Overview
‘TajMahal’ is a previously unknown and technically complex APT framework discovered by Kaspersky Lab in the fall of 2018. This complete spy framework consists of two packages named "Tokyo" and "Yokohama". It includes backdoors, loaders, orchestrators, C2 communicators, voice recorders, keyloggers, screen and webcam grabbers, document and encryption key stealers, and even the victim machine's own file indexer. We found up to 80 malicious modules stored in its encrypted virtual file system, which is one of the highest number of plugins we have seen in an APT tool set.
To highlight its capabilities, TajMahal is able to steal data from victims as well as from burned CDs in the printer queue. It can also request to steal specific files from a previously seen USB stick; the next time the USB is connected to the computer, the files will be stolen.
TajMahal has been developed and used for at least the past five years. The first known "legitimate" sample timestamp is from August 2013, and the last is from April 2018. The first confirmed date of seeing a TajMahal sample on a victim's machine is August 2014.
Technical Details
Kaspersky discovered two different types of TajMahal packages, claiming to be Tokyo and Yokohama. Kaspersky Lab discovered that victim systems were infected by two software packages. This suggests that Tokyo was used as a first-stage infection, with Tokyo deploying a fully functional Yokohama on the victim's system, with the framework shown below:
According to these victims The module on the attacker's machine identified the following interesting capabilities:
The ability to steal documents sent to the printer queue.
The data collected for victim reconnaissance includes backup lists of Apple mobile devices.
Take screenshots while recording VoiceIP application audio.
Steal and write the CD image.
Ability to steal files previously seen on removable drives when they become available again.
Steal Internet Explorer, Netscape Navigator, FireFox and RealNetworks cookies.
If removed from the frontend file or related registry value, it will reappear after a reboot with a new name and launch type.
Affiliation:
Conjecture 1: Russia
Kaspersky has only disclosed one victim so far, a diplomatic department in Central Asia , in previous reports, APT28 also began to carry out attacks against Central Asia.
Conjecture 2: United States:
As can be seen from the map, Central Asia is adjacent to Russia and China. This region has always been the target of the United States’ efforts to win over
And the framework Kabba is called a complex modular framework. According to the timestamp, it was compiled as early as 13 years ago. Kabba was first discovered in 18 years, and the American APT Attacks are usually stealthy and modular, making them difficult to detect. Flame was the first complex modular Trojan to be discovered
The above is the detailed content of How to use APT framework TajMahal. For more information, please follow other related articles on the PHP Chinese website!

Hot AI Tools

Undresser.AI Undress
AI-powered app for creating realistic nude photos

AI Clothes Remover
Online AI tool for removing clothes from photos.

Undress AI Tool
Undress images for free

Clothoff.io
AI clothes remover

Video Face Swap
Swap faces in any video effortlessly with our completely free AI face swap tool!

Hot Article

Hot Tools

VSCode Windows 64-bit Download
A free and powerful IDE editor launched by Microsoft

MantisBT
Mantis is an easy-to-deploy web-based defect tracking tool designed to aid in product defect tracking. It requires PHP, MySQL and a web server. Check out our demo and hosting services.

PhpStorm Mac version
The latest (2018.2.1) professional PHP integrated development tool

Zend Studio 13.0.1
Powerful PHP integrated development environment

mPDF
mPDF is a PHP library that can generate PDF files from UTF-8 encoded HTML. The original author, Ian Back, wrote mPDF to output PDF files "on the fly" from his website and handle different languages. It is slower than original scripts like HTML2FPDF and produces larger files when using Unicode fonts, but supports CSS styles etc. and has a lot of enhancements. Supports almost all languages, including RTL (Arabic and Hebrew) and CJK (Chinese, Japanese and Korean). Supports nested block-level elements (such as P, DIV),
