In January, a series of attacks using new Windows malware was detected using several countries in Eastern Europe to backdoor entities in the government and military sectors, as well as firms in the defense industry.
There has been a link made between this campaign and an APT group tracked as TA428 based in China that targets organizations in Asia and Eastern Europe for information theft and espionage activities.
During the course of this campaign, dozens of targets were affected by hacking attempts designed to gain access to security control systems.
They even managed to gain complete control of their entire IT infrastructure when they hijacked their security management solution and were able to take over all of their computer networks and IT infrastructures.
A number of targets were targeted by the attack, including:-
It is important to note that all these targets were mostly based in several countries in East Europe, such as the following:-
Using spear phishing emails as a means of achieving their goal, the Chinese cyberspies succeeded in their goal. PortDoor malware is deployed through these emails in order to exploit the CVE-2017-11882 vulnerability in Microsoft Office.
There has also been evidence that Chinese-backed hackers utilized PortDoor as part of spear phishing attacks in April 2021. In order to attack a Russian Navy submarine design company, hackers hacked into the contractor’s systems.
A new malware strain named CotSam, which hasn’t been seen before, was installed on the system by the group in addition to other malware linked to TA428 in the past.
As part of the delivery of CotSam, the attackers also included with the payload a vulnerable version of Microsoft Word, which made it possible for the attackers to hide their tracks.
In order to obtain domain privileges and harvest confidential information from their victims’ enterprise networks, they move laterally through the victim’s network.
Then, they sent the ZIP archives encrypted and password-protected to C2 servers located in different countries using different encryption algorithms.
In spite of this, the C2 servers sent all of the stolen data to a second-stage server with an IP address in China, where it was forwarded to the third party.
A significant overlap in the TTPs of the campaign with the previous activity of this group is one of the points that connect it to TA428.
Moreover, other vendors have linked this Chinese APT group to malware and servers used in previous attacks. Here below we have mentioned all the recommendations:-
You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity updates.
Google has once again raised the bar for mobile security by introducing two new AI-powered…
Daren Li, 41, a dual citizen of China and St. Kitts and Nevis, and a…
Google Cloud has announced a significant step forward in its commitment to transparency and security…
GitLab has rolled out critical security updates to address multiple vulnerabilities in its Community Edition…
A newly discovered zero-day vulnerability, CVE-2024-43451, has been actively exploited in the wild, targeting Windows systems…
Keeping track of who has access and managing their permissions has gotten a lot more…