
A bank in Chinahas forced at least two Western businesses to install infected tax software on their systems.
This is a UK -based technology/software provider and a financial institution. Both companies had recently opened new offices in China.
Trustwave reports that after contacting the two businesses, it found that the bank had demanded that both companies install the infected software. The software, called Intelligent Tax , is used for local tax payments.
GoldenSpy Backdoor

Trustwave, which provides cybersecurity services provider , said it detected the malware after noticing suspicious network requests originating from its customers' network.
When researchers tested the Intelligent Tax software, they found that while it does indeed work to pay local taxes, it also has a hidden backdoor.
The backdoor in question, which the security firm has dubbed GoldenSpy, allows system-level access, allowing a remote attacker to connect to the infected system and execute Windows or upload and install other software.
Trustwave said it identified certain features that are often found in malware and have no legitimate uses anywhere else:
- GoldenSpy installs two identical versions of itself as permanent auto-start services. If one stops working, the other will start working. In addition, it uses an exeprotector module that monitors in case one of the versions is deleted. If this happens, it will download and run a new version. This makes it very difficult to remove from a system.
- Even if someone uninstalls the Intelligent Tax software, GoldenSpy will continue to operate as a Backdoor.
- GoldenSpy is not installed immediately on the victim's device. Instead, at least two hours must pass after Intelligent Tax is installed, and then the malware is downloaded without any updates, making it undetectable.
- GoldenSpy does not communicate with the tax software's network infrastructure (i-xinnuo [.] Com), but instead addresses ningzhidata [.] Com, a domain known to host other variants of the malware. After the first three attempts to communicate with the C&C server, it randomizes the signal times, a method used to avoid detection by security technologies.
- GoldenSpy operates with system-level privileges, making it extremely dangerous and capable of executing any software on the system.
Where did it come from?

Although Trustwave was able to detect the backdoor in Aisino Intelligent Tax Software, it was unable to discover who placed it there in the first place.
It could have come either from government hackers, who secretly placed it in the software, or from a rogue bank employee.
However, whoever is responsible for this particular Backdoor, it is very important that other companies that cooperate with Chinese banks be particularly careful, as there is a possibility that they too may be asked to install this software.
