Cyber Attacks

Cyber espionage group targets Asian Governments and Organizations

0

Government and state-owned organizations in several Asian countries were targeted by a new group of espionage hackers as part of an intelligence gathering mission that has been ongoing since early 2021.

The Symantec Threat Hunter team, part of Broadcom Software reported that a distinct feature of these attacks is that the attackers leveraged a wide range of legitimate software packages in order to load their malware payloads using a technique known as DLL side-loading.

The campaign is exclusively targeted at government institutions related to finance, aerospace, defense, state-owned media, IT, and telecom firms.

Dynamic-link library (DLL) side-loading is a popular cyberattack method that leverages how Microsoft Windows applications handle DLL files. In these intrusions, a spoofed malicious DLL is planted in the Windows Side-by-Side (WinSxS) directory so that the operating system loads it instead of the legitimate file.

The attacks used old and outdated versions of security solutions, graphics software, and web browsers that are bound to lack mitigations for DLL side-loading, using them as a conduit to load arbitrary shellcode designed to execute additional payloads.

The software packages could also deliver tools to facilitate credential theft and lateral movement across the compromised network.

In one of the attacks against a government-owned organization in the education sector in Asia which lasted from April to July 2022, the adversary accessed machines hosting databases and emails, before accessing the domain controller.

The intrusion also used an 11-year-old version of Bitdefender Crash Handler (“javac.exe”) to launch a renamed version of Mimikatz (“calc.exe”), an open source Golang penetration testing framework called LadonGo, and other custom payloads on multiple hosts.

One among them includes a previously undocumented, feature-rich information stealer that can log keystrokes, capture screenshots, connect to and query SQL databases, download files, and steal clipboard data.

A publicly-available intranet scanning tool named Fscan was also used in the attack in order to exploit attempts leveraging the ProxyLogon Microsoft Exchange Server vulnerabilities.

The identity of the threat group is not known but it is said to have used ShadowPad in prior campaigns, a modular backdoor which is considered as a successor to PlugX (aka Korplug) and shared among many Chinese threat actors.

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

Iran-linked APT42 launched over 30 espionage attacks

Previous article

Zero-day in WPGateway WordPress plugin exploited in attacks

Next article

You may also like

Comments

Leave a reply

Your email address will not be published. Required fields are marked *