HomeSecurityChinese group Aoqin Dragon spied on organizations for a decade

Chinese group Aoqin Dragon spied on organizations for a decade

A Chinese-speaking threat actor was discovered by SentinelLabs threat analysts who were able to link it to malicious activity taking place in 2013. The hacking group called Aoqin Dragon focuses on espionage , targeting government, educational, and telecommunications organizations based in Singapore, Hong Kong, Vietnam, Cambodia, and Australia.

Chinese group Aoqin Dragon spied on organizations for a decade

See also: Symbiote malware: Infects all running processes on Linux systems

Threat actor techniques have evolved over the years, but certain tactics and concepts remain unchanged.

Invasion and infection tactics

The Aoqin Dragon group has used three distinct infection chains since it was first detected, according to SentinelLabs. The earliest, used between 2012 and 2015, involves Microsoft Office that exploit known vulnerabilities such as CVE-2012-0158 and CVE-2010-3333.

This tactic was detected by FireEye in 2014 in a spear-phishing campaign coordinated by the Chinese-backed Naikon APT group ,targeting an APAC government entity and a US think tank.

The second infection method is to cover malicious executable files with fake anti-virus icons, tricking users into launching them and activating a malware dropper on devices .

See also: Massive Facebook phishing campaign generates millions

Since 2018, Aoqin Dragon has switched to using a removable disk shortcut file which, when clicked, performs DLL hijacking and loads an encrypted backdoor payload.

The malware runs under the name “Evernote Tray Application” and is executed at system startup. If the loader detects removable devices, it also copies the payload to infect other devices on the target’s network.

Aoqin Dragon

SentinelLabs identified two different backdoors used by this threat group, Mongall and a modified version of Heyoka. Both are DLLs that are loaded into memory, decrypted, and executed.

Aoqin Dragon managed to stay in the shadows for a decade, with only parts of its operation appearing in older reports [PDF] from cybersecurity firms.

The group achieved this by constantly evolving its techniques and changing tactics, something that will likely happen again after the exposure it received following the SentinelLabs report.

See also: Cuba ransomware: New variant detected in recent attacks

Considering that its activities align with the political interests of the Chinese government, it is almost certain that Aoqin Dragon will continue its cyberespionage operations, improving its evasion of detection and switching to new evasion tactics.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS