Security researchers have revealed a new cyber-espionage campaign in which a threat group tracked as ‘Redfly’ compromised multiple computers used to run a national electricity grid organization in Asia.
The Redfly threat group identified by Symantec is not attributed to any nation, but two related groups – Blackfly and Greyfly – have been linked closely with China in previous reports.
Redfly used a bespoke version of popular modular remote access Trojan (RAT) ShadowPad. The RAT copied itself to disk in several locations, masquerading as VMware files and directories to stay hidden.
Another tool, Packloader, was used to load and execute shellcode, and a keylogger was installed under various names including winlogon.exe and hphelper.exe.
The evidence of ShadowPad malware activity in the organization’s network was found between February 28 and August 3, 2023, along with keyloggers and specialized file launchers.
ShadowPad, also known as PoisonPlug, is a follow-up to the PlugX remote access trojan and is a modular implant capable of loading additional plugins dynamically from a remote server as required to harvest sensitive data from breached networks.
ShadowPad extracts information about the host, executes commands, interacts with the file system and registry, and deploys new modules to extend functionality.
The threat actors were also found running PowerShell commands to gather information on the storage devices attached to the system, dump credentials from Windows Registry, while simultaneously clearing security event logs from the machine.
It is suspected that Redfly used stolen credentials in order to propagate the infection to other machines within the network.
Symantec said the campaign shares infrastructure and tooling overlaps with previously identified activity attributed to the Chinese state-sponsored group referred to as APT41 (aka Winnti), with Redly almost exclusively focusing on targeting critical infrastructure entities.
While the attackers’ intent to disrupt the power supply remains uncertain, the potential risk poses a significant threat.














Comments