HomeSecurityGallium Group Targets Government Services with New PingPull RAT

Gallium Group Targets Government Services with New PingPull RAT

New reports indicate that the state-sponsored hacking group Gallium is using a new trojan called “PingPull RAT” and targeting government agencies and financial institutions in Europe, Southeast Asia, and Africa.

Gallium

The victims are based in Australia, Russia, the Philippines, Belgium, Vietnam, Malaysia, Cambodia and Afghanistan.

See also: Fake Coinbase, MetaMask wallet apps steal cryptocurrency

It is believed that the Gallium hacking group is associated with China and the targets (telecom providers, financial and government agencies) in espionage are aligned with the country's interests.

According to analysts at Unit42 (Palo Alto Networks), Gallium is using a new RAT, which operates quite insidiously.

Researchers say the PingPull RAT is designed to provide threat actors with a reverse shell on the compromised machine. This allows attackers to execute commands remotely. Unit42 identified three different variants with similar functionality that use different C2 communication protocols: ICMP, HTTPS, and TCP.

Different C2 protocols may aim to evade specific network reconnaissance tools , with attackers developing the appropriate variant based on the initial reconnaissance.

See also: How to find out if your passwords have been leaked online?

In all three cases, the malware installs itself as a service and has a description that simulates a legitimate service, aiming to discourage users from terminating it.

Some of the commands supported by all three variants are:

  • Storage volume control
  • Folder contents list
  • Reading a file
  • File recording
  • Delete folder
  • Create a directory
  • Timestomp file
  • Execute a command via cmd .exe etc.
PingPull RAT
Gallium Group Targets Government Services with New PingPull RAT

Gallium hackers

The infrastructure discovered by Unit 42 researchers and linked to the state-run hacking group Gallium includes more than 170 IP addresses, some of which date back to late 2020.

Microsoft had reported on this group in 2019, when hackers were primarily targeting telecommunications providers.

The group is also monitored as Soft Cell by Cybereason.

See also: FakeCrack: Malware is distributed via fake Windows CCleaner Pro!

Gallium's latest campaigns have brought to light a new RAT, which shows that the hacking group is still active and a threat. Furthermore, Gallium is now not only targeting telecommunications but also government and financial services almost all over the world (Asia, Africa, Europe and Australia).

It is unclear how the networks are compromised, although these hackers typically exploit applications exposed online to gain initial access and deploy a modified version of the China Chopper web shell to establish persistence.

More details on how the RAT works and protection methods can be found in the Unit 42 report.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS