Wednesday, April 23, 2025
HomeCyber Security NewsAPT32 Hacker Group Attacking Cybersecurity Professionals Poisoning GitHub

APT32 Hacker Group Attacking Cybersecurity Professionals Poisoning GitHub

Published on

SIEM as a Service

Follow Us on Google News

The malicious Southeast Asian APT group known as OceanLotus (APT32) has been implicated in a sophisticated attack that compromises the privacy of cybersecurity professionals.

A recent investigation by the ThreatBook Research and Response Team revealed that a popular privilege escalation tool utilized by cybersecurity experts had been backdoored, leading to significant data breaches and identity leaks.

Methodology of the Attack

The attack, which was first identified in November 2024, involved the release of a Cobalt Strike exploit plugin embedded with a Trojan onto GitHub.

- Advertisement - Google News
plugin embedde
plugin embedde

The attackers employed a novel tactic by incorporating a malicious .suo file within a Visual Studio project. When unsuspecting users compile the project, the Trojan executes automatically, effectively compromising their systems.

Investigate Real-World Malicious Links, Malware & Phishing Attacks With ANY.RUN – Try for Free

The poisoned account, set up to resemble a legitimate security researcher from a prominent Chinese FinTech company, is linked to the malicious repository at GitHub.

Timeline and Execution

The OceanLotus group targeted Chinese cybersecurity researchers, with the attack commencing between mid-September and early October 2024.

 execution of malicious code.
 execution of malicious code.

On October 10, the rogue account registered on GitHub, strategically forking various legitimate security tools to lower the victims’ guard.

Within days, two malevolent projects were published, containing Chinese-language descriptions and aimed specifically at enticing local cybersecurity professionals.

Despite the attacker’s subsequent deletion of these projects, the poisoned code had already been integrated into other researchers’ repositories, making detection increasingly difficult.

The code is designed to execute malicious commands seamlessly while self-destructing to avoid detection.

ThreatBook’s extensive analysis revealed that the attack was not only sophisticated but indicative of OceanLotus’s evolving techniques.

By utilizing a combination of dll hollowing and base64 encoding, the malware establishes command-and-control communication via the Notion platform, cleverly circumventing traffic detection measures.

spear-phishing email
spear-phishing email

The research team provided numerous Indicators of Compromise (IOCs) derived from their analyses, enabling cybersecurity entities to enhance their defenses against such targeted threats.

ThreatBook’s suite of security tools—including the Threat Detection Platform (TDP) and Cloud Sandbox—has been instrumental in identifying and mitigating the effects of this attack.

The OceanLotus group’s use of GitHub for conducting such targeted cyber operations raises urgent awareness regarding software supply chain vulnerabilities.

As the cybersecurity landscape becomes increasingly complex, professionals must maintain vigilance and utilize robust security practices to protect sensitive information.

Cybersecurity professionals must remain informed and proactive in safeguarding their tools and identities against such pernicious threats.

Find this News Interesting! Follow us on Google NewsLinkedIn, and X to Get Instant Updates!

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Latest articles

CrowdStrike Launches Falcon® Privileged Access with Advanced Identity Protection

CrowdStrike today announced the general availability of Falcon® Privileged Access, a breakthrough module in...

Zyxel Releases Patches for Privilege Management Vulnerabilities in Firewalls

Zyxel, a leading provider of secure networking solutions, has released critical security patches to...

Marks & Spencer Confirms Cyberattack Disrupting Payments and Online Orders

Leading British retailer Marks & Spencer Group plc (M&S) has confirmed it has been...

CISA Issues Five ICS Advisories Highlighting Critical Vulnerabilities

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has released five urgent advisories on...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

CrowdStrike Launches Falcon® Privileged Access with Advanced Identity Protection

CrowdStrike today announced the general availability of Falcon® Privileged Access, a breakthrough module in...

Zyxel Releases Patches for Privilege Management Vulnerabilities in Firewalls

Zyxel, a leading provider of secure networking solutions, has released critical security patches to...

Marks & Spencer Confirms Cyberattack Disrupting Payments and Online Orders

Leading British retailer Marks & Spencer Group plc (M&S) has confirmed it has been...