonce=f6e4b1f2e6 "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/digital-quartermaster-scenario-demonstrated-in-attacks-against-the-mongolian-government/?pdf=print&lg=en&_wpnonce=f6e4b1f2e6 "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=Digital%20Quartermaster%20Scenario%20Demonstrated%20in%20Attacks%20Against%20the%20Mongolian%20Government&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fdigital-quartermaster-scenario-demonstrated-in-attacks-against-the-mongolian-government%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Fdigital-quartermaster-scenario-demonstrated-in-attacks-against-the-mongolian-government%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fdigital-quartermaster-scenario-demonstrated-in-attacks-against-the-mongolian-government%2F&title=Digital%20Quartermaster%20Scenario%20Demonstrated%20in%20Attacks%20Against%20the%20Mongolian%20Government "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fdigital-quartermaster-scenario-demonstrated-in-attacks-against-the-mongolian-government%2F&text=Digital%20Quartermaster%20Scenario%20Demonstrated%20in%20Attacks%20Against%20the%20Mongolian%20Government "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fdigital-quartermaster-scenario-demonstrated-in-attacks-against-the-mongolian-government%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=Digital%20Quartermaster%20Scenario%20Demonstrated%20in%20Attacks%20Against%20the%20Mongolian%20Government%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fdigital-quartermaster-scenario-demonstrated-in-attacks-against-the-mongolian-government%2F "Share in Mastodon")
  Unit 42 has collected multiple spear phishing emails, weaponized document files, and payloads that targeted various offices of the Mongolian government during the time period of August 2015 and February 2016. The phishing emails and document files leveraged a variety of geopolitically sensitive subject matters as attractive lures, such as events in Beijing, the Dalai Lama, North Korea relations, the Zika virus, and various legitimate appearing announcements. As we began to analyze and tear down the various samples we collected, we found significant overlaps with previously reported and documented adversary groups, attack campaigns, and their toolsets, exemplifying the concept of the [Digital Quartermaster](https://www.fireeye.com/content/dam/fireeye-www/global/en/current-threats/pdfs/rpt-malware-supply-chain.pdf).

The concept of the Digital Quartermaster is not a particularly new one; it is the idea that there is a group, or groups whose mission is to supply and maintain malicious tools in support of cyber espionage operations. The existence of a Digital Quartermaster has been discussed within the intelligence community for some time, but it is not often that sufficient overlaps exist between what appear to be separate toolsets to confidently claim this idea is indeed in use. The data Unit 42 has collected and analyzed however, does strongly point to the possibility that while there may be multiple operations groups, a Digital Quartermaster may be the one supplying and maintaining the tools used.

### Attack Analysis

While investigating new [BBSRAT](https://blog.paloaltonetworks.com/2015/12/bbsrat-attacks-targeting-russian-organizations-linked-to-roaming-tiger/) instances discovered using the AutoFocus tool, Unit 42 was able to collect additional samples, weaponized documents, and phishing emails uploaded to VirusTotal between August 2015 through February 2016. Each of the samples collected via WildFire and VirusTotal contained significant overlaps in tactics used, tools used, as well as infrastructure for command and control channels. In addition, a large majority of the samples gathered from VirusTotal were uploaded from a single entity in Mongolia.

The attacks themselves followed a consistent playbook throughout the observed timeframe; using weaponized Microsoft Word documents initially containing an exploit for only CVE-2012-0158, appearing to use the highly popular 'Tran Duy Linh' toolkit, then adding in an additional exploit for CVE-2014-1761 in the three newest samples we collected. The newer documents containing exploits for both vulnerabilities appeared to use a publically available PoC authored by 'HCL', with little to no modifications made. All of the weaponized documents except two executed the Cmstar loader or a lightly modified variant of Cmstar onto the victim host while displaying a decoy document or a legitimate appearing document that is generated and presented to the user to make it appear that the weaponized document that had been executed was indeed, legitimate. Once Cmstar was loaded onto the victim hosts, it would attempt to retrieve a final payload. Unfortunately, at the time of analysis, we were unable to retrieve the majority of the payloads the Cmstar loaders were attempting to download, but those that were available were variants of BBSRAT. The two samples not using Cmstar simply had BBSRAT embedded directly into to the weaponized document.

Furthermore, examining the data from August indicates that this campaign had started earlier and the adversary may have already achieved initial footholds, due to the use of what appears to be compromised legitimate email accounts from within the Mongolian government.

### Attack Timeline

[![Quartermaster 1](http://blog.paloaltonetworks.com/wp-content/uploads/2016/03/Quartermaster-1-500x219.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2016/03/Quartermaster-1.png)

### Attack Details

|----------------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **SHA256**                 | 5beb50d95c1e720143ca0004f5172cb8881d75f6c9f434ceaff59f34fa1fe378                                                                                                                                                                                                                                                                                                                                                                                                       |
| **Date**                   | 8/12/2015                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| **Filename**               | Ялалтын баярын ар дахь улс төр.doc (Victory in the back of the government)                                                                                                                                                                                                                                                                                                                                                                                             |
| **Vulnerability Targeted** | CVE-2012-0158                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| **Tools Used**             | Cmstar                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| **Description**            | Two spear-phishing emails originating from likely compromised account 'altangadas@energy.gov.mn' targets multiple other Mongolian government officials. The subject and file attachment are titled 'Ялалтын баярын ар дахь улс төр' (Victory in the back of the government). CVE-2012-0158 exploit used, dropping new variant of Cmstar. The dropped decoy document talks about a Russian festival known as 'Victory Day' and Mongolian's participation in this event. |

[![Quartermaster 2](https://unit42.paloaltonetworks.com/wp-content/uploads/2016/03/Quartermaster-2.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2016/03/Quartermaster-2.png)

![Picture3](http://blog.paloaltonetworks.com/wp-content/uploads/2016/03/Picture3-500x779.png)

|----------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **SHA256**                 | 10090692ff40758a08bd66f806e0f2c831b4b9742bbf3d19c250e778de638f57                                                                                                                                                                                                                                                                                                                             |
| **Date**                   | 8/28/2015                                                                                                                                                                                                                                                                                                                                                                                    |
| **Filename**               | Бээжин хотод цэргийн ёслолын жагсаал.doc (Military ceremonial parade in Beijing)                                                                                                                                                                                                                                                                                                             |
| **Vulnerability Targeted** | CVE-2012-0158                                                                                                                                                                                                                                                                                                                                                                                |
| **Tools Used**             | Cmstar                                                                                                                                                                                                                                                                                                                                                                                       |
| **Description**            | Spear-phishing email originating from 'ganbat\_g@bpo.gov.mn'. A single target is discovered in the collected sample. Subject and filename are titled 'Бээжин хотод цэргийн ёслолын жагсаал' (Military ceremonial parade in Beijing). CVE-2012-0158 exploit used, dropping new variant of Cmstar. The decoy document contains a flight itinerary from Ulaanbaatar, Mongolia to Beijing, China. |

[![Quartermaster 4](https://unit42.paloaltonetworks.com/wp-content/uploads/2016/03/Quartermaster-4.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2016/03/Quartermaster-4.png)

![Picture1](http://blog.paloaltonetworks.com/wp-content/uploads/2016/03/Picture1-500x725.png)

|----------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **SHA256**                 | 44dbf05bc81d17542a656525772e0f0973b603704f213278036d8ffc999bb79a                                                                                                                                                                                                              |
| **Date**                   | 9/15/2015                                                                                                                                                                                                                                                                     |
| **Filename**               | Путины урилга.doc (Putin's Invitation)                                                                                                                                                                                                                                        |
| **Vulnerability Targeted** | CVE-2012-0158                                                                                                                                                                                                                                                                 |
| **Tools Used**             | Cmstar                                                                                                                                                                                                                                                                        |
| **Description**            | Weaponized Microsoft Word document found titled 'Путины урилга.doc' (Putin's Invitation). CVE-2012-0158 exploit used, dropping new variant of Cmstar. The following decoy image, embedded within a Word document, is displayed to the victim upon opening the malicious file. |

[![Quartermaster 6](https://unit42.paloaltonetworks.com/wp-content/uploads/2016/03/Quartermaster-6.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2016/03/Quartermaster-6.png)

|----------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **SHA256**                 | 91ffe6fab7b33ff47b184b59356408951176c670cad3afcde79aa8464374acd3                                                                                                                                                                                                                                      |
| **Date**                   | 9/16/2015                                                                                                                                                                                                                                                                                             |
| **Filename**               | 1.doc                                                                                                                                                                                                                                                                                                 |
| **Vulnerability Targeted** | CVE-2012-0158                                                                                                                                                                                                                                                                                         |
| **Tools Used**             | Cmstar                                                                                                                                                                                                                                                                                                |
| **Description**            | Weaponized Microsoft Word document with unknown title found. Likely delivered via spear-phishing. CVE-2012-0158 exploit used, dropping new variant of Cmstar. The decoy document, which is 13 pages in length, talks about the interference of the United States in other countries across the globe. |

[![Quartermaster 7](https://unit42.paloaltonetworks.com/wp-content/uploads/2016/03/Quartermaster-7.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2016/03/Quartermaster-7.png)

|----------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **SHA256**                 | 6f3d4fb64de9ae61776fd19a8eba3d1d828e7e26bb89ace00c7843a57c5f6e8a                                                                                                                                                                                                                                                                                                                                                                                              |
| **Date**                   | 9/29/2015                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| **Filename**               | Далай ламыг эмч нар амрахыг зөвлөжээ.doc                                                                                                                                                                                                                                                                                                                                                                                                                      |
| **Vulnerability Targeted** | CVE-2012-0158                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| **Tools Used**             | Cmstar                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| **Description**            | Spear-phishing email originating from 'bilguun@masm.gov.mn'. Nearly two thousand recipients found to be targeted, all within the Mongolian government. Email subject and filenames titled 'Далай ламыг эмч нар амрахыг зөвлөжээ' (Dalai Lama doctors advised rest). CVE-2012-0158 exploit used, dropping new variant of Cmstar. The decoy document discusses the latest health of the Dalai Lama, as well as a number of US-based trips he made in late 2015. |

[![Quartermaster 8](https://unit42.paloaltonetworks.com/wp-content/uploads/2016/03/Quartermaster-8.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2016/03/Quartermaster-8.png) [![Quartermaster 9](https://unit42.paloaltonetworks.com/wp-content/uploads/2016/03/Quartermaster-9.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2016/03/Quartermaster-9.png)

|----------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **SHA256**                 | e88ea5eb642eaf832f8399d0337ba9eb1563862ddee68c26a74409a7384b9bb9                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| **Date**                   | 10/2/2015                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| **Filename**               | Sudalgaa avah zagvar.doc                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| **Vulnerability Targeted** | CVE-2012-0158                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| **Tools Used**             | Cmstar                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| **Description**            | Spear-phishing email originating from 'davaa\_ayush@yahoo.com'. 'davaa\_ayush@mod.gov.mn' was a target in the August 12, 2015 attack, indicating the user may have had their personal email account compromised as well. Single target found. Email subject is 'Fw:_Fwd:_@\_БХЯ-наас' (Defense Ministry). Filename is titled 'Sudalgaa avah zagvar.doc', a possible Romanization of Mongolian. CVE-2012-0158 exploit used, dropping new variant of Cmstar. The decoy table provides information about the rank, class, date of birth, and experience of individuals in the Mongolian armed forces. |

**[![Quartermaster 10](https://unit42.paloaltonetworks.com/wp-content/uploads/2016/03/Quartermaster-10.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2016/03/Quartermaster-10.png) [![Quartermaster 11](https://unit42.paloaltonetworks.com/wp-content/uploads/2016/03/Quartermaster-11.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2016/03/Quartermaster-11.png)**

![screenshot](http://blog.paloaltonetworks.com/wp-content/uploads/2016/03/screenshot-500x121.png)

|----------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **SHA256**                 | 68f97bf3d03b1733944c25ff4933e4e03d973ccdd73d9528f4d68806b826735e                                                                                                                                                                                                                                                                                                                                      |
| **Date**                   | 10/22/2015                                                                                                                                                                                                                                                                                                                                                                                            |
| **Filename**               | албанушаалтнуудын сарын цалингийнхаа 30 хувийг хасах.doc                                                                                                                                                                                                                                                                                                                                              |
| **Vulnerability Targeted** | CVE-2012-0158                                                                                                                                                                                                                                                                                                                                                                                         |
| **Tools Used**             | Cmstar                                                                                                                                                                                                                                                                                                                                                                                                |
| **Description**            | Weaponized Microsoft Word document found titled 'Ерөнхий сайд албанушаалтнуудын сарын цалингийнхаа 30 хувийг хасах.doc' (Prime Minister albanushaaltnuudyn monthly salary minus 30%.doc). Likely delivered via spear-phishing. CVE-2012-0158 exploit used, dropping new variant of Cmstar The document discusses changes made to the salaries of government officials within the Mongolian government |

[![Quartermaster 13](https://unit42.paloaltonetworks.com/wp-content/uploads/2016/03/Quartermaster-13.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2016/03/Quartermaster-13.png) [![Quartermaster 14](http://blog.paloaltonetworks.com/wp-content/uploads/2016/03/Quartermaster-14-500x430.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2016/03/Quartermaster-14.png)

|----------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **SHA256**                 | 00ddae5bbc2ddf29954749519ecfb3978a68db6237ebea8e646a898c353053ce                                                                                                                                                                                                                                                                                                  |
| **Date**                   | 10/22/2015                                                                                                                                                                                                                                                                                                                                                        |
| **Filename**               | Улс төрийн www.politik.mn сайт нээгдлээ.doc                                                                                                                                                                                                                                                                                                                       |
| **Vulnerability Targeted** | CVE-2012-0158                                                                                                                                                                                                                                                                                                                                                     |
| **Tools Used**             | Cmstar                                                                                                                                                                                                                                                                                                                                                            |
| **Description**            | Weaponized Microsoft Word document found titled 'Улс төрийн www.politik.mn сайт нээгдлээ.doc' (States opens state www.politik.mn site.doc). Likely delivered via spear-phishing. CVE-2012-0158 exploit used, dropping new variant of Cmstar. The decoy document dropped by the malicious file discusses a new website being launched by the Mongolian government. |

**[![Quartermaster 15](http://blog.paloaltonetworks.com/wp-content/uploads/2016/03/Quartermaster-15-500x200.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2016/03/Quartermaster-15.png)**

|----------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **SHA256**                 | c2ebaf4366835e16f34cc7f0b56f8eaf80a9818375c98672bc678bb4107b4d8c                                                                                                                                                                                   |
| **Date**                   | 10/28/2015                                                                                                                                                                                                                                         |
| **Filename**               | Unknown                                                                                                                                                                                                                                            |
| **Vulnerability Targeted** | CVE-2012-0158                                                                                                                                                                                                                                      |
| **Tools Used**             | Cmstar                                                                                                                                                                                                                                             |
| **Description**            | Weaponized Microsoft Word document with unknown title found. Likely delivered via spear-phishing. CVE-2012-0158 exploit used, dropping new variant of Cmstar. The decoy document talks about a 2016 budget discussion in the Mongolian Parliament. |

**[![Quartermaster 16](https://unit42.paloaltonetworks.com/wp-content/uploads/2016/03/Quartermaster-16.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2016/03/Quartermaster-16.png)**

|----------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **SHA256**                 | aa86f4587423c2ff677aebae604614030f9f4d38280409501662ab4e4fe20c2a                                                                                                                                                                                                                                                    |
| **Date**                   | 12/23/2015                                                                                                                                                                                                                                                                                                          |
| **Filename**               | СОНОРДУУЛГА.doc                                                                                                                                                                                                                                                                                                     |
| **Vulnerability Targeted** | CVE-2012-0158                                                                                                                                                                                                                                                                                                       |
| **Tools Used**             | BBSRAT                                                                                                                                                                                                                                                                                                              |
| **Description**            | Weaponized Microsoft Word document found titled 'СОНОРДУУЛГА.doc' (Announcement). Likely delivered via spear-phishing. CVE-2012-0158 exploit used, with BBSRAT embedded. The document translates to an announcement of a loan agreement signed with foreign banks and financial institutions on October 16th, 2015. |

[![Quartermaster 17](https://unit42.paloaltonetworks.com/wp-content/uploads/2016/03/Quartermaster-17.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2016/03/Quartermaster-17.png)

|----------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **SHA256**                 | fc21814a5f9ed2f6bef9e15b113d00f9291a6553c1e02cc0b4c185c6030eca45                                                                                                                                                                                                                                                   |
| **Date**                   | 1/4/2016                                                                                                                                                                                                                                                                                                           |
| **Filename**               | Өвлийн өвгөнийн үг.doc                                                                                                                                                                                                                                                                                             |
| **Vulnerability Targeted** | CVE-2012-0158                                                                                                                                                                                                                                                                                                      |
| **Tools Used**             | BBSRAT                                                                                                                                                                                                                                                                                                             |
| **Description**            | Weaponized Microsoft Word document found titled 'Өвлийн өвгөнийн үг.doc' (Santa's word). Likely delivered via spear-phishing. CVE-2012-0158 exploit used, with BBSRAT embedded. The decoy document, which had spacing removed for an unknown reason, provides a series of children holiday season songs and poems. |

**[![Quartermaster 18](https://unit42.paloaltonetworks.com/wp-content/uploads/2016/03/Quartermaster-18.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2016/03/Quartermaster-18.png)**

|----------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **SHA256**                 | 7e031a04e570cddda907d0b4b7af19ce60dc481394dfb3813796ce0e6d079305                                                                                                                                                                                                                                                                                                                                               |
| **Date**                   | 2/17/2016                                                                                                                                                                                                                                                                                                                                                                                                      |
| **Filename**               | Хойд Солонгост хориг арга хэмжээ авна.doc                                                                                                                                                                                                                                                                                                                                                                      |
| **Vulnerability Targeted** | CVE-2012-0158 and CVE-2014-1761                                                                                                                                                                                                                                                                                                                                                                                |
| **Tools Used**             | Cmstar and BBSRAT                                                                                                                                                                                                                                                                                                                                                                                              |
| **Description**            | Weaponized Microsoft Word document found titled 'Хойд Солонгост хориг арга хэмжээ авна.doc' (North Korea sanctions). Exploits for both CVE-2012-0158 and CVE-2014-1761 used, dropping a separate, newer variant of Cmstar which downloaded BBSRAT as its final payload. The decoy document talks about a recent speech made by the South Korean President regarding sanctions made against North Korea.  |

[![Quartermaster 19](http://blog.paloaltonetworks.com/wp-content/uploads/2016/03/Quartermaster-19-500x236.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2016/03/Quartermaster-19.png)

|----------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **SHA256**                 | 5c7e3cde4d286909154e9a5ee5a5d061a1f0efaa9875fb50c9073e1e8b6cfaef                                                                                                                                                                                                                                                                                                                                                                           |
| **Date**                   | 2/19/2016                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| **Filename**               | Зика Монголд ойртсоор.doc                                                                                                                                                                                                                                                                                                                                                                                                                  |
| **Vulnerability Targeted** | CVE-2012-0158 and CVE-2014-1761                                                                                                                                                                                                                                                                                                                                                                                                            |
| **Tools Used**             | Cmstar and BBSRAT                                                                                                                                                                                                                                                                                                                                                                                                                          |
| **Description**            | Weaponized Microsoft Word document found titled 'Зика Монголд ойртсоор' (Zika closer to Mongolia). Exploits for both CVE-2012-0158 and CVE-2014-1761 used, dropping a separate, newer variant of Cmstar which downloaded BBSRAT as its final payload. The translated Mongolian text found within the decoy document discusses how the Zika virus has been witnessed in both China and Russia, as well as other countries across the globe. |

[![Quartermaster 20](http://blog.paloaltonetworks.com/wp-content/uploads/2016/03/Quartermaster-20-500x239.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2016/03/Quartermaster-20.png)

|----------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **SHA256**                 | 0b0e6b40a63710b4f7e6d00d7a4a86e6db2df720fef48640ab6d9d88352a4890                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| **Date**                   | 2/19/2016                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| **Filename**               | Хятадад "Зика" вирусын хоёр дахь тохиолдол илэрчээ.doc                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| **Vulnerability Targeted** | CVE-2012-0158 and CVE-2014-1761                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| **Tools Used**             | Cmstar and BBSRAT                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| **Description**            | Weaponized Microsoft Word document found titled 'Хятадад "Зика" вирусын хоёр дахь тохиолдол илэрчээ' (China "Zika" viruses in two cases). Exploits for both CVE-2012-0158 and CVE-2014-1761 used, dropping a separate, newer variant of Cmstar which downloaded BBSRAT as its final payload. The dropped decoy document contains a press release dated on February 16^th^, 2016. The press release discusses changes made to the coal industry in inner Mongolia, The G-20 meeting in China, a five year plan for economic and social development, and two cases of the Zika virus. |

[![Quartermaster 21](https://unit42.paloaltonetworks.com/wp-content/uploads/2016/03/Quartermaster-21.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2016/03/Quartermaster-21.png)

### The Digital Quartermaster: Tool Overlap

The tools we observed being used in this attack campaign remained consistent throughout the six months of data we were able to collect and analyze. Yet, prior to the findings in this report, none of the tools used in this campaign had been observed being used in conjunction with each other. [In their 2013 report](https://kasperskycontenthub.com/wp-content/uploads/sites/43/vlpdfs/kaspersky-the-net-traveler-part1-final.pdf), Kaspersky theorized that NetTraveler may have had connections to the Lurid/Enfal adversaries due to some similarities in command and control infrastructure and targeting of minority groups in China, but no strong evidence was discovered since then. [CMStar](https://blog.paloaltonetworks.com/2015/05/cmstar-downloader-lurid-and-enfals-new-cousin/) is a variant of Lurid discovered by us in May 2015, with similar targeting as previously observed as NetTraveler, but again, with no strong connections. [BBSRAT](https://blog.paloaltonetworks.com/2015/12/bbsrat-attacks-targeting-russian-organizations-linked-to-roaming-tiger/) is a relatively new Trojan we had discovered and publicized in December 2015 and had attributed it to a campaign dubbed 'Roaming Tiger' by ESET in 2014, which specifically appeared to target Russia and Russian speaking nation state. None of these tools have been publicly observed in use together, in a singular campaign, until now:

* The initial dropper embedded in the weaponized document files were obfuscated using a subtraction cipher previously used to obfuscate strings in the NetTraveler malware family.
* A BinDiff comparison of the newer Cmstar variant with a previously reported on NetTraveler sample shows an 80% code similarity
* The first stage loader used in the attacks was Cmstar, or lightly modified variants. Cmstar is closely related to Lurid which is associated with the Enfal trojan
* The final payload for the newest weaponized documents retrieved was BBSRAT, which was previously associated with an attack campaign called "Roaming Tiger", targeting Russia and other Russian speaking nations speaking

The one commonality that does appear amongst these seemingly different tools used by different operators is their geolocational nexus: China. In 2011, TrendMicro strongly attributed Lurid/Enfal to operators based out of China, although they stopped just short of claiming it. In Kaspersky's 2013 report on NetTraveler, another strong attribution was made to a China-based operator. ESET's "Roaming Tiger" reporting did not attribute the attack to any specific nation-state, but examining the command and control infrastructure and WHOIS data again suggested a China-based operator.

These facts begin to lead us to the following possible conclusions: the previous attack campaigns associated with their specific tool were all actually conducted by one, large, all encompassing operations unit. The previous attack campaigns were conducted by separate, but related operations unit with access to a common Digital Quartermaster for tools, or some combination of either scenario.

### Technical Analysis of Tools Used

All of the Microsoft Word documents leveraged in these attacks used the CVE-2012-0158 and CVE-2014-1761 exploits. All of the exploit documents, in addition to targeting the same organizations and relying upon the same exploit techniques, ultimately dropped a version of the BBSRAT. A large number of the encountered samples used a new version of the Cmstar downloader to accomplish this, while some documents dropped and executed BBSRAT directly. Upon successful exploitation, the exploit documents would drop and execute a payload using one of the following techniques:

1. The exploit document drops and executes a file with a path of %TEMP%\\xpsfiltsvcs.tmp. This file contains an original Cmstar downloader that was discussed in a [previous blog post](https://blog.paloaltonetworks.com/2015/05/cmstar-downloader-lurid-and-enfals-new-cousin/).
2. The 'MSOProtect.acl', 'offcln.log', and 'offcln.pip' files are dropped in the %APPDATA%\\Microsoft\\Office\\ directory. The MSOProtect.acl file contains a new variant of the Cmstar malware family. The offcln.pip is a DLL that is responsible for opening a legitimate Microsoft Word decoy document. The offcln.log file contains a command that will open this decoy document. The offcln.log file is used by offcln.pip in order to accomplish this.
3. The %APPDATA%\\comctl32.dll file is dropped and subsequently loaded. This file contains either a new instance of the Cmstar downloader, or a copy of the BBSRAT malware family, which was [discussed by Palo Alto Networks in December 2015](https://blog.paloaltonetworks.com/2015/12/bbsrat-attacks-targeting-russian-organizations-linked-to-roaming-tiger/).

#### New Cmstar Downloader

The majority of the spear-phishing attachments leveraged variants of the [previously discussed downloader named 'Cmstar](https://blog.paloaltonetworks.com/2015/05/cmstar-downloader-lurid-and-enfals-new-cousin/)'. Much of the functionality remained consistent in the newest variants, which were compiled in July and August of 2015. For reference, the original Cmstar downloader malware samples were compiled in February 2015.

The new samples appear to have minimal changes made, and in fact a number of the debugging statements mentioned in the original samples are seen in a number of the newest variants. The obfuscated routine that is responsible for downloading the payload has increased in size from 779 bytes to 943 bytes. This increase in size is due to additional error controls put into place. This routine is still encrypted using a single-byte XOR operation.

However, the newest Cmstar variants use a different routine to obfuscate important strings within the binary. The following code, represented in Python, accomplishes this:  
def decode(data): out = "" c = 0 for d in data: out += chr(ord(d) - c - 10) c += 1 return out

|---------------|-----------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 | def decode(data): out = "" c = 0 for d in data: out += chr(ord(d) - c - 10) c += 1 return out |

Malware analysts may recognize this routine, as it's identical to the one witnessed in [previously discussed NetTraveler samples](https://blog.paloaltonetworks.com/2016/01/nettraveler-spear-phishing-email-targets-diplomat-of-uzbekistan/) that were found to be targeting an individual working for the Foreign Ministry of Uzbekistan in China. As witnessed in the following diagram, the new Cmstar downloader's obfuscation routine has a 100% code match to the NetTraveler downloader previously encountered:

[![Quartermaster fig1](http://blog.paloaltonetworks.com/wp-content/uploads/2016/03/Quartermaster-fig1-500x406.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2016/03/Quartermaster-fig1.png)Figure 1 Code Overlap Between Cmstar and NetTraveler Downloaders

The following URLs were identified to be used by these Cmstar samples:

* http://thbaw.ofhloe\[.\]com/cgl-bin/conime.cgi
* http://dolimy.celeinkec\[.\]com/cgl-bin/upl.cgi
* http://question.eboregi\[.\]com
* http://pplime.savecarrots\[.\]com/cgl-bin/upsd.cgi
* http://dolimy.celeinkec\[.\]com/bin/r0206/update.tmp

The majority of these URLs were not responsive at the time of analysis, with the exception of the last one. This returned file is an encoded executable that contains a dropper, which in turn loads BBSRAT.

#### BBSRAT

Much of BBSRAT's functionality has remained consistent in the newest variants. Like previous versions, the malware will build an Import Address Table at runtime and uses the following mutex to ensure a single copy of BBSRAT is running at a given time:

*Global\\\\GlobalAcProtectMutex*

Additionally, the network structure, URL pattern, and other characteristics of the malware remain consistent. BBSRAT will ensure persistence by setting the following registry key:

*HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run\\comctl32 - rundll32.exe %APPDATA%\\comctl32.dll, Enter*

The largest modification has been the addition of four commands to the command and control handler. These commands are still being researched and full functionality of them has yet to be determined. We have identified the following BBSRAT command and control servers:

* cocolco\[.\]com
* ofhloe\[.\]com
* housejjk\[.\]com

### Infrastructure Analysis

Mapping out the first stage command and control infrastructure for the analyzed Cmstar samples revealed an infrastructure that was most likely deployed specifically for this attack campaign:

[![Quartermaster fig2](http://blog.paloaltonetworks.com/wp-content/uploads/2016/03/Quartermaster-fig2-500x472.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2016/03/Quartermaster-fig2.png)

Figure 2 Cmstar Command and Control Infrastructure

A single domain, question.erobegi\[.\]com, was found to be reused. This domain had previous been identified as a first stage command and control in [May 2015](https://blog.paloaltonetworks.com/2015/05/cmstar-downloader-lurid-and-enfals-new-cousin/) when we initially discovered CMStar. However, the payload was not identified at the time. The WHOIS data revealed heavy usage of resellers by the adversary, likely as an evasion technique. Analyzing the historical WHOIS data however, revealed one of the 'clean' personas used by the adversary as a registrant '[HELENEHELEN@EXCITE.CO.JP](mailto:HELENEHELEN@EXCITE.CO.JP)', was used to register one of the command and control domains for CMStar, celeinkec\[.\]com as well as one of the primary command and control domains for BBSRAT, housejjk\[.\]com, further supporting the links between CMStar, and BBSRAT.

The BBSRAT command and control infrastructure remained exactly the same as previously reported in December 2015:

[![Quartermaster fig3](http://blog.paloaltonetworks.com/wp-content/uploads/2016/03/Quartermaster-fig3-500x315.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2016/03/Quartermaster-fig3.png)

Figure 3 BBSRAT Command and Control Infrastructure

Unfortunately, we were unable to retrieve all of the final payloads from every sample at the time of analysis. ￼One interesting fact to note is the use of the primary domain ofhloe\[.\]com; BBSRAT uses pagbine.ofhloe\[.\]com as a primary command and control, while we also observed Cmstar thbaw.ofhloe\[.\]com as a first stage command and control to likely retrieve BBSRAT.

### Conclusion

Unit 42 often speaks of sharing threat intelligence, tools, and procedures amongst the security industry, often times pointing to the fact that the adversaries we are up against on an everyday basis are doing the exact same. Still, as a community, when we do publicize adversary groups or campaigns, there is a tendency to encapsulate each and place them in their own isolated bubbles, directly contradicting the message of sharing amongst the adversary. The reasoning behind this is not meant to be hypocritical -- it is simply more straightforward for identification and ingestion purposes to be able to silo each group or campaign rather than come to the conclusion that *every* group or campaign is somehow related due to the sharing nature of the adversaries. We must acknowledge the fact however, that in general many attacks *are* related, even if they do appear significantly different or do not share the same TTPs as observed previously

The collection of data we have analyzed strongly points to the fact that a Digital Quartermaster may exist amongst the adversary. The strong overlaps within the tactics used in the toolsets as well as links in infrastructure indicate it is likely that a singular entity is responsible for deployment and maintenance of the tools used, in conjunction with a separate operator group responsible for the actual execution of the cyber espionage operations.

Palo Alto Networks customers are protected through our next-generation security platform:

* WildFire successfully detects BBSRAT, Cmstar, and the weaponized documents as malicious
* AutoFocus identifies the tools used under the [Cmstar](https://autofocus.paloaltonetworks.com/#/tag/Unit42.Cmstar) and [BBSRAT](https://autofocus.paloaltonetworks.com/#/tag/Unit42.BBSRAT) tags
* Traps actively detects and prevents exploitation of both CVE-2012-0158 and CVE-2014-1761
* The C2 domains and files mentioned in this report are blocked through Threat Prevention

### Indicators of Compromise

#### Exploit Document SHA256 Hashes

5beb50d95c1e720143ca0004f5172cb8881d75f6c9f434ceaff59f34fa1fe378  
10090692ff40758a08bd66f806e0f2c831b4b9742bbf3d19c250e778de638f57  
44dbf05bc81d17542a656525772e0f0973b603704f213278036d8ffc999bb79a  
91ffe6fab7b33ff47b184b59356408951176c670cad3afcde79aa8464374acd3  
6f3d4fb64de9ae61776fd19a8eba3d1d828e7e26bb89ace00c7843a57c5f6e8a  
e88ea5eb642eaf832f8399d0337ba9eb1563862ddee68c26a74409a7384b9bb9  
68f97bf3d03b1733944c25ff4933e4e03d973ccdd73d9528f4d68806b826735e  
00ddae5bbc2ddf29954749519ecfb3978a68db6237ebea8e646a898c353053ce  
c2ebaf4366835e16f34cc7f0b56f8eaf80a9818375c98672bc678bb4107b4d8c  
aa86f4587423c2ff677aebae604614030f9f4d38280409501662ab4e4fe20c2a  
fc21814a5f9ed2f6bef9e15b113d00f9291a6553c1e02cc0b4c185c6030eca45  
7e031a04e570cddda907d0b4b7af19ce60dc481394dfb3813796ce0e6d079305  
0b0e6b40a63710b4f7e6d00d7a4a86e6db2df720fef48640ab6d9d88352a4890  
5c7e3cde4d286909154e9a5ee5a5d061a1f0efaa9875fb50c9073e1e8b6cfaef

#### BBSRAT SHA256 Hashes

567a5b54d6c153cdd2ddd2b084f1f66fc87587dd691cd2ba8e30d689328a673f  
cd3b8e4f3a6379dc36fedf96041e292b4195d03f27221167bce7302678fb2540

#### BBSRAT C2 Servers

jowwln.cocolco\[.\]com  
pagbine.ofhloe\[.\]com  
cdaklle.housejjk\[.\]com

#### Cmstar SHA256 Hashes

c3253409cccee20caa7b77312eb89bdbe8920cdb44f3fabfe5e2eeb78023c1b8  
3e2c0d60c7677d3ead690b1b6d4d7c5aaa2d218679634ac305ef3d75b5688e6a  
3a7348d546d85a179f9d52ff83b20004136ee584993c23a8bfe5c168c00fbaa9  
19ba40a7fa332b750c7d93385dd51bd08ee63f91cedb4ae5a93f9f33ecb38c44  
4e1d59042336c3758e77c5c521f60ae262aad01bf7265581de54e869a02b65bc

#### Cmstar C2 Servers

http://thbaw.ofhloe\[.\]com/cgl-bin/conime.cgi  
http://dolimy.celeinkec\[.\]com/cgl-bin/upl.cgi  
http://question.eboregi\[.\]com  
http://pplime.savecarrots\[.\]com/cgl-bin/upsd.cgi  
http://dolimy.celeinkec\[.\]com/bin/r0206/update.tmp
Back to top

### Tags

* [BBSRAT](https://unit42.paloaltonetworks.com/tag/bbsrat/ "BBSRAT")
* [Cmstar](https://unit42.paloaltonetworks.com/tag/cmstar/ "cmstar")
* [Digital Quartermaster](https://unit42.paloaltonetworks.com/tag/digital-quartermaster/ "Digital Quartermaster")
* [Mongolia](https://unit42.paloaltonetworks.com/tag/mongolia/ "Mongolia")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: PowerSniff Malware Used in Macro-based Attacks](https://unit42.paloaltonetworks.com/powersniff-malware-used-in-macro-based-attacks/ "PowerSniff Malware Used in Macro-based Attacks")

### Related Articles

* [Threat Actors Target Government of Belarus Using CMSTAR Trojan](https://unit42.paloaltonetworks.com/unit42-threat-actors-target-government-belarus-using-cmstar-trojan/ "article - table of contents")
* [Using IDAPython to Make Your Life Easier: Part 6](https://unit42.paloaltonetworks.com/unit42-using-idapython-to-make-your-life-easier-part-6/ "article - table of contents")
* [BBSRAT Attacks Targeting Russian Organizations Linked to Roaming Tiger](https://unit42.paloaltonetworks.com/bbsrat-attacks-targeting-russian-organizations-linked-to-roaming-tiger/ "article - table of contents")

## Related Malware Resources

![Pictorial representation of post-exploitation identity misuse in SPIFFE/SPIRE. Close-up of a person wearing glasses, with computer code reflected in the lenses.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/12_Security-Technology_Category_1920x900-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 10, 2026 [#### The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE](https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/)

* [API](https://unit42.paloaltonetworks.com/tag/api/ "API")

* [Cryptographic](https://unit42.paloaltonetworks.com/tag/cryptographic/ "cryptographic")

* [JSON](https://unit42.paloaltonetworks.com/tag/json/ "JSON")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/ "The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE")  
  ![Pictorial representation of a pay-per-install threat group campaign prodiving infection service for spreading malware. A close-up of a computer circuit board with a central microchip is depicted. Red digital data streams in the form of glowing binary numbers and arrows appear to flow in and out of the chip, symbolizing data processing and transfer. The scene is illuminated with a futuristic blue and red glow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/04_Malware_Category_1920x900-6-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 9, 2026 [#### Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure](https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/)

* [ARKTunnel](https://unit42.paloaltonetworks.com/tag/arktunnel/ "ARKTunnel")

* [C2](https://unit42.paloaltonetworks.com/tag/c2/ "C2")

* [CL-CRI-1171](https://unit42.paloaltonetworks.com/tag/cl-cri-1171/ "CL-CRI-1171")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/ "Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure")  
  ![Pictorial representation of attackers using AI tools to target Latin American organizations. A vibrant cityscape with silhouettes of numerous people walking along a bustling street. The scene is illuminated by bright urban lights and digital-like particles, creating a dynamic and futuristic atmosphere.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/AdobeStock_768915868-2-1-786x373.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 3, 2026 [#### Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/)

* [Agentic AI](https://unit42.paloaltonetworks.com/tag/agentic-ai/ "Agentic AI")

* [ChatGPT](https://unit42.paloaltonetworks.com/tag/chatgpt/ "ChatGPT")

* [CL-CRI-1131](https://unit42.paloaltonetworks.com/tag/cl-cri-1131/ "CL-CRI-1131")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/ "Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America")  
  ![Pictorial representation of vishing campaigns in Microsoft Teams. A digital image of a skull formed by blue binary code on a black background, with scattered ones and zeros and digital noise, symbolizes how stealthy prompt injection attacks can exploit AI logic to bypass security controls.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/01_Malware_Category_1920x900-5-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 31, 2026 [#### Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/)

* [Cloaked Ursa](https://unit42.paloaltonetworks.com/tag/cloaked-ursa/ "Cloaked Ursa")

* [Entra ID](https://unit42.paloaltonetworks.com/tag/entra-id/ "Entra ID")

* [Microsoft Teams](https://unit42.paloaltonetworks.com/tag/microsoft-teams/ "Microsoft Teams")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/ "Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams")  
  ![Pictorial representation of AI-enabled malware. A vibrant digital interface displaying various icons and graphs, resembling a futuristic network or data analysis dashboard. The scene is illuminated with glowing lights and patterns.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/AdobeStock_1270203474-2-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 25, 2026 [#### The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/)

* [Backdoor](https://unit42.paloaltonetworks.com/tag/backdoor/ "backdoor")

* [Bitcoin](https://unit42.paloaltonetworks.com/tag/bitcoin/ "Bitcoin")

* [DLL hijacking](https://unit42.paloaltonetworks.com/tag/dll-hijacking/ "DLL hijacking")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/ "The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution")  
  ![Pictorial representation of identity abuse through trusted communication channels. Close-up view of a digital screen displaying a glitched and pixelated image of a skull-like shape.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/02_Malware_Category_1920x900-2-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 20, 2026 [#### Identity Abuse Through Trusted Communication Channels](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/)

* [Authentication](https://unit42.paloaltonetworks.com/tag/authentication/ "authentication")

* [Identity theft](https://unit42.paloaltonetworks.com/tag/identity-theft/ "identity theft")

* [Malware](https://unit42.paloaltonetworks.com/tag/malware/ "malware")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/ "Identity Abuse Through Trusted Communication Channels")  
  ![Pictorial representation of Kimwolf botnet malware family. Digital screen with a warning sign reading "Malware." The background features lines of computer code and graphics, creating a sense of cybersecurity threat.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/07_Malware_Category_1920x900-3-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 11, 2026 [#### Kimwolf v7: An Evolution of the Kimwolf Botnet](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/)

* [Android APK](https://unit42.paloaltonetworks.com/tag/android-apk/ "Android APK")

* [Ethereum](https://unit42.paloaltonetworks.com/tag/ethereum/ "Ethereum")

* [HTTP](https://unit42.paloaltonetworks.com/tag/http/ "HTTP")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/ "Kimwolf v7: An Evolution of the Kimwolf Botnet")  
  ![Pictorial representatiom pf Aeternum's blockchain C2. A close-up of a computer circuit board with a central microchip is depicted. Red digital data streams in the form of glowing binary numbers and arrows appear to flow in and out of the chip. The scene is illuminated with a futuristic blue and red glow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/04_Malware_Category_1920x900-4-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 10, 2026 [#### The Permanent Threat: Analyzing Aeternum's Blockchain-Based C2 Operations and Communications](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/)

* [Aeternum](https://unit42.paloaltonetworks.com/tag/aeternum/ "Aeternum")

* [Infection chain](https://unit42.paloaltonetworks.com/tag/infection-chain/ "infection chain")

* [JSON](https://unit42.paloaltonetworks.com/tag/json/ "JSON")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/ "The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications")  
  ![Pictorial representation of ChainDrop, a self-propagating npm worm. An artistic depiction of a digital workspace featuring an open laptop with a red virus on the screen.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/03_Malware_Category_1920x900-7-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) August 6, 2026 [#### ChainDrop: Inside a Self-Propagating npm Worm](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/)

* [Blockchain](https://unit42.paloaltonetworks.com/tag/blockchain/ "blockchain")

* [ChainDrop](https://unit42.paloaltonetworks.com/tag/chaindrop/ "ChainDrop")

* [Claude code](https://unit42.paloaltonetworks.com/tag/claude-code/ "Claude code")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/ "ChainDrop: Inside a Self-Propagating npm Worm")  
  ![Pictorial representation of Token-jacking. A person types on a laptop with multiple digital interface elements projected, including an "AI" icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/AdobeStock_1246251272-2-786x369.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 6, 2026 [#### Token Jacking: Cybercriminals Could Be Stealing Your AI Resources](https://unit42.paloaltonetworks.com/ai-token-jacking/)

* [AI API](https://unit42.paloaltonetworks.com/tag/ai-api/ "AI API")

* [AI gateway](https://unit42.paloaltonetworks.com/tag/ai-gateway/ "AI gateway")

* [API keys](https://unit42.paloaltonetworks.com/tag/api-keys/ "API keys")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-token-jacking/ "Token Jacking: Cybercriminals Could Be Stealing Your AI Resources")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/frontier-ai-defense)

* [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses)

* [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy)

* [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence)

* [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
