HomeSecurityMoshen Dragon: Chinese espionage group targets Asian telecoms

Moshen Dragon: Chinese espionage group targets Asian telecoms

The Chinese group Moshen Dragon has targeted telecommunications service providers in Central Asia, security researchers have discovered.

See also: Google: Chinese hacking group targets Ukrainian government
Dragon Moshe

While this new threat group has some commonalities with “ RedFoxtrot ” and “ Nomad Panda ,” including the use of ShadowPad and PlugX malware variants , there are several differences in its activity.

According to Sentinel Labs, Moshen Dragon is a specialized hacking group with the ability to adapt its approach depending on the defenses it faces.

Hackers seek to load malicious Windows DLLs into antivirus products, steal credentials to move laterally, and ultimately exfiltrate data from infected machines .

At present, the infection vector is unknown, so Sentinel Lab's report begins with antivirus abuse, which includes products from TrendMicro, Bitdefender, McAfee, Symantec, and Kaspersky.

Because these AV products run with elevated privileges on the Windows operating system, sideloading a malicious DLL into their process allows hackers to execute code on the machine with few restrictions and potentially evade detection.

See also: US: Sanctions on Chinese companies that help Russia

Chinese team

Moshen Dragon uses this method to develop Impacket, a Python created to facilitate lateral movement and remote code execution via Windows Management Instrumentation (WMI).

Impacket also contributes to credential theft by integrating an open source tool that records the details of password changes even within a domain.

Having access to neighboring systems, the threat group drops a passive loader on them that verifies that it is on the correct machine before activating by comparing the hostname to a hardcoded value.

As Sentinel Labs suggests, this is an indication that the threat actor creates a unique DLL for each of the machines it targets, another indication of its sophistication and diligence.

The loader uses the WinDivert to intercept incoming traffic until it receives the string required for self-decryption, and then unpacks and launches the payload.

See also: Chinese government-backed APT41 group breached 6 US government networks

According to Sentinel Labs, the payloads include variants of PlugX and ShadowPad, two backdoors that have been used by many Chinese APTs in recent years. The threat actor's ultimate goal is to extract data from as many systems as possible.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS