HomeSecurityEspionage campaign targets Pro-Tibet Group with ExileRAT

Spying campaign targets Pro-Tibet Group with ExileRAT

ExileRAT An online has been detected targeting subscribers to the mailing list belonging to the Central Tibetan Administration (CTA).

The CTA of India is an organization that officially represents the Tibetan government-in-exile. The territory of Tibet is administered by the People's Republic of China – but the CTA considers it an illegal military occupation. The CTA believes that Tibet is a separate independent nation.

Researchers with Cisco Talos recently discovered spam emails being sent to subscribers on the CTA mailing list. The emails, purporting to be from the CTA, claimed to be celebrating the upcoming 60th anniversary of the Dalai Lama’s exile on March 31st with an attached PowerPoint document titled “Tibet was never part of China.”.

However, the attached file is actually a malicious PPSX file, used as a dropper to allow an attacker to execute various JavaScript scripts and ultimately download a payload to the victims' systems. This payload is essentially a remote access trojan (RAT) called ExileRAT that steals computer information.

“Given the nature of this malware and its goals, it is likely designed for espionage purposes rather than financial gain,” researchers Warren Mercer, Paul Rascagneres and Jaeson Schultz said. “This is just one part of an ongoing trend of national actors working to spy on citizens for political reasons.”.

Researchers told Threatpost that so far they have no information about who is behind this campaign.

Method of infection

Craig Williams, director of social activity at Cisco Talos, told Threatpost that the company noticed the first sample from the campaign on January 30th.

Although the number of people on the CTA mailing list is not known, it appears that everyone on it received the email.

The mailing list infrastructure is run by India-based DearMail. Researchers said the attackers modified the standard “Reply-To” header so that replies were directed back to an email address belonging to the hackers (mediabureauin [at] gmail.com).

The email is called “Tibet-was-never-part-of-China.”.

Researchers said the email contained a malicious PPSX file attachment, intended to attack subscribers to the CTA mailing list. PPSX is a file format used to deliver an uneditable slide show, derived from a Microsoft PowerPoint document.

The attached document is a large set of slides (consisting of over 240 slides). Interestingly, the document is actually a copy of a legitimate PDF file, available for download from the CTA's tibet.net homepage, according to the researchers.

This attack exploits CVE-2017-0199, a very serious vulnerability in Microsoft Office, which allows remote attackers to execute arbitrary code via a crafted document. Once downloaded, the malicious PPSX file executes a Javascript that is responsible for downloading the payload, ExileRAT (“syshost.exe”), from the command and control (C2) server.

ExileRAT is capable of transferring information about the system (computer name, username, disk drives, network adapter, process name), executing or terminating processes.

Connecting to LuckyCat RAT

Interestingly, the infrastructure used for C2 was previously linked to the LuckyCat Android RAT. The LuckyCat Android RAT was used in 2012 against Tibetan activists.

“The newer version [Jan. 3] includes the same features as the 2012 version (file upload, download, information theft, and remote deletion) but adds many new features, such as file removal, application execution, audio recording, personal contact theft, SMS theft, location theft,” Cisco researchers said.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS