• About
  • Privacy Policy
Open Security Labs
No Result
View All Result
No Result
View All Result
Open Security Labs
No Result
View All Result
Home Uncategorized

Coordinated Cyber Espionage Campaign by Chinese Hacking Groups

Hriday Nakka by Hriday Nakka
8th June 2024
in Uncategorized
0
Cyber Espionage
469
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter
  1. Emerging Threats to Remote Access VPNs
  2. Discovery and Nature of the Attack
  3. Activity Clusters
    1. Cluster Alpha (STAC1248):
    2. Cluster Bravo (STAC1807):
    3. Cluster Charlie (SCAT1305):
  4. High-Level Coordination
  5. Attribution and Persistence
  6. Continuous Monitoring and Defense
  7. Conclusion

Emerging Threats to Remote Access VPNs

Chinese state-sponsored hackers have been targeting a government agency in Southeast Asia since March 2023 in a sophisticated cyber espionage campaign known as Crimson Palace. The campaign involved new malware variants and three distinct activity clusters, suggesting a coordinated effort among various Chinese hacking groups.

Discovery and Nature of the Attack

The Crimson Palace campaign revealed that attackers had been using custom Nupakage malware, previously linked to the Chinese threat group Mustang Panda. The initial access point remains unclear, but related activities date back to early 2022.

Activity Clusters

Three distinct activity clusters in the campaign were associated with known Chinese threat groups such as BackdoorDiplomacy, REF5961, Worok, TA428, and the APT41 subgroup Earth Longzhi. These clusters are believed to have operated under a single organization.

Cluster Alpha (STAC1248):

Active from early March to August 2023, this cluster focused on deploying updated ‘EAGERBEE’ malware variants. The primary objective was to map server subnets and enumerate administrator accounts by conducting reconnaissance on Active Directory infrastructure. The activity used multiple persistent command and control (C2) channels, including Merlin Agent, PhantomNet backdoor, RUDEBIRD malware, and PowHeartBeat backdoor. To avoid detection, the attackers employed living-off-the-land binaries (LOLBins) and DLL side-loading with eight unique DLLs.

Cluster Bravo (STAC1807):

This cluster was active for only three weeks in March 2023, focusing on lateral movement and persistence. The attackers deployed a previously unknown backdoor called ‘CCoreDoor’ to establish external C2 communications, perform discovery, and dump credentials. They used renamed versions of signed side-loadable binaries to obfuscate the backdoor deployment and facilitate lateral movement, while also overwriting ntdll.dll in memory to unhook the endpoint protection agent process from the kernel.

Cluster Charlie (SCAT1305):

Active from March 2023 to at least April 2024, this cluster was involved in persistent access management and extensive reconnaissance. The attackers deployed multiple samples of an unidentified malware called ‘PocoProxy’ for persistent C2 communications. They also used the HUI loader to inject a Cobalt Strike Beacon into mstsc.exe, though these attempts were blocked. Additionally, they injected an LSASS login credential interceptor to capture credentials on domain controllers and conducted a mass analysis of Event Logs and automated ping sweeps to map users and endpoints across the network.

High-Level Coordination

These clusters operated during standard Chinese work hours (08:00 AM to 05:00 PM CST), indicating a high level of coordination. Activity spikes were observed on dates like June 12, 2023, a holiday in the target country, likely to catch defenders understaffed.

Attribution and Persistence

Although confirming high-confidence attribution is challenging, researchers believe the detected activity represents coordinated efforts by separate actors under a central authority pursuing Chinese state interests. Blocking the threat actor’s C2 implants in August 2023 halted Cluster Alpha activity. However, Cluster Charlie activity resumed after a brief silence, with adversaries attempting to breach the network again, this time with higher intensity and evasion tactics.

Continuous Monitoring and Defense

Continuous monitoring and robust cybersecurity measures are essential to defend against such coordinated cyber espionage campaigns. The use of multiple clusters and advanced malware variants highlights the evolving nature of cyber threats and the need for comprehensive security strategies.

Conclusion

The Crimson Palace campaign underscores the sophisticated and coordinated nature of cyber espionage efforts by state-sponsored actors. Organizations must remain vigilant and adopt advanced cybersecurity measures to protect their networks from such threats. Continuous monitoring, timely patching, and multi-layered defense mechanisms are crucial in mitigating the risks posed by these advanced persistent threats.

By understanding the tactics and techniques employed in this campaign, cybersecurity professionals can better prepare and defend against similar threats in the future. The collaboration and information sharing among cybersecurity researchers and organizations are vital in combating the ever-evolving landscape of cyber espionage.

Cyber Espionage

Share this:

  • Share on X (Opens in new window) X
  • Share on Facebook (Opens in new window) Facebook
  • Share on LinkedIn (Opens in new window) LinkedIn
  • Share on Telegram (Opens in new window) Telegram
  • Share on WhatsApp (Opens in new window) WhatsApp
  • Share on Mastodon (Opens in new window) Mastodon
  • Email a link to a friend (Opens in new window) Email

Related


Discover more from Open Security Labs

Subscribe to get the latest posts sent to your email.

Previous Post

Security Flaw in Check Point VPNs Risks Corporate Networks (0)

Next Post

New Mallox Ransomware variant – A danger to VMWare ESXi Environments (0)

Related Posts

CyberStalking
Uncategorized

The Dark Reality of Cyberstalking: How to Stay Safe on Social Media (0penBuckets)

29th December 2024
Volkswagen
Uncategorized

Massive Data Exposure from Volkswagen Electric Cars Highlights Cloud Security Risks (0penBuckets)

29th December 2024
amazon
Uncategorized

Dangerous Android Malware Found on Amazon Appstore – Steals Your Data in Disguise! (0penBuckets)

21st December 2024
Live Sports
Uncategorized

Massive Live Sports Piracy Ring Shut Down – Over 821 Million Visits Annually!”

21st December 2024
BellaCPP
Uncategorized

BellaCPP: The C++ Malware That’s Redefining Cyber Threats (0penBuckets)

21st December 2024
Docker
Uncategorized

Mastering Docker Security: Essential Tips for Unbreakable Containers (0penBuckets)

21st December 2024
Next Post
Mallox Ransomware

New Mallox Ransomware variant - A danger to VMWare ESXi Environments (0)

Leave a ReplyCancel reply

  • About
  • Privacy Policy

© 2024 OpenSecurityLabs.com

No Result
View All Result
  • About
  • Privacy Policy

© 2024 OpenSecurityLabs.com

Discover more from Open Security Labs

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from Open Security Labs

Subscribe now to keep reading and get access to the full archive.

Continue reading

Loading Comments...