HomeSecurityChinese group LuoYu develops cyberespionage malware

Chinese group LuoYu develops cyberespionage malware

A hacking group originating from China known as LuoYu is infecting victims with the information-stealing malware WinDealer that is deployed by swapping legitimate application updates with malicious payloads in man-on-the-side. attacks

Chinese hacker group develops cyberespionage malware

To accomplish this, threat actors actively monitor their targets' network traffic for application update associated with popular Asian applications, such as QQ, WeChat, and WangWang , and replace them with WinDealer installers.

What WinDealer does is that it helps attackers search and capture large amounts of data from compromised Windows, install backdoors to maintain stability , manipulate files, and execute arbitrary commands.

Instead of using the common hard-coded command-and-control (C2) server information, WinDealer will connect to a random ChinaNet IP address (AS4134) from Xizang and Guizhou provinces from a pool of 48,000 IP addresses, according to security researchers at Kaspersky who discovered this new delivery method.

Since controlling all of these IPs is likely impossible, explanations for how the LuoYu group could do this include using compromised routers “in route to or within AS4134”, using law enforcement tools at the ISP level, or “information methods unknown to the general public”.

The LuoYu group has moved on to abusing the automatic update mechanism of its victims', after previously pushing malware into easier attacks where they would use compromised local news websites as infection vectors.

Suguru Ishimaru, a senior security researcher at Kaspersky, says that Man-on-the-side attacks are extremely destructive, as the only requirement for an attack on a device is that it be connected to the internet. Even if the attack fails the first time, attackers can repeat this process as many times as necessary until they achieve their goal.

Chinese hacker group develops cyberespionage malware

“Regardless of how the attack was carried out, the only way for potential victims to defend themselves is to remain vigilant and have strong security procedures in place, such as regular antivirus scans, outbound network traffic analysis, and extensive logging to detect anomalies,” he continued.

In addition to its attacks on Korean and Japanese organizations since at least 2014, LuoYu is also known for its attacks on foreign diplomatic organizations in China , the academic community , and organizations from many industries including defense and telecommunications.

Kaspersky 's Global Research and Analysis Team (GReAT) has also detected sporadic infections in other countries such as Germany, Austria, the United States, the Czech Republic, Russia, and India. Recently, LuoYu has also begun targeting companies in East Asia and branches located in China.

In addition to targeting Windows devices using WinDealer, this lesser-known hacking group has previously been observed attacking macOS, Linux, and Android devices with the Demsty (ReverseWindow) and SpyDealer malware.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS