Malware Stager Uses CommuniGate-Themed Lure to Target a Russian Organization

Summary
Analysis of a malware sample describes a CommuniGate Pro-themed LNK lure, DLL side-loading through calibre.exe, persistence, and a stager that contacts a command-and-control server to retrieve and execute additional payloads.
Key points
- The LNK lure presents a CommuniGate Pro implementation questionnaire and appears aimed at a Russian-speaking victim; its filename suggests a possible link to logistics company Delovye Linii, but the article does not confirm a victim.
- The first LNK downloads a tar archive from ncloudtechlab[.]online, opens a decoy PDF, and launches a second LNK.
- The second LNK extracts files into %AppData% and runs legitimate calibre.exe to side-load the malicious calibre-launcher.dll.
- The DLL creates a RunOnce registry entry for persistence and decrypts its configuration using AES-CTR.
- The stager profiles the host, sends an RSA-encrypted beacon to its C2, and uses HMAC-SHA256 challenges to authenticate the server.
- It polls the C2 for tasks, downloads additional payloads, and can execute them; the article identifies www.ncloudtechlab[.]online as the C2.
Article Details
- Attack Vectors
- A PDF-themed LNK lure, apparently targeting a Russian-speaking victim, downloads a tar archive from ncloudtechlab[.]online and runs a second LNK inside it.
- The second LNK displays a decoy CommuniGate Pro questionnaire, extracts files to %AppData%, and launches a legitimate calibre.exe that side-loads a malicious calibre-launcher.dll.
- The DLL profiles the host, contacts its C2, and can download and execute additional payloads specified in C2 tasks.
- Defensive Notes
- The DLL creates the mutex Global\LightshotsService32 to avoid duplicate execution and sets an HKCU RunOnce value named LightshotsService for persistence.
- The stager sends an RSA-encrypted host profile as a session cookie. It uses HTTP GET and POST requests, attempts proxy discovery, and authenticates C2 responses before retrieving tasks.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | ncloudtechlab[.]online | Host used by the initial LNK to download the tar archive. |
| HOSTNAME | www[.]ncloudtechlab[.]online | C2 hostname recovered from the stager configuration and listed in the article's IOCs. |
| SHA256 | 57e37123a8c30641640bada2e0712351a457ee6c8d279926819da178d99fabaf | Hash of the initial malicious LNK lure. |
| SHA256 | 9f30f57c0fb56f08adc8fb72ceee5053becaad9d54cfdb09be08bb37b60f2a2b | Hash of the second malicious LNK, 88.lnk. |
| SHA256 | a8d04c3d4a97c48d33d9e14009bb3765f22242d51d9a6c9cabdaaa0bb7b22270 | Hash listed for the downloaded archive disguised as an image. |
| SHA256 | ac8428684424dbae254570f757ac2b79eb5bf78e6dfbb0d4247fd814bb1e95cb | Hash of the malicious side-loaded calibre-launcher.dll. |
| SHA256 | c73b421c0d32816e23f49a60cba708b8c113126b54af74e140af8cdb62acd3d7 | Hash of the treesn archive extracted during the infection chain. |
MITRE ATT&CK
T1033 · System Owner/User DiscoveryThe stager includes the user name in its host-profile beacon.T1059.003 · Windows Command ShellThe LNK chain invokes cmd.exe to download and extract archives and launch the next-stage files.T1071.001 · Web ProtocolsThe stager exchanges HTTP GET and POST requests with its C2, placing the encoded host profile in a session cookie header.T1082 · System Information DiscoveryThe stager's host profile includes OS version, build number, product type, and suite mask.T1105 · Ingress Tool TransferThe first LNK downloads a tar archive; the DLL can subsequently download payloads from URLs supplied in C2 tasks.T1140 · Deobfuscate/Decode Files or InformationThe DLL AES-decrypts its embedded configuration before using the recovered C2 domain and RSA key.T1547.001 · Registry Run Keys / Startup FolderThe DLL creates an HKCU RunOnce value named LightshotsService pointing to the executable that loaded it.T1573.001 · Symmetric CryptographyThe stager AES-decrypts tasks received from the C2.T1573.002 · Asymmetric CryptographyThe stager RSA-encrypts the host-profile beacon before sending it to the C2.T1574.002 · DLL Side-LoadingA legitimate calibre.exe loads the malicious calibre-launcher.dll from the extracted files.
Vendors
Products
calibre.exeinfection chain. This file opens the decoy PDF, untars the content in treesn to %AppData% and executes calibre.exe from the untared content, side-loading the malicious calibre-launcher.dll.CommuniGate ProThe lure is associated with a CommuniGate Pro implementation. CommuniGate Pro is a corporate communications server developed by CommuniGate.It is associated (and likely targeting) Delovye Linii, a Saint Petersburg-based