Last week, security researchers from Trend Micro published a report on a targeted cyber espionage campaign dubbed “Siesta.” Experts from FireEye said today that they have uncovered a connection between the Siesta campaign and the notorious Chinese cyber espionage group known as APT1.
Siesta targets a variety of companies, including energy organizations, banking institutions, healthcare services, telecommunications, government, defense, and transportation. Attackers use a variety of techniques to compromise these companies, but these tactics are not always that sophisticated.
In a case study, Trend Micro details a spear phishing email attack designed to trick company executives into installing malware.
The name of the campaign, Siesta, comes from the Spanish word meaning “short sleep.” The name is no coincidence as the malware used in the campaign is designed to execute “Sleep” commands and remain dormant for a specified time.
FireEye researchers report that the group that created Siesta either used the same tactics and tools as APT1 or it is APT1 itself that is carrying out these attacks.
FireEye also analyzed the same campaign (Siesta) and reports that it began on February 20, 2014 against a telecommunications company. Spear phishing emails with links leading to files located on “legitimate” websites are tactics, techniques, and procedures used by the APT1 group.
A hash of the message sender detected by Trend Micro has also been observed in a series of APT1 attacks, some of which date back to 2011.
However, researchers are not so sure that APT1 is behind the Siesta attacks.
"While we are not certain that APT1 is responsible for the Siesta activity, this campaign appears to have a number of characteristics that resemble previous APT1 campaigns."

