
Chinese state-backed hackers have targeted industrial organizations with new malware that can steal data from air-gapped systems. Air-gapped systems typically fulfill critical roles and are isolated from the company’s network and the public internet either physically or through software and network devices.
Researchers at cybersecurity firm Kaspersky discovered the new malware and attributed it to the cyberespionage group APT31, also known as Zirconium.
See also:The possible existence of Chinese malware in US systems is a "time bomb"
According to the findings, hackers used at least 15 different implants in attacks in Eastern Europe, each for a separate stage of the operation, as well as the signature of the “FourteenHi” malware family.
Multi-stage attacks
Kaspersky reported that APT31 launched a three-stage attack last April. The first stage created remote access and collected data. The second stage involved stealing data from isolated systems using USB propagation. The third stage uploaded the collected data to the hackers’ servers. The malware targeting isolated systems had four modules: removable drive profiling, removable drive infection, device data collection, and a variant of the first module that acted as a payload dropper, keylogger, screenshot tool, and file stealer.
Suggestion: Hackers steal data from air-gapped computers

In May 2022, Kaspersky observed an additional implant used in APT31 attacks, designed to collect local files from compromised systems.
This implant decrypts and injects its payload into the memory of a legitimate process to evade malware detection, then remains in a sleep state for 10 minutes and finally copies all files that match the file type extensions defined in its configuration.
The stolen files are archived using WinRAR (if unavailable, the malware exits) and then stored in temporary local folders created by the malware in “C:\ProgramData\NetWorks\”. Finally, the files are transferred to Dropbox.

Kaspersky emphasizes that the attacks were covert and lists the following tactics, techniques, and procedures (TTPs): Abuse of DLL instructions to load malicious payloads into memory and hiding payloads in encrypted form in separate binary data files.
The company provides a technical report that includes additional data, such as malware hashes, a full set of indicators of compromise, and details about the malware's activity from start to finish.
Air-sealed systems are an attractive target for APT groups, who typically turn to USB drives to transfer malware and wipe data from the isolated environment.
Read also: Chinese hacking group APT31 targets French organizations
source of information:bleepingcomputer.com
