Cyber Security News

Earth Preta Hackers Abuses Google Drive to Deploy DOPLUGS Malware

Threat actors abuse Google Drive for several malicious activities due to its widespread use, easy file sharing, and collaboration features.

These things provide a convenient platform to host and distribute malware. Integration with legitimate services makes detecting and blocking malicious content challenging.

Cybersecurity researchers at Check Point recently found SMUGX in July 2023, linked to Earth Preta, hitting Europe. They also found a phishing email with PlugX in Taiwan tied to SMUGX.

Researchers found a new variant, DOPLUGS, which differs from typical PlugX and is mainly used for downloading. 

It employs the KillSomeOne module and was first reported by Sophos in 2020. Earth Preta campaign researchers analyze DOPLUGS, noting its backdoor commands, integration with KillSomeOne, and changes over time.

Document
Live Account Takeover Attack Simulation

How do Hackers Bypass 2FA?

Live attack simulation Webinar demonstrates various ways in which account takeover can happen and practices to protect your websites and APIs against ATO attacks .

Technical analysis

DOPLUGS files found since July 2023 indicate victims from Taiwan and Mongolia. File names suggest social engineering tied to recent events, like the January 2024 Taiwanese presidential election.

The “水源路二至五期整建住宅都市更新推動說明.pdf” decoy file relates to a Taiwanese urban renewal project in traditional Chinese.

The decoy document (Source – Trend Micro)

The Үер усны сэрэмжлүүлэг.pdf decoy warns of floods in Mongolia, in Mongolian. From 2022-2023 VirusTotal data (Asia-focused), Taiwan and Vietnam were prime targets, with fewer attacks in China, Singapore, Hong Kong, Japan, India, Malaysia, and Mongolia.

The decoy document ‘Үер усны сэрэмжлүүлэг.pdf’ (Source – Trend Micro)

The spear-phishing emails carry a Google Drive link, which leads to a password-protected archive with DOPLUGS malware. 

Disguised as documents, LNK files in the RAR archive download MSI files from https://getfiledown[.]com/vgbskgyu, which helps trigger subsequent file drops.

  • %localappdata%\MPTfGRunFbCn\OneNotem.exe (legitimate executable)
  • %localappdata%\MPTfGRunFbCn\msi.dll (malicious DLL file)
  • %localappdata%\MPTfGRunFbCn\NoteLogger.dat (encrypted payload)
Timeline of the malware evolution (Source – Trend Micro)

DOPLUGS includes four backdoor commands, as it is a downloader. Among them, one downloads the PlugX malware.

Infection flow of DOPLUGS (Source – Trend Micro)

Researchers discovered a new DOPLUGS variant with a KillSomeOne module for malware distribution, information collection, and USB-based document theft.

Unlike the previous version, it employs diverse infection methods. There are similarities with the prior DOPLUGS variant, but it has a distinctive infection approach.

Besides this, it has four components, including a malicious DLL and encrypted payload.

Earth Preta targets global government entities, especially in Asia-Pacific and Europe, using spear-phishing emails and Google Drive links. 

DOPLUGS malware is a vital tool for downloading PlugX. Besides this, a 2018 DOPLUGS variant was also discovered with KillSomeOne module integration, indicating ongoing tool improvement.

Since the Earth Preta remains active, the security teams should stay vigilant about Earth Preta’s tactics.

You can block malware, including Trojans, ransomware, spyware, rootkits, worms, and zero-day exploits, with Perimeter81 malware protection. All are extremely harmful, can wreak havoc, and damage your network.

Stay updated on Cybersecurity news, Whitepapers, and Infographics. Follow us on LinkedIn & Twitter.

Tushar Subhra Dutta

Tushar is a Cyber security content editor with a passion for creating captivating and informative content. With years of experience under his belt in Cyber Security, he is covering Cyber Security News, technology and other news.

Recent Posts

Alert! Palo Alto RCE Zero-day Vulnerability Actively Exploited in the Wild

In a recent security bulletin, Palo Alto Networks disclosed a critical vulnerability in its GlobalProtect Gateway, identified as CVE-2024-3400. This…

2 days ago

6-year-old Lighttpd Flaw Impacts Intel And Lenovo Servers

The software supply chain is filled with various challenges, such as untracked security vulnerabilities in open-source components and inconsistent update…

2 days ago

Hackers Employ Deepfake Technology To Impersonate as LastPass CEO

A LastPass employee recently became the target of an attempted fraud involving sophisticated audio deepfake technology. This incident underscores the…

2 days ago

Sisence Data Breach, CISA Urges To Reset Login Credentials

In response to a recent data breach at Sisense, a provider of data analytics services, the U.S. Cybersecurity and Infrastructure…

2 days ago

DuckDuckGo Launches Privacy Pro: 3-in-1 service With VPN

DuckDuckGo has launched Privacy Pro, a new subscription service that promises to enhance user privacy across the web. This innovative…

2 days ago

Cyber Attack Surge by 28%:Education Sector at High Risk

In Q1 2024, Check Point Research (CPR) witnessed a notable increase in the average number of cyber attacks per organization…

2 days ago