HomeSecurityVLC Media Player is being abused by Chinese hackers

VLC Media Player is being abused by Chinese hackers

A long-running malicious campaign is being used by hackers associated with the Chinese government, who are abusing VLC Media Player to launch a custom malware loader.

See also: VLC Media Player 3.0.11: Fixes serious remote code execution bug

VLC Media Player

The campaign appears to serve espionage purposes, and researchers from Symantec Threat Hunter Team said the cyberattack campaigns target various government and non-government organizations across three continents, including North America, Asia, and Europe.

Brigid O Gorman told the news agency that although the Chinese hackers targeted government and non-governmental organizations, they also attacked other educational and religious groups.

The group behind the malicious campaign is known as Cicada (but also as menuPass, Stone Panda, Potassium, APT10, Red Apollo) and has been active for more than 15 years, at least since 2006.

The start of the current campaign was discovered in mid-2021 and was still active in February 2022.

There is evidence that initial access to some of the compromised networks was through a Microsoft Exchange, indicating that the group exploited a known vulnerability in unpatched machines.

See also: Apple and Meta shared data with hackers pretending to be researchers

Chinese hackers

Researchers at Symantec, a division of Broadcom, discovered that, after gaining access to the target machine, the attacker deployed a custom loader on compromised systems with the help of the popular VLC media player.

Gorman said the attacker is using a clean version of VLC with a malicious DLL file in the same path as the media player's export functions.

The technique is known as DLL sideloading and is widely used by malicious actors to load malware into legitimate processes to hide malicious activity.

In addition to the custom loader, which O'Gorman said Symantec does not have a name for, the group also deployed a WinVNC to gain remote control over victims' systems.

The attacker also executed the Sodamaster backdoor on compromised networks, a tool believed to be used exclusively by the Cicada threat group since at least 2020.

See also: Russian hackers target NATO networks and European military forces

Sodamaster runs in system memory (fileless) and is equipped to evade detection by searching the registry for sandbox or delaying its execution.

The malware can also collect details about the system, look for running processes, and download and execute various payloads from the command and control server.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS