HomeSecurityChinese malware used in attacks on Australia

Chinese malware used in attacks on Australia

The Australian government made some statements late last week about the increased cyberattack activity the country has been facing – organizations and companies – recently. Behind the attacks on Australia is a “sophisticated” adversary that relies on slightly modified proof-of-concept code for older vulnerabilities, the government says. But unofficial sources seem to be blaming China.

Australia

The attacker targets public infrastructure with remote code execution exploits - a common option is outdated versions of the Telerik user interface (UI).

The set of tools used by the attacker makes it difficult to attribute the attacks to any specific direction, although the Australian government is confident that the enemy is someone associated with a state.

While the prime minister avoided assigning responsibility and simply said that there are not many who can carry out such attacks, senior sources seem to attribute responsibility to China.

One link to China is the fact that the threat actor uses malware associated with Chinese hacking groups, with some believed to be operating on behalf of the government.

In the list of indicators of compromise (IoC) provided by the ACSC, there is one sample that stands out. For example, Korplug – the name appears in a report by ESET on OceanLotus, which is believed to be based in Vietnam.

However, this particular sample is PlugX and ESET classifies it as Korplug because the two malware families share a specific DLL.

PlugX has been around since at least 2008 and has been mentioned in several reports from cybersecurity firms about attack campaigns linked to China. In the attacks reported by the ACSC, the malware was used to load a Cobalt Strike payload.

A report from Palo Alto Networks in 2015 linked the malware to DragonOK, which they linked to China two years later.

In a newer report published this year, Avira says the Mustang Panda threat group used PlugX and Cobalt Strike against victims in Hong Kong, Vietnam, China, and Australia.

There are at least 10 threat actors linked to China and involved in espionage campaigns that use PlugX. See below who these threat actors are:

  • APT41
  • Deep Panda
  • APT19
  • APT17
  • Suckfly
  • DragonOK
  • Mustang Panda
  • APT10
  • APT27
  • Roaming Tiger

The fact that it is used by so many groups makes it difficult to pin specific blame for the cyberattacks in Australia, but based on the presence of PlugX alone, it is easy to understand why senior government officials would single out China as the first suspect country.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS