HomeSecurityAPT10 hackers return with new loaders and new payload versions

APT10 hackers return with new loaders and new payload versions

APT10 The Chinese hacking, known as APT10, is using two new malware loaders and new versions of known payloads to carry out attacks on government and private organizations in Southeast Asia.

The APT10 group emerged in 2009. Since then, it has carried out various attacks. In April 2017, security experts revealed a large hacking campaign, known as Operation Cloud Hopper. The campaign targeted many services and companies around the world.

In July 2018, FireEye detected new attacks by the APT10 group, in which hackers sent phishing emails to company employees, which contained tampered Word files, with the aim of installing the UPPERCUT backdoor on the victims' systems.

In September 2018, APT10 hackers organized a campaign targeting Japanese media outlets. However, researchers from FireEye managed to discover and block it.

The recent APT10 attacks took place in April 2019 and were detected by researchers at enSilo. The researchers found that the hackers used modified versions of known malware.

Experts linked the April attacks to the Chinese espionage group, as the two loader variants and payloads analyzeduse similar Tactics, Techniques, Procedures (TTPs). They also use code associated with the APT10 group.

The two loaders deliver different payloads to victims, however, both variants install the following files:

jjs.exe – legitimate executable, JVM-based javascript as part of the Java platform, which acted as a loader for the malware.
jli.dll – malicious DLL file
msvcrt100.dll – legitimate Microsoft C Runtime DLL
svchost.bin – binary file

Both variants serve various payloads, including the PlugX and Quasar RATs, which allow remote access to systems.

According to research, the payloads used by hackers in their latest attacks are still in the development stage.

Experts conclude that, although both variants of the loader have some differences, they nevertheless use the same mechanism for decrypting and transmitting the malicious code.

More technical details from enSilo.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS