Malware Stager Uses CommuniGate-Themed Lure to Target a Russian Organization

· Original article ↗

Summary

Analysis of a malware sample describes a CommuniGate Pro-themed LNK lure, DLL side-loading through calibre.exe, persistence, and a stager that contacts a command-and-control server to retrieve and execute additional payloads.

Key points

  • The LNK lure presents a CommuniGate Pro implementation questionnaire and appears aimed at a Russian-speaking victim; its filename suggests a possible link to logistics company Delovye Linii, but the article does not confirm a victim.
  • The first LNK downloads a tar archive from ncloudtechlab[.]online, opens a decoy PDF, and launches a second LNK.
  • The second LNK extracts files into %AppData% and runs legitimate calibre.exe to side-load the malicious calibre-launcher.dll.
  • The DLL creates a RunOnce registry entry for persistence and decrypts its configuration using AES-CTR.
  • The stager profiles the host, sends an RSA-encrypted beacon to its C2, and uses HMAC-SHA256 challenges to authenticate the server.
  • It polls the C2 for tasks, downloads additional payloads, and can execute them; the article identifies www.ncloudtechlab[.]online as the C2.

Article Details

Attack Vectors
  • A PDF-themed LNK lure, apparently targeting a Russian-speaking victim, downloads a tar archive from ncloudtechlab[.]online and runs a second LNK inside it.
  • The second LNK displays a decoy CommuniGate Pro questionnaire, extracts files to %AppData%, and launches a legitimate calibre.exe that side-loads a malicious calibre-launcher.dll.
  • The DLL profiles the host, contacts its C2, and can download and execute additional payloads specified in C2 tasks.
Defensive Notes
  • The DLL creates the mutex Global\LightshotsService32 to avoid duplicate execution and sets an HKCU RunOnce value named LightshotsService for persistence.
  • The stager sends an RSA-encrypted host profile as a session cookie. It uses HTTP GET and POST requests, attempts proxy discovery, and authenticates C2 responses before retrieving tasks.

Indicators of compromise

TypeIndicatorContext
DOMAINncloudtechlab[.]onlineHost used by the initial LNK to download the tar archive.
HOSTNAMEwww[.]ncloudtechlab[.]onlineC2 hostname recovered from the stager configuration and listed in the article's IOCs.
SHA25657e37123a8c30641640bada2e0712351a457ee6c8d279926819da178d99fabafHash of the initial malicious LNK lure.
SHA2569f30f57c0fb56f08adc8fb72ceee5053becaad9d54cfdb09be08bb37b60f2a2bHash of the second malicious LNK, 88.lnk.
SHA256a8d04c3d4a97c48d33d9e14009bb3765f22242d51d9a6c9cabdaaa0bb7b22270Hash listed for the downloaded archive disguised as an image.
SHA256ac8428684424dbae254570f757ac2b79eb5bf78e6dfbb0d4247fd814bb1e95cbHash of the malicious side-loaded calibre-launcher.dll.
SHA256c73b421c0d32816e23f49a60cba708b8c113126b54af74e140af8cdb62acd3d7Hash of the treesn archive extracted during the infection chain.

MITRE ATT&CK

Vendors

Products

Countries

Industries

Related Articles