Cyber Hacking News

Chinese hackers target script kiddies with info-stealer trojan

0

A new campaign was discovered by security researchers that is attributed to the Chinese “Tropic Trooper” hacking group, which employs a novel loader called Nimbda and a new variant of the Yahoyah trojan.

The trojan is bundled in a greyware tool named ‘SMS Bomber,’ which is used for denial of service (DoS) attacks against phones, flooding them with messages.

According to researchers at Check Point, the threat actors also demonstrate in-depth cryptographic knowledge, extending the AES specification in a custom implementation.

By downloading a malicious version of SMS Bomber, which contains the tool’s binary and standard functionality, the infection starts. However, the download has been modified to include additional code that injects into a notepad.exe process.

The downloaded executable is actually the ‘Nimbda’ loader, which uses the SMS Bomber icon, and contains SMS Bomber as an embedded executable.

In the background, the loader injects shellcode into the notepad process to reach a GitHub repository, fetch an obfuscated executable, decode it, and then run it via process hollowing in ‘dllhost.exe.’

This payload is the new Yahoyah variant, which collects data about the host and sends it to the C2 server. The information collected by Yahoyah includes local wireless network SSIDs in the victim machine’s vicinity, computer name, MAC address, OS version, installed AV products and presence of WeChat and Tencent files.

The final payload, dropped by the Yahoyah executable, is encoded in a JPG image using steganography which is identified as ‘TClient,’ a backdoor Tropic Trooper used in past campaigns.

The encryption used to wrap Yahoyah is a custom implementation of AES, which performs the inverted sequence of round operations twice, so it was named by the CheckPoint as AEES.

This doesn’t make encryption stronger but makes analysis of the sample very difficult.

Tropic Trooper is a sophisticated threat actor focused on espionage, previously seen running phishing campaigns against Russian officials.

This campaign demonstrates Tropic Trooper’s capability to create any decoy needed for their operations, cryptographic knowledge, and malware development activity.

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

Yodel confirms cyberattack disrupting UK deliveries

Previous article

New MetaMask phishing campaign uses KYC lures to steal passphrases

Next article

You may also like

Comments

Leave a reply

Your email address will not be published. Required fields are marked *