Recently, media reported of a targeted attack against the Israeli government, in the form of emails purporting to come from IDF Chief of Staff Benny Gantz, where the email contained a malicious attachment.
We located this file. It was signed with a fake digital certificate. In the following investigation we first found several other trojans similarly signed, then many more trojans connecting to the same command & control structure as the first batch. Many of these contained bait documents and video to attract attention (and clicks). These baits are in English or Hebrew and touch on issues interesting for an Israeli audience.
The Command & Control structure is centered around a few dynamic DNS (DynDNS) domains that at the time of writing point to hosting services in the US.
But then the ground shifted. The next batch of files we found were older, were aimed at different targets, but still connected to the same Command & Control servers. Below are examples of the bait documents and videos used:
These bait documents are in Arabic and apparently aimed at a Palestinian audience – they revolve around issues such as the Palestinian government policies and the Israeli hostage Gilad Shalit and his exchange for Palestinian prisoners. The video is interesting. It appears to be lambasting the Palestinian president Mahmoud Abbas for not working for the interests of the Palestinian people.
These samples belong to an older series going back to October 2011. As mentioned they use more or less the same C&C infrastructure – but at the time the C&C host names resolved to IP addresses in Palestine. Gaza, to be exact. The providers in question were:
Palestinian Territory, Occupied Gaza Palestine Telecommunications Company (paltel), ASN: AS12975
Palestinian Territory, Occupied Gaza Hadara Technologies Private Shareholding Company, ASN: AS15975
These are both Paltel divisions. Paltel is headquartered in Ramallah in the West Bank.
The updated command- and control map now looks something like this (samples: blue, C&C’s: yellow, certificate:green, IP addresses:purple). Note that historical IP addresses are not shown, these are current resolves.
Document metadata
Most of the bait attachments are Word documents, and Word documents can contain metadata (typically the usernames of the creator and the one who last saved the document). It is possible to scrub these details, but our attackers seem to have forgotten this – or inserted faked data.
Palestinian baits:Hmas.doc: Created by “Hitham”, saved by “anar” date Oct 12 2011484hhh.doc: Created by “Hitham”, saved by “Ayman” date Nov 27 2011Word.doc: Created and saved by “Tohan” date Feb 18 2012Israeli baits:word.doc: Created by “ahmed”, saved by “aert” date May 14 2012IDF NEWS.doc: Created and saved by “aert” date May 26 2012Brotherhood.doc: Created and saved by “aert” date Jun 24 2012detl.doc: Created and saved by “aert” date Jun 29 2012Advisor.doc: Created and saved by “HinT” date Jul 29 2012IDF.doc: Created and saved by “aert” date Aug 1 2012System.doc: Created and saved by “HinT” date Aug 5 2012York.doc: Created and saved by “HinT” date Oct 1 2012barrage.doc : Created and saved by “HinT” date Oct 24 2012shehab.doc: Created and saved by “HinT” date Oct 31 2012 |
There seems to be a number of people involved in creating these bait files. The dates also roughly coincide with the apparent shift in IP ranges, from first being located in Gaza, to being located internationally.
So what does it all mean?
Obviously, an espionage operation using mostly XtremeRats has been underway for at least a year. It is interesting that the operation apparently shifted over time from Palestinian target to Israeli target. This can be due to changes in the political situation, or maybe the first half of the operation uncovered something that caused the target shift.
A full PDF report is available for download here.



















