An advanced persistent threat (APT) actor tracked as ToddyCat has been linked to a string of attacks aimed at government and military entities in Europe and Asia since at least December 2020.
According to researchers from Kaspersky, the threat actors initially launched a cyber-espionage campaign against entities in Taiwan and Vietnam. The group was found targeting Microsoft Exchange servers with a zero-day exploit.
The attackers leveraged the exploit to establish the China Chopper web shell on the target systems, a malicious code commonly used by China-linked threat actors. This tool lets hackers to install a PHP, ASP, ASPX, JSP, and CFM webshells (backdoor) on publicly exposed web servers.
Once the China Chopper Web Shell is installed, the attackers will get complete access to a remote server through the exposed website. ToddyCat used the web shell to start the multi-stage attack chain that involved, the Samurai backdoor, and the ‘Ninja Trojan’.
From February 26 until early March, the attackers exploited the ProxyLogon vulnerability in attacks aimed at organizations across Europe and Asia.
The researchers believe that the group started exploiting the Microsoft Exchange vulnerability in December 2020, but unfortunately, they do not have sufficient information to confirm the hypothesis. All the targeted machines infected between December and February were Microsoft Windows Exchange servers; the attackers compromised the servers with an unknown exploit, with the rest of the attack chain the same as that used in March.
The first wave of attacks aimed at Microsoft Exchange Servers that were compromised with the sophisticated passive backdoor Samurai.
The Samurai backdoor is able to execute C# code and has a modular architecture, it allows operators to fully control the target system. The malware also allows to perform lateral movements and load other malicious payloads, including an unknown post-exploitation toolkit dubbed Ninja.
Ninja is a collaborative tool that lets multiple operators to work on the same machine simultaneously. It provides a large set of commands to remotely control the infected systems, avoid detection and perform a broad range of malicious activities.
Other attacks associated to this APT were against entities in multiple countries, including Afghanistan, India, Indonesia, Iran, Kyrgyzstan, Malaysia, Pakistan, Russia, Slovakia, Thailand, the U.K., and Uzbekistan.
Kaspersky concludes that ToddyCat is a sophisticated APT group that uses multiple techniques to avoid detection and thereby keeps a low profile. As the affected organizations are both governmental and military, it indicates that this group is focused on very high-profile targets and is probably used to achieve critical goals, likely related to geopolitical interests. Also the group shows strong interest in targets in Southeast Asia, and also impact targets in the rest of Asia and Europe.
Image Credit : Securelist
















Comments