Cyber Hacking News

Chinese hackers target Governments worldwide

0

An advanced persistent threat actor known as Mustang Panda has been linked to a spear-phishing campaign targeting government, education, and research sectors across the world.

Mustang Panda, also called Bronze President, Earth Preta, HoneyMyte, and Red Lich, is a China-based espionage actor believed to be active since at least July 2018.

According to cybersecurity firm Trend Micro, the attacks which were observed from May to October 2022 targeted organizations in Myanmar, Australia, the Philippines, Japan, and Taiwan.

The group is known for its use of malware such as China Chopper and PlugX to collect data from compromised environments.

In the recent attacks the group used Google accounts to send their targets email messages with lures that tricked them into downloading custom malware from Google Drive links.

The group used tactics to evade detection and adopt infection routines that lead to the deployment of bespoke malware families like TONEINS, TONESHELL, and PUBLOAD.

The hackers abused fake Google accounts to distribute the malware via spear-phishing emails, initially stored in an archive file (such as RAR/ZIP/JAR) and distributed through Google Drive links.

Initial access is facilitated through decoy documents that include geopolitical themes to lure the targeted organizations into downloading and triggering the malware.

In some cases, the phishing messages were sent from previously compromised email accounts belonging to specific entities.

The archive files, when opened, display a lure document to the victim, while stealthily loading the malware in the background through a method referred to as DLL side-loading.

The attack chains ultimately lead to the delivery of three malware families – PUBLOAD, TONEINS, and TONESHELL – which could download next-stage payloads and flying under the radar.

TONESHELL, the main backdoor used in the attacks, is installed through TONEINS and is a shellcode loader, with an early version detected in September 2021.

The hacker group is known to develop their own loaders in combination with existing tools like PlugX and Cobalt Strike for compromise.

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

Critical SQLi and access flaws spotted in Zendesk analytics service

Previous article

5 Million AirAsia passengers’ and employees’ data stolen

Next article

You may also like

Comments

Leave a reply

Your email address will not be published. Required fields are marked *