Microsoft announced the seizure of 42 web domains used by a Chinese cyber espionage group that was targeting the organizations in the U.S. and 28 other countries in accordance with a legal warrant issued by a federal court in the U.S. state of Virginia.
The Redmond company attributed the malicious activities to a group it pursues as Nickel, and by the wider cybersecurity industry under the monikers APT15, Bronze Palace, Ke3Chang, Mirage, Playful Dragon, and Vixen Panda. The APT actor is believed to have been active since at least 2012.
Microsoft’s Corporate Vice President for Customer Security and Trust, Tom Burt, said that Nickel has targeted organizations in both the private and public sectors, including diplomatic organizations and ministries of foreign affairs in North America, Central America, South America, the Caribbean, Europe and Africa. There is often a correlation between Nickel’s targets and China’s geopolitical interests.
The hackers managed to maintain long-term access to the compromised machines and execute attacks for intelligence gathering purposes targeting unnamed government agencies, think tanks, and human rights organizations as part of a digital espionage campaign dating back to September 2019.
The threat actor is considered as highly sophisticated that used a multitude of techniques, including breaching remote access services and exploiting vulnerabilities in unpatched VPN appliances as well as Exchange Server and SharePoint systems to “insert hard-to-detect malware that facilitates intrusion, surveillance and data theft.”
After getting an initial foothold, Nickel deploys credential dumping tools and stealers such as Mimikatz and WDigest to hack into victim accounts. Then it delivers custom malware that allowed the actor to maintain persistence on victim networks over extended periods of time and conduct regularly scheduled exfiltration of files, execute arbitrary shellcode, and collect emails from Microsoft 365 accounts using compromised credentials.
The multiple backdoor families used for command and control are being tracked as Neoichor, Leeson, NumbIdea, NullItch, and Rokum.
The latest wave of attacks adds to a huge list of surveillanceware campaigns mounted by the APT15 group in recent years.
Microsoft concluded that as China’s influence around the world continues to grow and the nation establishes bilateral relations with more countries and extends partnerships in support of China’s Belt and Road Initiative, they assess that China-based threat actors will continue to target customers in government, diplomatic, and NGO sectors to gain new insights, likely in pursuit of economic espionage or traditional intelligence collection objectives.
















Comments