Malware

Chinese hackers use new Linux version of the SideWalk Backdoor

0

State-backed Chinese hackers have developed a Linux variant for the SideWalk backdoor used against Windows systems belonging to targets in the academic sector.

The malware is attributed to the SparklingGoblin threat group, also known as Earth Baku, that is believed to be connected to the APT41 cyberespionage group.

The SideWalk Linux backdoor was initially being tracked as StageClient by security researchers at cybersecurity company ESET.

The researchers at 360 Netlab has spotted the early variant of the malware, and detailed two years ago in a blog post about the Specter botnet hitting IP cameras.

After analyzing Specter and StageClient, ESET researchers determined that both malware pieces have the same root and are Linux variants of SideWalk.

In 2021, researchers at Trend Micro documented new tools from a cyberespionage campaign attributed to APT41/Earth Baku, including the SideWalk backdoor, which they track as ScrambleCross.

Although SparklingGoblin is attacking targets in East and Southeast Asia, the group has also been hitting organizations outside these regions focusing the academic sector.

The SideWalk variants for Linux and Windows shows similarities in the way they function, the implementation of multiple components, and the payloads dropped on the compromised system.

Both the variants implemented the ChaCha20 encryption algorithm to “use a counter with an initial value of 0x0B,” something that is particular to SideWalk. They also had the same payload delivered through the dead-drop resolver string hosted in a Google Docs file.

SparklingGoblin has the capabilities to develop malware adapted to its needs, as evidenced by the SideWalk Linux variant. However, the group also has access to implants observed in operations attributed to other Chinese hacking groups.

According to the researchers, the SparklingGoblin has access to the ShadowPad backdoor and Winnti malware.

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

Zero-day in WPGateway WordPress plugin exploited in attacks

Previous article

Uber suffers internal system breach

Next article

You may also like

More in Malware

Comments

Leave a reply

Your email address will not be published. Required fields are marked *