HomeSecurityGallium hackers use Linux variant of PingPull RAT in cyberespionage attacks

Gallium hackers use Linux variant of PingPull RAT in cyberespionage attacks

Chinese hackers (Gallium) are deploying new Linux malware variants in cyberespionage attacks, including a new variant of the PingPull RAT and a new backdoor tracked as “Sword2033“.

Gallium hackers Linux variant of PingPull RAT

The PingPull RAT was first detected by Unit 42 last summer . It was used in espionage attacks carried out by the Chinese state-owned group Gallium , also known as Alloy Taurus. The attacks targeted government and financial organizations in Australia, Russia, Belgium, Malaysia, Vietnam, and the Philippines.

Security researchers continued to monitor these attacks and found that Chinese hackers are now using new malware variants against targets in South Africa and Nepal.

See also: VMware fixes critical zero-day exploit chain

PingPull RAT: Linux variant

The Linux variant of the PingPull RAT is an ELF file. It is worth noting that only 3 out of 62 antivirus vendors currently flag it as malicious.

Researchers were able to determine that it is a port of known Windows malware after noting similarities in HTTP communication structure, POST parameters, AES key, and commands it receives from the attackers' C2 server.

The commands sent by the C2 to the Gallium hackers' malware are indicated by a single uppercase character in the HTTP parameter, and the payload returns the results to the server via a base64-encoded request.

The parameters and corresponding commands are:

A – Get the current directory

B – List folder

C – Read text file

D – Write a text file

E – Delete file or folder

F – Read binary file, convert to hex

G – Write binary file, convert to hex

H – Copy file or folder

I – Rename a file

J – Create a Directory

K – Timestamp file with a specified timestamp in “%04d-%d-%d %d:%d:%d” format

M – Run command

Unit 42 noticed that the command handlers used in PingPull matched those seen in another malware called “China Chopper.” This was a web shell widely used in attacks against Microsoft Exchange servers.

See also: Intel CPUs vulnerable to new side-channel attack

cyber espionage attacks
Gallium hackers use Linux variant of PingPull RAT in cyberespionage attacks

Sword2023 backdoor

Unit 42 also found, as mentioned above, a new ELF backdoor that communicated with the same command and control server (C2) as PingPull. This is a simpler tool with more basic functionality.

Researchers also discovered a second Sword2023 associated with a different C2 address impersonating the South African military. The same sample was linked to a Soft Ether VPN address, a product known to be used by Gallium hackers in their operations.

The cybersecurity company comments that this is not a random choice, as in February 2023, South Africa participated in joint military exercises with Russia and China.

Chinese hackers Gallium seem to be constantly developing their tactics and “weapons”, while at the same time expanding their target range using new Linux variants of the PingPull RAT and the recently discovered Sword2023 backdoor.

See also: New SLP bug leads to enhanced DDOS attacks

Organizations and businesses need to adopt a comprehensive security strategy to effectively address this threat. In the age of technology and digital data, it is almost impossible to remain immune to cyberattacks. We hear about security incidents and breaches data. Hackers are everywhere, looking for weak spots in your system to exploit, which is why it is important to take steps to protect your data, online accounts, and other digital assets.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS