The Chinese group Moshen Dragon has targeted telecommunications service providers in Central Asia, security researchers have discovered.
See also: Google: Chinese hacking group targets Ukrainian government

While this new threat group has some commonalities with “ RedFoxtrot ” and “ Nomad Panda ,” including the use of ShadowPad and PlugX malware variants , there are several differences in its activity.
According to Sentinel Labs, Moshen Dragon is a specialized hacking group with the ability to adapt its approach depending on the defenses it faces.
Hackers seek to load malicious Windows DLLs into antivirus products, steal credentials to move laterally, and ultimately exfiltrate data from infected machines .
At present, the infection vector is unknown, so Sentinel Lab's report begins with antivirus abuse, which includes products from TrendMicro, Bitdefender, McAfee, Symantec, and Kaspersky.
Because these AV products run with elevated privileges on the Windows operating system, sideloading a malicious DLL into their process allows hackers to execute code on the machine with few restrictions and potentially evade detection.
See also: US: Sanctions on Chinese companies that help Russia

Moshen Dragon uses this method to develop Impacket, a Python created to facilitate lateral movement and remote code execution via Windows Management Instrumentation (WMI).
Impacket also contributes to credential theft by integrating an open source tool that records the details of password changes even within a domain.
Having access to neighboring systems, the threat group drops a passive loader on them that verifies that it is on the correct machine before activating by comparing the hostname to a hardcoded value.
As Sentinel Labs suggests, this is an indication that the threat actor creates a unique DLL for each of the machines it targets, another indication of its sophistication and diligence.
The loader uses the WinDivert to intercept incoming traffic until it receives the string required for self-decryption, and then unpacks and launches the payload.
See also: Chinese government-backed APT41 group breached 6 US government networks
According to Sentinel Labs, the payloads include variants of PlugX and ShadowPad, two backdoors that have been used by many Chinese APTs in recent years. The threat actor's ultimate goal is to extract data from as many systems as possible.
