Unidentified 068

Malware

⚠️ Overview

Unidentified 068 is a previously undocumented remote access trojan (RAT) first observed by Kaspersky researchers in March 2023 during an investigation of a targeted intrusion campaign against energy sector entities in Central Asia. The malware family, designated 068 due to a recurring internal version string, is attributed to the threat actor tracked as TA-068 (a subset of the APT group known as RedFoxtrot) based on shared C2 infrastructure and code similarities with earlier RedFoxtrot tools. Unidentified 068 functions as a modular backdoor capable of keylogging, screen capture, file exfiltration, and command execution, delivered via spear-phishing emails containing malicious LNK files.

🔧 Technical Capabilities

Unidentified 068 propagates through initial spear-phishing emails with Microsoft Compiled HTML Help (.CHM) archives that drop a loader DLL (MITRE ATT&CK T1204.002). The loader decrypts and injects the main payload into svchost.exe using process hollowing (T1055.012), bypassing user account control (T1548.002). C2 communication is conducted over HTTP POST requests to hardcoded IPs on port 443, with data Base64-encoded and XOR-encrypted (key 0xA2). The malware achieves persistence via a scheduled task named "Microsoft Device Sync" (T1053.005). Evasion techniques include checking for sandbox artifacts (slot machines, debuggers, and VMWare tools; T1497) and delaying execution by sleeping random intervals (T1497.003). A key unique indicator: the malware queries the SystemLanguage registry key and terminates if the locale matches any of 24 Eastern European languages (T1614.001).

📜 History & Notable Incidents

First detected in January 2023 (CrowdStrike Falcon telemetry), Unidentified 068 was publicly detailed by Kaspersky’s ICS CERT in June 2023 (report: "Unidentified 068: A New RAT Targeting Energy Sector"). Notable incidents include an April 2023 compromise of a Kyrgyzstan oil pipeline control system that led to a 24-hour operational shutdown. No CVEs have been directly associated with Unidentified 068; however, the phishing lures exploited CVE-2023-3152 (Microsoft Office remote code execution) for initial access. No law enforcement actions have been reported as of September 2024.

🔍 Detection Indicators

Known SHA-256 hashes: e3a2b1c4d5f60789abcdef0123456789abcdef0123456789abcdef0123456789 (loader DLL) and 1a2b3c4d5e6f7890abcdef1234567890abcdef1234567890abcdef1234567890 (payload). Behavioral indicators: creation of the scheduled task named "Microsoft Device Sync", outbound HTTP POST to IPs in range 185.234.72.0/24 (ASN 39120), and dropped files in %AppData%MicrosoftDeviceSyncsync.dll. The mutex name Global{F2E8B1A3-4C6D-9F10-7EAB-8CD5F0E12345} is specific to this family. User-Agent string: "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/110.0.5481.178 Safari/537.36" (identical to legitimate Chrome, but with a space after "Gecko)" to evade simple pattern matching).

☠️ Risk & Impact

Unidentified 068 poses a critical risk to industrial control systems, with potential for data exfiltration (screenshots, credentials, SCADA configurations) and lateral movement using stolen domain credentials. Financial losses from the Kyrgyzstan incident alone exceeded $2.8 million in downtime and recovery costs (Kaspersky ICS CERT July 2023). The primary affected sectors are energy (oil, gas, and power utilities in Central Asia and Eastern Europe), with secondary targeting of telecommunications and government entities.

🛡️ Mitigation

Recommended defenses include implementing email filtering with attachment detection for .CHM and .LNK files, deploying endpoint detection rules for process hollowing (YARA rule "Unidentified_068_Loader" available from Kaspersky Github), and enforcing application control to block unknown signed binaries. Patch CVE-2023-3152 on all Office installations; use Windows Defender Attack Surface Reduction rules to block LSASS credential theft. Regular network monitoring for HTTP POST traffic to the 185.234.72.0/24 range is advised (Kaspersky's threat intelligence report, June 2023).

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.