HomeSecurityHydrochasma hackers target medical research labs

Hydrochasma hackers target medical research labs

A new malicious actor called Hydrochasma has launched cyberattacks on organizations involved in the development of COVID-19 vaccines and treatments, including medical laboratories and shipping companies.

Since last October, threat hunters at Symantec—a division of Broadcom—have been monitoring the actions of the Hydrochasma hackers, whose intent appears to be to gather information.

Hydrochasma attacks stand out due to their reliance on open source tools and “living off the land” (LotL) tactics, eliminating any evidence that could potentially lead to them.

See also: Fake ChatGPT apps/sites distribute Windows & Android malware

Hydrochasma hackers target medical research labs

It is believed that a Hydrochasma attack likely begins with a phishing email, as Symantec has revealed executable files that mirror documents as a source of malicious behavior on infected computers.

To deceive shipping companies, the fraudulent documents use a “product specification information” pattern, while medical laboratories are victimized with a “job candidate resume.”.

After compromising a machine, the attacker uses the access to drop a Fast Reverse Proxy (FRP), which can be exposed to public local web servers behind a NAT (Network Address Translation) or firewall.

See also: Google Bug Bounty: $12 million awarded to researchers in 2022

The attacker then deploys the following tools on the compromised system:

  • Meterpreter (disguised as Microsoft Edge Updater) a tool with advanced penetration testing capabilities that provides remote access
  • Gogo: an automated network scanning engine
  • Process Dumper, for dumping domain passwords (lsass.exe)
  • Cobalt Strike beacon, for executing commands, importing processes, sending/receiving files
  • AlliN scanning tool, used for lateral movement
  • Fscan: open port scanner
  • Dogz: free VPX proxy tool
  • SoftEtherVPN: free open source VPN tool
  • Procdump: a Microsoft Sysinternals utility that allows you to create error dumps, process dumps, and monitor the CPU usage of an application.
  • BrowserGhost: browser password grabber
  • Ghost proxy: tunneling tool
  • Ntlmrelay: used for NTLM relay attacks and to intercept valid authentication requests
  • Task Scheduler: automates tasks on a system
  • Go-strip: reduces the size of a Go binary
  • HackBrowserData: open source utility for decrypting browser data

With such a large list of publicly available tools, it is difficult to attribute any malicious activity to specific actors – indicating that hackers want to remain on the network for a long time.

Hydrochasma

Researchers cannot rule out the possibility that Hydrochasma is a recognized threat actor that began using exclusive LotL tools and tactics in specific campaigns in an attempt to conceal its activities .

See also: New S1deload Stealer malware hacks YouTube and Facebook accounts

At present, the only tangible clues to the origin of the Hydrochasma threat come from its victims located in Asia– however, this information alone is not sufficient to form a comprehensive profile.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS