A China-based advanced persistent threat (APT) group is deploying short-lived ransomware families as a decoy to cover up the true operational and tactical objectives behind its campaigns.
Secureworks has attributed the activity to a hacking group named Bronze Starlight which involves the deployment of post-intrusion ransomware such as LockFile, Atom Silo, Rook, Night Sky, Pandora, and LockBit 2.0.
The researchers reported that the ransomware could distract incident responders from identifying the threat actors’ real intent and reduce the likelihood of attributing the malicious activity to a government-sponsored Chinese threat group. In each case, the ransomware targets a small number of victims over a relatively less period of time before it ceases operations, supposedly permanently.
The hacking group Bronze Starlight which was active since mid-2021, is also tracked by Microsoft under the emerging threat cluster moniker DEV-0401.
The attack launched by the actor are characterized by the use of unpatched vulnerabilities affecting Exchange Server, Zoho ManageEngine ADSelfService Plus, Atlassian Confluence (including the newly disclosed flaw), and Apache Log4j.
Within a year, the group have cycled through as many as six different ransomware strains such as LockFile (August 2021), Atom Silo (October), Rook (November), Night Sky (December), Pandora (February 2022), and most recently LockBit 2.0 (April).
Also some similarities were spotted between LockFile and Atom Silo as well as between Rook, Night Sky, and Pandora — the latter three derived from Babuk ransomware, whose source code leaked in September 2021 — indicating the work of a common actor.
As DEV-0401 maintains and frequently rebrands their own ransomware payloads, they can appear as different groups in payload-driven reporting and evade detections and actions against them.
Upon gaining a foothold inside a network, Bronze Starlight is depends on techniques like using Cobalt Strike and Windows Management Instrumentation (WMI) for lateral movement. Recently, the group has replaced Cobalt Strike with the Sliver framework in their attacks.
The group also uses HUI Loader to launch next-stage encrypted payloads such as PlugX and Cobalt Strike Beacons, the latter of which is employed to deliver the ransomware, but not before obtaining privileged Domain Administrator credentials.
The researchers explained that the use of HUI Loader to load Cobalt Strike Beacon, the Cobalt Strike Beacon configuration information, the C2 infrastructure, and the code overlap suggest that the same threat group is associated with these five ransomware families.
Both HUI Loader and PlugX, alongside ShadowPad, are malware which are usually used by Chinese nation-state adversarial collectives, which suggests the possibility that Bronze Starlight is more geared towards espionage than immediate monetary benefits.
Also based on the victims that spans across the different ransomware strains shows that a majority of the targets are likely to be of more interest to Chinese government-sponsored groups focused on long-term intelligence gathering.
The key victims confine pharmaceutical companies in Brazil and the U.S., a U.S.-based media organization with offices in China and Hong Kong, electronic component designers and manufacturers in Lithuania and Japan, a law firm in the U.S., and an aerospace and defense division of an Indian conglomerate.














Comments