Earth Preta Hackers Abuses Google Drive to Deploy DOPLUGS Malware

Threat actors abuse Google Drive for several malicious activities due to its widespread use, easy file sharing, and collaboration features.

These things provide a convenient platform to host and distribute malware. Integration with legitimate services makes detecting and blocking malicious content challenging.

Cybersecurity researchers at Check Point recently found SMUGX in July 2023, linked to Earth Preta, hitting Europe. They also found a phishing email with PlugX in Taiwan tied to SMUGX.

Researchers found a new variant, DOPLUGS, which differs from typical PlugX and is mainly used for downloading. 

It employs the KillSomeOne module and was first reported by Sophos in 2020. Earth Preta campaign researchers analyze DOPLUGS, noting its backdoor commands, integration with KillSomeOne, and changes over time.

Document
Live Account Takeover Attack Simulation

How do Hackers Bypass 2FA?

Live attack simulation Webinar demonstrates various ways in which account takeover can happen and practices to protect your websites and APIs against ATO attacks .

Technical analysis

DOPLUGS files found since July 2023 indicate victims from Taiwan and Mongolia. File names suggest social engineering tied to recent events, like the January 2024 Taiwanese presidential election.

The “水源路二至五期整建住宅都市更新推動說明.pdf” decoy file relates to a Taiwanese urban renewal project in traditional Chinese.

The decoy document (Source – Trend Micro)

The Үер усны сэрэмжлүүлэг.pdf decoy warns of floods in Mongolia, in Mongolian. From 2022-2023 VirusTotal data (Asia-focused), Taiwan and Vietnam were prime targets, with fewer attacks in China, Singapore, Hong Kong, Japan, India, Malaysia, and Mongolia.

The decoy document ‘Үер усны сэрэмжлүүлэг.pdf’ (Source – Trend Micro)

The spear-phishing emails carry a Google Drive link, which leads to a password-protected archive with DOPLUGS malware. 

Disguised as documents, LNK files in the RAR archive download MSI files from https://getfiledown[.]com/vgbskgyu, which helps trigger subsequent file drops.

  • %localappdata%\MPTfGRunFbCn\OneNotem.exe (legitimate executable)
  • %localappdata%\MPTfGRunFbCn\msi.dll (malicious DLL file)
  • %localappdata%\MPTfGRunFbCn\NoteLogger.dat (encrypted payload)
Timeline of the malware evolution (Source – Trend Micro)

DOPLUGS includes four backdoor commands, as it is a downloader. Among them, one downloads the PlugX malware.

Infection flow of DOPLUGS (Source – Trend Micro)

Researchers discovered a new DOPLUGS variant with a KillSomeOne module for malware distribution, information collection, and USB-based document theft.

Unlike the previous version, it employs diverse infection methods. There are similarities with the prior DOPLUGS variant, but it has a distinctive infection approach.

Besides this, it has four components, including a malicious DLL and encrypted payload.

Earth Preta targets global government entities, especially in Asia-Pacific and Europe, using spear-phishing emails and Google Drive links. 

DOPLUGS malware is a vital tool for downloading PlugX. Besides this, a 2018 DOPLUGS variant was also discovered with KillSomeOne module integration, indicating ongoing tool improvement.

Since the Earth Preta remains active, the security teams should stay vigilant about Earth Preta’s tactics.

You can block malware, including Trojans, ransomware, spyware, rootkits, worms, and zero-day exploits, with Perimeter81 malware protection. All are extremely harmful, can wreak havoc, and damage your network.

Stay updated on Cybersecurity news, Whitepapers, and Infographics. Follow us on LinkedIn & Twitter.

Tushar Subhra

Tushar is a Cyber security content editor with a passion for creating captivating and informative content. With years of experience under his belt in Cyber Security, he is covering Cyber Security News, technology and other news.

Recent Posts

LightSpy iOS Malware Enhanced with 28 New Destructive Plugins

The LightSpy threat actor exploited publicly available vulnerabilities and jailbreak kits to compromise iOS devices.…

1 day ago

ATPC Cyber Forum to Focus on Next Generation Cybersecurity and Artificial Intelligence Issues

White House National Cyber Director, CEOs, Key Financial Services Companies, Congressional and Executive Branch Experts…

3 days ago

New PySilon RAT Abusing Discord Platform to Maintain Persistence

Cybersecurity experts have identified a new Remote Access Trojan (RAT) named PySilon. This Trojan exploits…

3 days ago

Konni APT Hackers Attacking Organizations with New Spear-Phishing Tactics

The notorious Konni Advanced Persistent Threat (APT) group has intensified its cyber assault on organizations…

3 days ago

Google Chrome Security, Critical Vulnerabilities Patched

Google has updated its Chrome browser, addressing critical vulnerabilities that posed potential risks to millions…

3 days ago

Notorious WrnRAT Delivered Mimic As Gambling Games

WrnRAT is a new malware attack that cybercriminals have deployed by using popular gambling games…

4 days ago