HomeSecurityChinese group Earth Longzhi resurfaces with advanced malware tactics

Chinese group Earth Longzhi resurfaces with advanced malware tactics

Chinese hacking group Earth Longzhi has resurfaced with a new campaign targeting government, healthcare, technology, and manufacturing entities based in Taiwan, Thailand, the Philippines, and Fiji, after more than six months of inactivity.

See also: Is misinformation the new malware?

Chinese group Earth Longzhi resurfaces with advanced malware tactics

Trend Micro attributed the intrusion to a cyber espionage group it monitors by the name “Earth Longzhi,” which is a subgroup within APT41 (also known as “HOODOO” or “Winnti”) and shares overlaps with several other groups known as “Earth Baku,” “SparklingGoblin,” and “GroupCC.”.

Earth Longzhi was first documented by the cybersecurity firm in November 2022, detailing its attacks against various organizations located in East and Southeast Asia, as well as Ukraine.

The attack chains created by the threat actor leverage vulnerable public-facing applications as entry points to deploy the BEHINDER web shell and then leverage this access to drop additional payloads, including a new variant of the Cobalt Strike loader called CroxLoader.

This is by no means the first time Earth Longzhi has exploited the BYOVD technique, with previous campaigns using the vulnerable RTCore64.sys driver to restrict the execution of security products.

See also: Hacking group ScarCruft spreads RokRAT malware

The malware, dubbed SPHijacker, also uses a second method referred to as “stack rumbling” to achieve the same goal. This involves intentionally causing targeted applications to crash upon startup.

These two approaches are far from the only methods that can be used to compromise security products. Last month, Deep Instinct detailed a new code injection technique dubbed “Dirty Vanity” that exploits Windows’ remote branching mechanism to bypass endpoint detection systems.

Earth Longzhi

Additionally, the driver payload is installed as a kernel-level service using Microsoft's Remote Procedure Call (RPC), as opposed to Windows APIs, to avoid detection.

The attacks were observed using a DLL-based dropper, named Roxwrapper, to deliver another Cobalt Strike loader, named BigpipeLoader, as well as a privilege escalation (dwm.exe) that abuses the Windows Task Scheduler to launch a specific payload with SYSTEM privileges.

See also: Ransomware attack continues at Bluefield University

The specified payload, dllhost.exe, is a downloader that can retrieve next-stage malware from a server controlled by the threat actor.

It is worth noting here that dwm.exe is based on an open-source proof-of-concept (PoC) available on GitHub, which suggests that the perpetrator is drawing inspiration from existing programs to improve his malware.

Trend Micro also reported that it detected misleading documents written in Vietnamese and Indonesian, indicating possible attempts to target users in those two countries in the future.

Information source: thehackernews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS