ALFA Wordpress attack
Menu ALFA Wordpress attack
 

ALFA Wordpress attack

This is a remote access threat launched at Wordpress installs.

The following was observed when I was monitoring server logs:

It looks like a "fishing expedition" looking for files related to the Alfa Team

Top

" ALFA TEaM is an Iranian associated group who create various web malware including PHP shells and in the past one such tool, ALFA TEaM Shell, has been used by threat actors like APT 33. APT 33 is a suspected Iranian group that has targeted various industries in the past.

You can read a detailed analysis from FireEye on the group APT 33 and their tactics here. "

APT33

APT33 seem to be an Iranian Cyber-Security group that I have seen making probes on this website. The probes apparently are looking for vulnerabilites in Wordpress installations. Seeing as I don't use Wordpress, and I have stated why I have problems with Wordpress, there is little for me or vistors to this website to be concerned with.

The ALFA attack is attempt to compromise a Wordpress built website so that subversive posts can be made by hostile agents.

The ALFA teams process

A snippet from my server log can be seen at the top of this page.

alfacgiapi perl.alfa

The probe for alfacgiapi/perl.alfa seems to indicate that there was an expectation that this file existed on my server.

What Trendmicro say:

" WordPress is a well-known open-source content management system (CMS) used for creating websites and personal blogs. The CMS is estimated to be used by 35% of all websitesopen on a new tab today, which makes it an ideal target for threat actors. A weak point in the platform is all it takes to allow an attacker to break a website’s security — a risk compounded by security issues brought about by poor cybersecurity hygiene.

Attacks against CMS platforms are not news, but threat actors still find that attacking sites is an effective way to gain a foothold on organizations’ assets to use for malicious purposes. This blog post lists different kinds of attacks against WordPress, by way of payload examples we observed in the wild, and how attacks have used hacked admin access and API, Alfa-Shell deployment, and SEO poisoning to take advantage of vulnerable sites.

As I have been saying for a long time, CMS systems are bad news when it comes to attracting interest from the Chinese, Russians and even the Iranian's. Wordpress is particularly a good target. Not only is it a hackers target it is a great way of those so inclined to post comments on legitamet blogs that can spread propaganda.

What Mandiant say:

When discussing suspected Middle Eastern hacker groups with destructive capabilities, many automatically think of the suspected Iranian group that previously used SHAMOON – aka Disttrack – to target organizations in the Persian Gulf. However, over the past few years, we have been tracking a separate, less widely known suspected Iranian group with potential destructive capabilities, whom we call APT33. Our analysis reveals that APT33 is a capable group that has carried out cyber espionage operations since at least 2013. We assess APT33 works at the behest of the Iranian government.

Links

References:

  • 1 - APT33 insights into iranian cyber espionage - https:// www.mandiant.com/resources/blog/apt33-insights-into-iranian-cyber-espionage
  • 2 - ALFA TEaM v4.1 Web Shell New Features - https:// lukeleal.com/research/posts/ alfa-shell-4-tesla/
  • 3 - APT33 - https:// attack.mitre.org/groups/ G0064/
  • 4 - Looking into attacks and techniques used against Wordpress sites - https:// www.trendmicro.com /en_gb/research/19/l/ looking-into-attacks-and-techniques-used-against-wordpress-sites.html - trendmicro.com

Site design by Tempusfugit Web Design -