HomeSecurityChinese hackers cloned tool belonging to NSA's Equation Group

Chinese hackers cloned tool belonging to NSA's Equation Group

Chinese hackers "cloned" and used for years a zero-day Windows exploit stolen from the NSA's Equation Group, researchers say.

On Monday, Check Point Research (CPR) said the Jian tool was a "clone" of software developed by the US National Security Agency's (NSA) Equation Group.

The hacking group Shadow Brokers released tools and files belonging to the Equation Group in 2017, some of which were used to exploit bugs in popular systems, including Microsoft Windows – forcing vendors to issue an emergency patch and fixes to render the tools useless.

That same year, Microsoft released a patch for CVE-2017-0005, a zero-day vulnerability that could be used to escalate privileges and completely compromise the system.

Initially, a tool created to exploit CVE-2017-0005 was thought to be the work of a Chinese advanced APT group called APT31, also known as Zirconium.

Equation Group

However, Check Point now says that the tool, called Jian, was actually a clone of software used by the Equation Group and was actively used from 2014 to 2017 – years before the vulnerability was patched – and was not a customized version by Chinese threat actors.

According to researchers, Jian is a clone of “EpMe”.

It is believed that the APT31 group had gained access to the Equation Group exploit module – both 32- and 64-bit versions – with researchers unsure how the Chinese APT gained access.

The investigation into Jian also uncovered a module containing four privilege escalation exploits that were part of the Equation Group's DanderSpritz framework.

Two of the exploits in the framework, dating back to 2013, were zero-day flaws. One of the exploits was EpMe, while another, dubbed “EpMo,” appears to have been patched by Microsoft since May 2017.

Chinese hackers cloned tool belonging to NSA's Equation Group
Timeline detailing the history of EpMe/Jian/CVE-2017-0005

This is not the only example of a Chinese APT stealing and redeploying Equation Group tools. In another case documented by Symantec in 2019, APT3 “Buckeye” was linked to attacks using Equation Group tools in 2016, before the Shadow Brokers leak.

While Buckeye appeared to be disbanding in mid-2017, the tools were in use until 2018 – but it is not known if they were transferred to another team.

Information source: zdnet.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS