HomeSecurityAnalysis of DragonSpark group attacks on East Asian orgs

Analysis of DragonSpark group attacks on East Asian orgs

Recently, the attacks by the “DragonSpark” group against organizations in East Asia were analyzed – the analysis was conducted by SentinelLabs. These malicious methods are characterized by the use of SparkRAT and other malware written in Golang, which is specifically designed to evade detection.

See also: CISA: Critical ManageEngine RCE bug used in attacks

Analysis of DragonSpark group attacks on East Asian orgs

See also: Rostelecom Russia: DDoS attacks in 2022 broke all records

As tracked by SentinelLabs, the DragonSpark attack exploits a little-known open-source tool called SparkRAT to indiscriminately collect confidential information from compromised devices, execute commands, and more.

To carry out their cyberattacks, malicious actors are targeting weakly secured MySQL databases in China, Taiwan , and Singapore. As expected, SentinelLabs observed that these servers are accessible online.

See also: GTA Online bug in PC version causes account problems

SparkRAT

By exploiting SQL injection, cross-site scripting, or web server vulnerabilities, malicious actors can gain access to vulnerable MySQL and web server endpoints and deploy webshells.

Next, the hackers develop SparkRAT, an open-source tool based on Golang that can run on Windows, macOS , and Linux, offering feature-rich remote access capabilities.

SparkRAT is equipped with 26 different commands that can be received from the C2, giving it the ability to perform a wide range of functions.

  • Remotely execute PowerShell and Windows system commands.
  • Handle Windows functions and force shutdown, restart, or suspend.
  • Perform file actions such as download, upload, or delete.
  • Steal system information or take screenshots and transfer them to C2.

SparkRAT leverages the power of the WebSocket protocol to communicate with the C2 server and can even perform automatic upgrades, thus constantly updating its arsenal of features.

dragonspark

In addition to SparkRAT, 'DragonSpark' also uses the SharpToken and BadPotato tools to enhance access privileges , as well as the GotoHTTP tool to maintain a persistent presence on each compromised system.

Advantages of code interpretation

However, what differentiates this campaign is the use of Golang source code interpretation to execute coded commands from Go scripts hidden within the malware binaries.

This Go script provides malicious actors with the opportunity to create a reverse shell and execute code remotely via Metepreter.

dragonspark SparkRAT

The Yaegi framework allows this malware to execute base64 encoded, embedded source code stored within the compiled binary at runtime. This bypasses static analysis by avoiding compiling before executing the code.

This complex but highly effective static analysis technique has proven to be a superior defense against security threats, as most programs are only able to evaluate compiled code instead of source code.

Analysis of DragonSpark group attacks on East Asian orgs

Who is the DragonSpark team?

DragonSpark doesn't appear to have any notable overlaps with other Chinese-speaking hacking groups, so SentinelLabs has given the cluster a new name.

In September 2022, suspicious activities involving the Zegost malware were first detected, which is historically associated with China-based APTs, which are primarily engaged in espionage.

The malicious webshell that DragonSpark installed on vulnerable servers was “China Chopper,” a tool that has become popular among cybercriminals worldwide.

Furthermore, all of the open source tools used by DragonSpark were written by Chinese authors, which strongly suggests that these malicious actors are linked to China.

DragonSpark infiltrated networks belonging to gaming, art galleries, tourism businesses, and academic institutions located in Taiwan, Hong Kong, China, and Singapore.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS