The Billbug cyberespionage group (also known as Thrip, Lotus Blossom, Spring Dragon) has targeted a certificate authority, government agencies, and defense organizations in several Asian countries in recent months through an ongoing campaign.
See also: Whoosh data breach: Hacker leaked customer details

The group has been carrying out these attacks for years, with the most recent being seen since March. It is believed to be a state-sponsored group from China.
Its activities have been documented by multiple cybersecurity companies over the past six years.
See also: 42,000 websites tricked users into thinking they were legitimate
In a report today, Symantec security researchers say that the Billbug group, which they have been monitoring since 2018, has also targeted a certificate authority company . If successful, this would allow for easier deployment of signed malware and make it harder to detect or decrypt HTTPS traffic .
New campaign, old tools
Symantec has not determined how Billbug initially gains access to target networks, but has seen evidence that it does so by exploiting public-facing applications with known vulnerabilities .
As in other campaigns attributed to the Billbug group, the threat actor combines tools already installed on the target system, utilities , and malware created specifically for this purpose. These include:
- AdFind
- Winmail
- WinRAR
- Ping
- Tracert
- Route
- NBTscan
- Certutil
- Port Scanner
These tools make it easier for hackers to go unnoticed while blending in with everyday activity. With these tools, hackers can avoid raising an alarm in security tools , thus making it more difficult to perform the hack.
A more rarely developed open source tool seen in recent Billbug features is Stowaway, a Go-based multi-layer proxy tool that helps users bypass network access restrictions .
Symantec was able to link the recent attacks to Billbug because it used two backdoors that had been observed in its previous attacks: Hannotog and Sagerunex.
Some of the Hannotog backdoor's functions include changing firewall settings to enable all traffic, persistence on the compromised machine, uploading encrypted data, executing CMD commands, and downloading files to the device.

Sagerunex is dropped by Hannotog and injected into an “explorer.exe” process. It then writes logs to a local temp file encrypted using the AES (256-bit) algorithm.

The backdoor's configuration and state are stored locally and encrypted with RC4. However, the keys for both of these features are hardcoded into the malware.
See also: Bug on Apple devices causes Safari to crash when certain letters are typed
Sagerunex uses HTTPS to communicate with the command and command server, sending a list of active proxies and files, as well as receiving payload and shell commands from operators. In addition, it can execute programs and DLLs using “runexe” or “rundll”.
The Billbug team uses the same custom backdoors with minimal changes over the years.
Information source: bleepingcomputer.com
