Someone pretending to be from the State Department just sent me a virus, a variation of a particularly nasty piece of malware that reportedly brought down the State Department’s email system last year and compromised the White House’s unclassified network.
Among the many emails waiting in my inbox this morning was one that seemed to come through a State Department .gov domain address. It purported to be a fax from a State Department machine, containing a PDF file.
More: State Department hit in cyberattack that also compromised White House
Getting an unsolicited email or document isn’t that unusual in the day-to-day of a reporter. However, the link to download the document went to a .org site (not the actual State Department site) and the file itself was a ZIP, not PDF. Seeing the red flags of a potential spear-phishing attempt, I contacted our IT department and we opened the file in the safety of a sandboxed environment.
The file, in fact, contained malware, specifically a variant of CozyDuke — also known as CozyCar and several other pseudonyms — an advanced persistent threat that was used to attack a number of high-profile targets last year, including the White House and State Department, as researchers at Kapersky Lab revealed in April.
That attack found its way into the White House’s unclassified network and forced the State Department to take its external email systems offline for months while the malware was expunged.
More: White House cyber breach one example of ‘daily’ attacks
The variant in Tuesday’s email was a new APT coined Minidionis by researchers at Palo Alto Networks, who exposed the malware campaign on July 14. Hackers started using the code on July 7, mostly targeting European organizations, including embassies and NGOs.
While the code itself is different than the malware that attacked the State Department last year, the signature style led researchers at Dell’s SecureWorks Counter Threat Unit to believe it was created by the same actors.
“This looks very similar. I can’t imagine it would be a different group using that exact technique,” said Joe Stewart, director of malware research. “It would be unlikely another group picked up the [CozyDuke] malware and used it, mainly because they don’t have the source code.”
More: Russians hacked White House computers, according to CNN report
Just because the phishing email I received Tuesday is likely from the same actors that compromised the State Department and the email purported to be from State does not mean the department’s systems are still infected, Stewart said.
“It’s trivial for anyone to pretend to be state.gov or any other domain they choose,” he said. “The odds the State Department was hacked by someone are 100 percent but the odds that this actually came from state.gov are zero percent.”
Spoofing email addresses is not particularly difficult, even for .gov domains. Chances are this phishing attempt was not the result of the prior hack, as the actual source header does not relate to any State Department IPs.
“There’s nothing in this message other than the fake state.gov return address” to connect this phishing attempt with a hack against the State Department, Stewart said. “I’m not saying they don’t still have intruders on the network, there’s just no evidence here whatsoever to connect the two.”
More: Malware getting more advanced, easier to use in 2015
Cybersecurity officials at the Department of Homeland Security agreed.
“The United States Computer Emergency Readiness Team (US-CERT) — part of the Department of Homeland Security’s National Cybersecurity and Communications Integration Center — is aware of an alleged phishing campaign masquerading as emails from the Department of State,” DHS spokesman S.Y. Lee said Tuesday. “US-CERT has determined that the emails were spoofed and did not originate from the Department of State networks.”
While the email address was from the State Department, the malware was hosted on a server for Counseling.org, the website of the American Counseling Association.
After I sent the original email to US-CERT, ACA’s IT managers received a call from the FBI alerting them that their servers were compromised.
ACA immediately took its servers offline and quarantined the malicious software, according to Chris Ecker, chief technology officer at DelCor, ACA’s IT managers. The website was still online Tuesday afternoon, though DelCor technicians were working to identify and remediate the compromised servers.
Slideshow: Federal data breaches of 2015




