Friday, May 23, 2025
HomeCyber Security NewsChinese APT Hackers Target Govt & Defense Orgs Using New Windows Malware

Chinese APT Hackers Target Govt & Defense Orgs Using New Windows Malware

Published on

SIEM as a Service

Follow Us on Google News

In January, a series of attacks using new Windows malware was detected using several countries in Eastern Europe to backdoor entities in the government and military sectors, as well as firms in the defense industry.

There has been a link made between this campaign and an APT group tracked as TA428 based in China that targets organizations in Asia and Eastern Europe for information theft and espionage activities.

During the course of this campaign, dozens of targets were affected by hacking attempts designed to gain access to security control systems. 

- Advertisement - Google News

They even managed to gain complete control of their entire IT infrastructure when they hijacked their security management solution and were able to take over all of their computer networks and IT infrastructures.

Victims Targeted

A number of targets were targeted by the attack, including:-

  • Industrial plants
  • Design bureaus
  • Research institutes
  • Government agencies
  • Ministries and departments 

It is important to note that all these targets were mostly based in several countries in East Europe, such as the following:-

  • Belarus
  • Russia
  • Ukraine
  • Afghanistan

Deployment of a New Backdoor

Using spear phishing emails as a means of achieving their goal, the Chinese cyberspies succeeded in their goal. PortDoor malware is deployed through these emails in order to exploit the CVE-2017-11882 vulnerability in Microsoft Office.

There has also been evidence that Chinese-backed hackers utilized PortDoor as part of spear phishing attacks in April 2021. In order to attack a Russian Navy submarine design company, hackers hacked into the contractor’s systems.

A new malware strain named CotSam, which hasn’t been seen before, was installed on the system by the group in addition to other malware linked to TA428 in the past.

As part of the delivery of CotSam, the attackers also included with the payload a vulnerable version of Microsoft Word, which made it possible for the attackers to hide their tracks.

In order to obtain domain privileges and harvest confidential information from their victims’ enterprise networks, they move laterally through the victim’s network.

Then, they sent the ZIP archives encrypted and password-protected to C2 servers located in different countries using different encryption algorithms.

Recommendations

In spite of this, the C2 servers sent all of the stolen data to a second-stage server with an IP address in China, where it was forwarded to the third party.

A significant overlap in the TTPs of the campaign with the previous activity of this group is one of the points that connect it to TA428.

Moreover, other vendors have linked this Chinese APT group to malware and servers used in previous attacks. Here below we have mentioned all the recommendations:-

  • Updating antivirus databases and software modules of your security solutions is key to ensuring your security software support centralized security policy management.
  • A policy that requires an administrator password is in place to disable protection when all security software components are enabled.
  • Restrict user access to Active Directory systems through Active Directory policies.
  • Ensure that only the systems that are on the OT network are allowed to connect to the network, including VPNs.
  • Ensure that all enterprise employees are trained on how to securely access and use internet resources within the enterprise.
  • Password policies with password complexity requirements should be enforced.
  • There is a need to change passwords on a regular basis in order to maintain security.
  • Security solutions dedicated to the ICS should be used.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity updates.

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

EU Targets Stark Industries in Cyberattack Sanctions Crackdown

The European Union has escalated its response to Russia’s ongoing campaign of hybrid threats,...

Venice.ai’s Unrestricted Access Sparks Concerns Over AI-Driven Cyber Threats

Venice.ai has rapidly emerged as a disruptive force in the AI landscape, positioning itself...

GenAI Assistant DIANNA Uncovers New Obfuscated Malware

Deep Instinct’s GenAI-powered assistant, DIANNA, has identified a sophisticated new malware strain dubbed BypassERWDirectSyscallShellcodeLoader. This...

Hackers Expose 184 Million User Passwords via Open Directory

A major cybersecurity incident has come to light after researcher Jeremiah Fowler discovered a...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

EU Targets Stark Industries in Cyberattack Sanctions Crackdown

The European Union has escalated its response to Russia’s ongoing campaign of hybrid threats,...

Venice.ai’s Unrestricted Access Sparks Concerns Over AI-Driven Cyber Threats

Venice.ai has rapidly emerged as a disruptive force in the AI landscape, positioning itself...

GenAI Assistant DIANNA Uncovers New Obfuscated Malware

Deep Instinct’s GenAI-powered assistant, DIANNA, has identified a sophisticated new malware strain dubbed BypassERWDirectSyscallShellcodeLoader. This...