HomeSecurityChinese hackers target Australia with ScanBox malware

Chinese hackers target Australia with ScanBox malware

Chinese threat actors, associated with the APT40 group, are using ScanBox for intelligence gathering purposes.

China-based threat actors are targeting Australian government agencies and wind turbine installations in the South China Sea by directing selected individuals to a fake website impersonating an Australian news outlet.

Victims landed on the fake website after receiving phishing and receiving a malicious JavaScript payload from the ScanBox framework.

The campaign was active from April to June this year and targeted individuals in Australian local and federal government agencies, Australian media organizations, and global heavy industry manufacturers who provide maintenance to wind turbines in the South China Sea.

Security researchers at Proofpoint and PwC (PricewaterhouseCoopers) who are monitoring the campaign assess that the goal was cyberespionage. They attribute the activity with moderate certainty to a China-based group tracked as a threat group named APT40 (also known as TA423, Leviathan, Red Ladon).

Chinese hackers target Australia with ScanBox malware
Chinese hackers target Australia with ScanBox malware

ScanBox has been observed in multiple attacks by at least six Chinese threat actors in the past, and there is sufficient evidence to show that the toolkit has been in use since at least 2014.

See also: Crypto-mining malware masquerades as Google Translate Desktop app

A report from Proofpoint notes that phishing emails were delivered to targets at various times using Gmail and Outlook email addresses .

The sender posed as an employee of the “Australian Morning News,” a fake news outlet, and added a URL to the malicious website. The website featured content copied from various legitimate news portals.

The URLs also included unique values ​​for each target, the researchers say, although they led to the same page and malicious payload in each case.

Visitors to the fake website were distributed with a copy of the ScanBox framework via JavaScript execution and gradual loading of modules.

“The ScanBox malware can deliver JavaScript code in a single block or, as in the April 2022 campaign, as a modular architecture based on plug-ins,” explains Proofpoint.

Chinese hackers target Australia with ScanBox malware
Chinese hackers target Australia with ScanBox malware

The report further explains that delivering the entire code may be preferable to threat actors. However, this approach could have caused crashes and bugs, which could have drawn the attention of researchers, so selective plugin loading was chosen.

The modules available in the ScanBox framework include:

See also: FBI: Hackers exploit DeFi bugs to steal crypto

  • Keylogger: Records keystrokes made within a ScanBox iframe.
  • Browser Plugins: Identifies installed browser plugins
  • Browser Fingerprinting: Identifies and analyzes the technical capabilities of the victim's browser
  • Peer connection: Implements WebRTC in real-time communication via API
  • Security Check: Checks if Kaspersky security tools are installed on the victim's machine

Once the framework is assembled on the victim's machine and the selected plugins are loaded, it sets up command and control (C2) communications and begins sending victim profile data, technical details, and information useful for identification and espionage.

Chinese hackers target Australia with ScanBox malware
Chinese hackers target Australia with ScanBox malware

In some cases observed in June 2022, threat actors targeted the Australian Maritime Defense and oil, gas, and deepwater drilling companies, using COVID-19 passport services as a lure, which downloaded a DLL stager to load Meterpreter .

Based on recent evidence from targeting methods and tools, Proofpoint concludes that the 2022 campaign is the third phase of the same intelligence gathering mission that APT40 has been conducting since March 2021.

In the past, threat actors have impersonated news outlets such as The Australian and the Herald Sunto perform RTF Template injection and load Meterpreter onto victims’ machines. The use of ScanBox malware in APT40 campaigns was also observed in 2018.

The threat actor has a history of attacks long enough to prompt the US Department of Justice in July 2021 to indict members of APT40.

Source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS