Saturday, May 17, 2025
HomeMalwareChinese APT 10 Hackers Attack Government and Private Organizations Through Previously Unknown...

Chinese APT 10 Hackers Attack Government and Private Organizations Through Previously Unknown Malware

Published on

SIEM as a Service

Follow Us on Google News

Researchers discovered a new malware attacker against the government and private organizations from Chinese cyber espionage group APT10 using previously unknown malware with a new set of unique activities.

Based on telemetry data, attackers launching two different loader variants and various other payloads with similar Tactics, Techniques that were used for other attacks by APT10.

APT10 hacking group is targeting mostly commercial activities including aviation, satellite and maritime technology, industrial factory automation, automotive supplies, laboratory instruments, banking, and finance industries.

- Advertisement - Google News

Recently, two Chinese hackers who are behind the APT10 hacking Group charged for compromising intellectual property and confidential business information from government agencies NASA & other 45 US Tech giants.

Threat actors using typosquatting domain names similar to real, legitimate tech companies to trick victims and inject the payload to the target machine.

APT10 Malware Infection Process

Initially, Once the dropper variants entered into the system, they deliver different payloads with the help of following files.

  • jjs.exe – legitimate executable
  • jli.dll – malicious DLL
  • msvcrt100.dll – legitimate Microsoft C Runtime DLL
  • svchost.bin – binary file

Researchers also discovered PlugX and Quasar, two different Remote Access Trojans among these variants.

“PlugX is a modular structured malware that has many different operational plugins such as communication compression and encryption, network enumeration, files interaction, remote shell operations and more.”

During the first stage of the infection process, a loader starts abusing the legitimate executable process (  jjs.exe ) and inject the malicious DLL inside, a method is known as DLL Side-Loading.

APT10
 Loader’s execution flow

According to Ensilo Research, “The malicious DLL maps the data file, svchost.bin, to memory and decrypt it. The decrypted content is a shellcode that is injected into svchost.exe and contains the actual malicious payload.”

The first variant delivers both PlugX and Quasar and the downloaded payload is a modified Quasar RAT to extract passwords from the victim machine using an addition called SharpSploit , a .NET post-exploitation library written in C#.

Another PlugX collects information about the infected machine such as the computer name, username, OS version, RAM usage, network interfaces, and resources. 

Researchers uncovered the APT10 attackers using C&C servers located in South Korea and some of the mentioned domain mappings were recently updated. Also, the certificate embedded in the Quasar sample.

IOCS

Loader v1:
41542d11abf5bf4a18332e9c4f2c8d1eb5c7e5d4298749b610d86caaa1acb62c (conhost.exe downloader jli.dll)
29b0454db88b634656a3fc7c36f318b126a83ae8fb7f73fe9ff349a8f8536c7b (conhost.exe downloader svchost.bin)
02b95ef7a33a87cc2b3b6fd47db03e711045974e1ecf631d3ba9e076e1e374e9 (PlugX jli.dll)
e0f91da52fdc61757f6a3f276ae77b01d2d1cc4b3743629c5acbd0341e5de80e (PlugX svchost.bin)

Loader v2:
f13536685206a94a8d3938266f100bb2dffa740a202283c7ea35c58e6dbbb839 (PlugX jli.dll)
c8d86e9f486d23285b744279812ef9047a0908e39656c2ea4cdf3e182f80e11d (PlugX svchost.bin)

.NET Downloader (conhost.exe):

96649c5428c874f2228c77c96526ff3f472bc2425476ad1d882a8b55faa40bf5

Quasar RAT:
0644e561225ab696a97ba9a77583dcaab4c26ef0379078c65f9ade684406eded

Domains:

update[.]kaspresksy[.]com
download[.]kaspresksy[.]com
api[.]kaspresksy[.]com
ffca[.]caibi379[.]com
update[.]microsofts[.]org
ppit[.]microsofts[.]org
cahe[.]microsofts[.]org

IP Addresses:

27.102.128.157
27.102.127.80
27.102.127.75
27.102.66.67
27.102.115.249

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity updates also you can take the Best Cybersecurity courses online to keep your self-updated.

Also Read:

Chinese Cyber Espionage Group APT10 Delivers UPPERCUT Backdoor Via Malicious Word Documents

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

VMware ESXi, Firefox, Red Hat Linux & SharePoint Hacked – Pwn2Own Day 2

Security researchers demonstrated their prowess on the second day of Pwn2Own Berlin 2025, discovering...

Critical WordPress Plugin Flaw Puts Over 10,000 Sites of Cyberattack

A serious security flaw affecting the Eventin plugin, a popular event management solution for...

Sophisticated NPM Attack Leverages Google Calendar2 for Advanced Communication

A startling discovery in the npm ecosystem has revealed a highly sophisticated malware campaign...

New Ransomware Attack Targets Elon Musk Supporters Using PowerShell to Deploy Payloads

A newly identified ransomware campaign has emerged, seemingly targeting supporters of Elon Musk through...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Printer Company Distributes Malicious Drivers Infected with XRed Malware

Procolored, a printer manufacturing company, has been found distributing software drivers infected with malicious...

Frigidstealer Malware Targets macOS Users to Harvest Login Credentials

An macOS users, a new information-stealing malware dubbed FrigidStealer has emerged as a formidable...

SSH Auth Key Reuse Uncovers Advanced Targeted Phishing Campaign

A meticulously orchestrated phishing campaign targeting Kuwait's fisheries, telecommunications, and insurance sectors has been...