Cyber Attacks

Redfly hackers compromises National Power Grid

0

Security researchers have revealed a new cyber-espionage campaign in which a threat group tracked as ‘Redfly’ compromised multiple computers used to run a national electricity grid organization in Asia.

The Redfly threat group identified by Symantec is not attributed to any nation, but two related groups – Blackfly and Greyfly – have been linked closely with China in previous reports.

Redfly used a bespoke version of popular modular remote access Trojan (RAT) ShadowPad. The RAT copied itself to disk in several locations, masquerading as VMware files and directories to stay hidden.

Another tool, Packloader, was used to load and execute shellcode, and a keylogger was installed under various names including winlogon.exe and hphelper.exe.

The evidence of ShadowPad malware activity in the organization’s network was found between February 28 and August 3, 2023, along with keyloggers and specialized file launchers.

ShadowPad, also known as PoisonPlug, is a follow-up to the PlugX remote access trojan and is a modular implant capable of loading additional plugins dynamically from a remote server as required to harvest sensitive data from breached networks.

ShadowPad extracts information about the host, executes commands, interacts with the file system and registry, and deploys new modules to extend functionality.

The threat actors were also found running PowerShell commands to gather information on the storage devices attached to the system, dump credentials from Windows Registry, while simultaneously clearing security event logs from the machine.

It is suspected that Redfly used stolen credentials in order to propagate the infection to other machines within the network.

Symantec said the campaign shares infrastructure and tooling overlaps with previously identified activity attributed to the Chinese state-sponsored group referred to as APT41 (aka Winnti), with Redly almost exclusively focusing on targeting critical infrastructure entities.

While the attackers’ intent to disrupt the power supply remains uncertain, the potential risk poses a significant threat.

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

Iranian hackers target entities with new Sponsor malware

Previous article

MetaStealer malware targets Intel-based macOS systems

Next article

You may also like

Comments

Leave a reply

Your email address will not be published. Required fields are marked *