Cyber Attacks

Chinese cyber-espionage group targets Asian telecom sector

0

A China-linked APT group, tracked as Moshen Dragon, was found targeting telecommunication service providers in Central Asia with ShadowPad and PlugX malware.

The security researchers from Sentinel Labs spotted overlap between the TTPs of the Moshen Dragon group with the ones of the Chinese Nomad Panda (aka RedFoxtrot).

PlugX and ShadowPad are mainly used by Chinese speaking hackers. According to a new report by Sentinel Labs, Moshen Dragon is a hacking group that can adjust its approach depending on the defenses they are facing.

Moshen Dragon’s TTPs involve the abuse of legitimate antivirus software belonging to BitDefender, Kaspersky, McAfee, Symantec, and Trend Micro to sideload ShadowPad and Talisman on compromised systems by using a technique called DLL search order hijacking.

The hacker group tries to sideload malicious Windows DLLs into antivirus products, steal credentials to move laterally, and eventually exfiltrate data from infected machines.

The hijacked DLL is used to decrypt and load the final ShadowPad or PlugX payload that resides in the same folder as that of the antivirus executable. Persistence is achieved by either creating a scheduled task or a service.

Once the attackers have established a foothold in an organization, they proceed with lateral movement by leveraging Impacket within the network, placing a passive backdoor into the victim environment, harvesting as many credentials as possible to insure unlimited access, and focusing on data exfiltration.

Sentinel Labs suggest that the threat actor generates a unique DLL for each of the machines it targets which indicates their sophistication and diligence.

The final goal of the threat actor is to exfiltrate data from as many systems as possible.

An interesting finding is that the loader analyzed by Sentinel Labs now, was spotted by Avast researchers in December 2021, who discovered it in a US government system.

This might indicate that Moshen Dragon has multiple targets or shifted its focus, or simply that multiple Chinese APTs use the particular loader.

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

Russian hackers target governments by compromising embassy emails

Previous article

Unpatched DNS bug affects millions of routers and IoT devices

Next article

You may also like

Comments

Leave a reply

Your email address will not be published. Required fields are marked *