An advanced hacking group, which also works on behalf of third-party companies/competitors, has breached the information systems of an architectural firm involved in luxury real estate projects worth billions of dollars.
The hacking group carries out attacks, with the attack vector in this case being a malicious plugin for Autodesk 3ds Max software for creating 3D computer graphics.

According to Bitdefender's investigation, the unnamed victim is a major company that works with luxury real estate developers in the US, UK, Australia and Oman who work with leading architects and interior designers.
For this specific attack, the hacking group relied on the command and control (C2) infrastructure in South Korea, which recorded traffic from malware samples in multiple countries (USA, South Korea, Japan, South Africa), even suggesting selected victims in these regions.
Evidence discovered by security researchers shows a group providing advanced hacking services to various clients seeking detailed confidential information and data for high-value contracts.
Careful operation
In this case, the attack exploited a security flaw affecting multiple versions of Autodesk 3ds Max that allows code execution on a Windows system.
Earlier this month, Autodesk warned that there is an exploit for the MAXScript scripting utility in the form of a malicious plugin called “PhysXPluginMfx.” When loaded into 3ds Max, the plugin can infect other MAX files, thereby spreading them to other users on the network.
Unlike cybercriminal groups that seek immediate financial gain, this particular hacking group uses malware that collects details about the compromised information system (computer name, username) and steals sensitive information.
In addition to using tools that take screenshots and extract passwords and history data from Google Chrome, the hacker uses malware to steal files with specific extensions.
Bitdefender researchers estimate that the attacker compiles this file-stealing component for each victim to include it in the list of files they may select.
Keeping a small footprint
To remain undetected on a compromised machine, the hacker turned to an interesting trick that made the malicious script inactive if Task Manager or Performance Monitor was running.
Depending on how much "window area" was visible for these two applications, a flag was set to instruct the malware to sleep, thereby reducing CPU usage and placing it lower on the list of energy-intensive processes.
Also, file compression was only used on certain files. Data that would attract unnecessary attention if archived would be skipped by this feature.
Bitdefender's report today says that telemetry data shows that similar malware samples contacted the same C2 in South Korea less than a month ago.
While this can help connect with other functions, it is not the beginning of the team's activity schedule.
