Monday, February 17, 2025
HomeComputer SecurityChinese State-Sponsored ATP 10 Hackers Launching Cyber Attack On U.S Utilities

Chinese State-Sponsored ATP 10 Hackers Launching Cyber Attack On U.S Utilities

Published on

SIEM as a Service

Follow Us on Google News

Researchers discovered a new malware dubbed “LookBack” distributed via spear-phishing email campaign to attack the entities in the United States.

Based on the telemetry data, the attack believed to be initiated by Chinese sponsored threat actors also known as APT 10, one of the sophisticated hacking group in the world and the group has a long history of targeting commercial activities including aviation, satellite, and maritime technology, industrial factory automation, finance, telecommunications and more.

Spear-phishing emails impersonate the US-based engineering licensing board and the email delivered from the threat actors who controlled domains nceess [.]com. Nceess[.]com which appears to be owned by the US National Council of Examiners for Engineering and Surveying.

Further analysis revealed that the spear-phishing emails carried malicious word documents with the macro that tricks victims to enable it to drop the malware dubbed “Lookback”.

Researchers from Proofpoint found a remote access trojan associated with a proxy mechanism to establish a connection with the command & control server to communicate further operations.

Threat actors using a sophisticated delivery mechanism to deliver the Lookback malware to target the utilities and critical infrastructure.

LookBack  Malware  Exploitation  Process

Through Malicious document, threat actors try to install the LookBack malware by tricking victims to enable the VBA macro which drops the three Privacy Enhanced Mail (PEM) files to the host: tempgup.txt, tempgup2.txt, and tempsodom.txt. 

The result of LookBack malware execution, macro launches GUP.exe and the libcurl.dll loaders separately.

LookBack malware developed to act as a remote access trojan which is written in C++ that relies on a proxy communication tool which is responsible to transfer data from infected host to command & control server.

This RAT functionality is powerful enough to enumerate of services viewing of process, system, and file data; deleting files; executing commands; taking screenshots; moving and clicking the mouse; rebooting the machine and deleting itself from an infected host, Proofpoint reported.

Following components are carried by LookBack RAT,

A command and control proxy tool (referred to as GUP)  

A malware loader comprised of a legitimate libcurl.dll file with one export function modified to execute shellcode.  

A communications module (referred to as SodomNormal) which creates a C&C channel with the GUP proxy tool.  

A remote access Trojan component (referred to as SodomMain), which is delivered following decoding the initial beacon response received via the GUP proxy tool and the SodomNormal local host proxy module.  

A that is described in these components masquerade as legitimate opensource software and the legitimate GUP.exe versions were utilized that were digitally signed by Notepad++

The SodomMain module is LookBack malware’s remote access Trojan module that can send and receive numerous commands to the command and control server that including,

Get process listing 
Kill process 
Executes cmd[.] exe command 
Gets drive type 
Find files 
Read files 
Delete files 
Write to files 
Execute files 
Enumerate services 
Starts services 
Delete services 
Takes a screenshot of desktop 
Move/Click Mouse and take a screenshot  
Exit 
Removes self (libcurl[.] dll)  
Shutdown 
Reboot   

“The profile of this campaign is indicative of specific risk to US-based entities in the utility sector. Phishing emails leveraged the knowledge of the licensing bodies utilized within the utility sector for social engineering purposes that communicated urgency and relevance to their targets.” Proofpoint said.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity updates also you can take the Best Cybersecurity course online to keep yourself updated.

Also Read:

Chinese APT 10 Group Hacked Nearly 10 Telecom Networks and Stealing Users Call Records, PII, Credentials, Email Data and more

Chinese APT 10 Hackers Attack Government and Private Organizations Through Previously Unknown Malware

Chinese Hackers from APT 10 Hacking Group Charged for a Cyber Attack on NASA

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Android’s New Security Feature Prevents Sensitive Setting Changes During Calls

Phone scams are becoming more sophisticated with advancements in AI-driven speech tools, making it...

Hackers Exploit Microsoft Teams Invites to Gain Unauthorized Access

The Microsoft Threat Intelligence Center (MSTIC) has uncovered an ongoing and sophisticated phishing campaign...

Meta’s Bug Bounty Initiative Pays $2.3 Million to Security Researchers in 2024

Meta's commitment to cybersecurity took center stage in 2024 as the tech giant awarded...

Google Chrome Introduces AI to Block Malicious Websites and Downloads

Google has taken a significant step in enhancing internet safety by integrating artificial intelligence...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

Android’s New Security Feature Prevents Sensitive Setting Changes During Calls

Phone scams are becoming more sophisticated with advancements in AI-driven speech tools, making it...

Hackers Exploit Microsoft Teams Invites to Gain Unauthorized Access

The Microsoft Threat Intelligence Center (MSTIC) has uncovered an ongoing and sophisticated phishing campaign...

Meta’s Bug Bounty Initiative Pays $2.3 Million to Security Researchers in 2024

Meta's commitment to cybersecurity took center stage in 2024 as the tech giant awarded...