Chinese security firm Qihoo 360 has revealed in a report an extensive hacking campaign targeting Kazakhstan.
The hacking campaign targeted both individuals and organizations. Key targets were: government agencies, military personnel, foreign diplomats, researchers, journalists, private companies, educators, religious figures, and individuals opposed to the government.
According to Qihoo 360, the hackers behind the campaign certainly had significant resources as well as the ability to develop private hacking tools and purchase expensive spyware.
In some cases, hackers sent victims emails with malicious attachments (spear-phishing), while in others they gained physical access to devices, which means there were people (organizational employees) in Kazakhstan who did this work.
Golden Falcon
Initially, Qihoo researchers thought it was a new hacking group and named it Golden Falcon (or APT-C-34). However, according to Kaspersky, it is more likely DustSquad ,which first appeared in 2017.
Last year, a report was published about this group, which said that hackers were sending phishing emails to victims and leading them to a malicious version of Telegram.
Those attacks were also focused on Kazakhstan. However, now different malware .
Qihoo researchers managed to gain access to a command and control (C&C) server , allowing them to obtain information and understand the group's activities.
The Chinese security firm discovered data belonging to victims. It was mainly office documents, which hackers stole from organizations' computers.
The hackers had sorted the stolen information into folders labeled with a city name. Researchers found data belonging to victims from 13 of Kazakhstan's largest cities.

The hackers had encrypted the data, but researchers said they were able to decrypt it. From the evidence, the researchers understood that the hackers were spying on foreign nationals in Kazakhstan, such as students and Chinese diplomats.
Expensive hacking tools
Qihoo discovered that the hackers mainly used two tools for their attacks. The first was a version of RCS (Remote Control System), a surveillance kit sold by the Italian company HackingTeam. The second was a backdoor trojan, called Harpoon, which was likely developed by the group itself.
In 2015, the RCS source code was leaked, but Golden Falcon used a new version.
As for the second tool, the researchers noticed that it was a backdoor that had not been found anywhere else, leading them to conclude that it was most likely created by Golden Falcon.
The Chinese security firm managed to obtain a manual for this tool. According to it, it is a well-developed tool with many features and capabilities (e.g. keylogging, taking screenshots, stealing contacts, sending stolen data, and more).
Mobile Malware
The researchers also found some additional records from the group, such as contracts, which were likely signed by the members.
These contracts are not usually exposed on C&C servers. We do not know if the researchers found them there or from other sources.
One of the contracts shows a mobile surveillance toolkit called Pegasus. It is a powerful mobile hacking tool sold by NSO Group that affects both Android and iOS devices.
However, it is not certain whether the team ultimately procured the Pegasus.
The only thing certain is that the group had other malware for tracking mobile devices, which was purchased from HackingTeam.
Member tracking
Chinese researchers were able to track several members of Golden Falcon, mainly through digital signatures found in the above contracts. One of the members was a Russian programmer.
According to Qihoo and Kaspersky, this is a Russian APT (advanced persistent threat) hacking group.
However, other theories were also heard from other analysts. Some of them were that the group behind the hacking campaign was: (1) a Russian APT group, (2) a Kazakh intelligence agency spying on its citizens, (3) a Russian group spying on the Kazakh government.
There is, however, no sufficient evidence for any of these theories.
The use of HackingTeam’s surveillance software and contracts indicating possible collaboration with NSO suggest that it may be an authorized law enforcement agency. However, according to Qihoo, some of the victims of the campaign were Chinese government officials. This means that if it is indeed a Kazakh law enforcement agency, it has overstepped its jurisdiction.
