HomeSecurityBitter Group: Targets Chinese nuclear energy organizations

Bitter Group: Targets Chinese nuclear energy organizations

Recently, the Bitter APT malicious group was spotted attempting to infiltrate China's nuclear power sector through malicious phishing emails that installed malware downloaders on unsuspecting victims' devices.

See also: BlackGuard stealer now targets 57 crypto wallets, extensions

Bitter

Bitter is a notorious hacking group known for infiltrating organizations in the energy, engineering, and government industries across the Asia-Pacific region.

In May 2022, a cybercriminal gang known as Bitter APT was observed sending spear phishing emails with XLSX attachments containing malicious code to infect victims in Southeast Asia. This malware was identified as “ZxxZ”.

See also: Phishing campaign exploits SharePoint to target users in the US and Europe

In August 2022, Meta revealed that the Bitter APT was using a new Android spyware tool called “Dracarys” to target victims in New Zealand, India, Pakistan , and the United Kingdom.

Intezer security analysts detected this hacking attempt and, based on the techniques and tactics used, linked it to Bitter APT – a group known to have repeatedly used similar strategies in previous attacks.

Targeting China's nuclear field

Intezer has now uncovered a new campaign where Bitter is sending emails impersonating the Kyrgyz Embassy in Beijing to several Chinese nuclear energy companies and related academics.

Pretending to be an invitation from the Kyrgyz Embassy, ​​the International Atomic Energy Agency (IAEA), and the China Institute of International Studies (CIIS) for a conference on nuclear energy, this email is sure to attract attention.

Bitter Group: Targets Chinese nuclear energy organizations

Bitter APT’s commitment to authenticity is remarkable, as evidenced by the fact that their emails are signed with a genuine name belonging to an employee of the Kyrgyz Ministry of Foreign Affairs. This attention to detail further lends legitimacy and credibility to communications .

Recipients are tricked into downloading the email's attached RAR file, which supposedly contains an invitation card for a conference. However, in reality, this attachment hides either a malicious Microsoft Compiled HTML Help (CHM) file or a malicious Excel document.

See also: Hackers target Middle Eastern telecom providers

Dropping payloads

Generally, the Bitter APT uses a CHM payload to issue commands that will create scheduled tasks on the compromised system and download subsequent stages.

Exploiting a notable Equation Editor vulnerability, when the malicious Excel document is opened, scheduled tasks are added to a downloaded RAR attachment.

Bitter

Intezer suggests that the threat actor likely chooses CHM payloads due to their simple installation , bypassing static analysis via LZX compression and requiring minimal user interaction.

The second-stage payload is an MSI or PowerShell file if a CHM payload is used, or an EXE file in the case of the Excel document payload.

Bitter Group: Targets Chinese nuclear energy organizations

To avoid detection and exposure, the second-stage payloads are empty. However, when the first-stage payloads send information about the compromised device to the attacker's command-and-control server, the attacker will determine whether it is a legitimate target before delivering malware to the compromised system.

Bitter Group: Targets Chinese nuclear energy organizations

Intezer researchers were unable to find the payloads delivered through this campaign, but speculated that they may have included keyloggers, RATs (remote access tools), and info-stealing malware.

Bitter

Dangerous attachments

CHM files were used in the past for software documentation, however, they are no longer widely used – not even in email correspondence.

People who receive emails should be especially careful when they find CHM files in attachments, as these may contain malicious material.

Ultimately, the files should be approached with caution, as they are capable of evading anti-virus scans, thus significantly increasing the chances of containing malicious content.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS