Friday, March 29, 2024

Chinese-linked APT Hackers Spying Orgs Over 10 Years Using DNS Tunneling To Evade Detection

Security researchers at SentinelLabs recently discovered that a Chinese-speaking APT adversary has been actively operating all of its operations since 2013 and has been executing all of its attacks since that time.

The hacking group is known as the “Aoqin Dragon” is focused on cyber-espionage, and their target sectors include:- 

  • Government
  • Education
  • Telecommunication organizations (Located in Singapore, Hong Kong, Vietnam, Cambodia, and Australia.)

Throughout the years, the techniques of threat actors have improved and evolved. However, some concepts and tactics remain the same.

Intrusion techniques

It has been revealed that in the time since Aoqin Dragon was first spotted, there were three distinct infection chains that it implemented. The oldest and most widespread of these attacks, used between 2012 and 2015, exploited vulnerabilities in Microsoft Office files, and the flaws exploited are known:-

  1. CVE-2012-0158 
  2. CVE-2010-3333

As a result of this attack tactic, the security firm, FireEye was able to detect a spear-phishing campaign, coordinated by the Chinese-sponsored, “Naikon Group.” 

While this Chinese-sponsored threat group targeted a government agency in the Asia-Pacific region (APAC) and the US think tank in 2014.

Malware executables are masked with fake anti-virus icons to make it appear as if they were legit anti-virus products, tricking the user into running them, and then executing a malicious dropper on the target system.

The use of removable disk shortcut files has become increasingly important for Aoqin Dragon since its initial release in 2018. When clicked, it executes a DLL hijacking and loads an encrypted payload to create backdoors, which enables the backdoor to become operational.

In this particular case, the “Evernote Tray Application” is the name that the malware runs under and was executed as soon as the system got activated. Its payload is copied onto other devices on the network of the target as soon as the loader detects removable devices. As a result, they are also infected by the payload as well.

As noted earlier, the malware is displayed with the name tag of “Evernote Tray Application” and then executed when the system gets started. The loader copies the payload on removable devices in order to infect other devices through the target’s network if it detects removable devices.

Tools and commands used

To make it more difficult for the group’s data thefts and detect their identity, they use the following tools when copying files from compromised devices:-

  • Themida wrapping
  • Heyoka exfiltration tool
  • Exfil tool

It has been reported that the malware developers at Aoqin Dragon have revised Heyoka in a way that authorizes it to be customized to sustain the following commands that we have mentioned below:-

  • open a shell
  • get host drive information
  • search file function
  • input data in an exit file
  • create a file
  • create a process
  • get all process information in this host
  • kill process
  • create a folder
  • delete file or folder

Cyberespionage group Aoqin Dragon has been active for nearly a decade now and has become a formidable force in global cybercrime. 

In order to provide insight into the evolution of this activity cluster, SentinelLabs will continue to track it.

You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity updates

Website

Latest articles

Beware Of Weaponized Air Force invitation PDF Targeting Indian Defense And Energy Sectors

EclecticIQ cybersecurity researchers have uncovered a cyberespionage operation dubbed "Operation FlightNight" targeting Indian government...

WarzoneRAT Returns Post FBI Seizure: Utilizing LNK & HTA File

The notorious WarzoneRAT malware has made a comeback, despite the FBI's recent efforts to...

Google Revealed Kernel Address Sanitizer To Harden Android Firmware And Beyond

Android devices are popular among hackers due to the platform’s extensive acceptance and open-source...

Compromised SaaS Supply Chain Apps: 97% of Organizations at Risk of Cyber Attacks

Businesses increasingly rely on Software as a Service (SaaS) applications to drive efficiency, innovation,...

IT and security Leaders Feel Ill-Equipped to Handle Emerging Threats: New Survey

A comprehensive survey conducted by Keeper Security, in partnership with TrendCandy Research, has shed...

How to Analyse .NET Malware? – Reverse Engineering Snake Keylogger

Utilizing sandbox analysis for behavioral, network, and process examination provides a foundation for reverse...

GoPlus’s Latest Report Highlights How Blockchain Communities Are Leveraging Critical API Security Data To Mitigate Web3 Threats

GoPlus Labs, the leading Web3 security infrastructure provider, has unveiled a groundbreaking report highlighting...
Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Mitigating Vulnerability Types & 0-day Threats

Mitigating Vulnerability & 0-day Threats

Alert Fatigue that helps no one as security teams need to triage 100s of vulnerabilities.

  • The problem of vulnerability fatigue today
  • Difference between CVSS-specific vulnerability vs risk-based vulnerability
  • Evaluating vulnerabilities based on the business impact/risk
  • Automation to reduce alert fatigue and enhance security posture significantly

Related Articles