HomeSecurityWaterbear malware used in attacks against government services

Waterbear malware used in attacks against government agencies

Researchers have identified a new Waterbear malware campaign in which Taiwan government agencies have been targeted with sophisticated attacks.

According to CyCraft researchers, the attacks took place in April 2020, and in an interesting twist, it appears that the attackers used malware already present on compromised servers – due to previous attacks – to develop their campaign.

The gang behind the Waterbear malware was previously linked to BlackTech, an advanced cyberattack group that generally attacks technology companies and government agencies across Taiwan, Japan , and Hong Kong.

Waterbear malware

Trend Micro researchers say that the modular malware is mainly used for lateral movement, decryption , and payload activation with the loader component. Last year, Waterbear gained the attention of the cybersecurity industry after implementing the API hooking technique to hide its activities by abusing security products.

In the latest wave, CyCraft says it exploited a vulnerability in a trusted data loss prevention (DLP) tool to load Waterbear. The job was made easier because malware remnants from previous attacks on the same targets had not been fully eradicated.

Attackers have been spotted attempting to use stolen credentials to access a targeted network. In some examples, endpoints were still compromised from previous attacks, and this was used to gain access to the victim's internal network and secretly establish a connection to the command-and-control (C2) server.

A vulnerability in the DLP tool was then used to perform DLL hijacking. As the software failed to verify the integrity of the DLLs it loaded, the malicious file was launched with elevated privileges.

This DLL then performed shellcode injection into various Windows system services, allowing the Waterbear loader to deploy additional malicious packages.

Another interesting aspect of the loader is the "resurrection" of an old antivirus technique ,according to the researchers. Known as "Heaven's Gate," the misdirection technique is used to trick operating systems into executing 64-bit code, even when it is declared as a 32-bit process. This, in turn, can be used to bypass security mechanisms and for shellcode injection.

In August, the CyCraft team told Black Hat USA attendees that a Chinese APT group had “hit” the systems of several Taiwanese chip manufacturers.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS