HomeSecurityBronze Starlight group attacks gaming companies

Bronze Starlight team attacks gaming companies

The China-linked APT (advanced persistent threat) group called “Bronze Starlight” has been spotted targeting the gaming industry in Southeast Asia with malware signed with a valid certificate used by VPN provider Ivacy.

The main advantage of using a valid certificate is that it bypasses security measures, avoids the suspicion caused by system alerts, and mixes with legitimate software and traffic.

According to SentinelLabs, which analyzed the campaign, the certificate belongs to PMG PTE LTD, a Singaporean company that supplies the VPN product 'Ivacy VPN'.

The cyberattacks observed in March 2023 are likely a more recent phase of 'Operation ChattyGoblin' that ESET investigated in a report for Q4 2022 – Q1 2023.

However, according to SentinelLabs, it is difficult to associate with specific groups due to the heavy sharing of tools among threats from China.

See also: Cuba ransomware: Using Veeam exploit to attack critical infrastructure

Bronze Starlight team attacks gaming companies

See also: New variant of BlackCat ransomware uses Impacket and RemCom tools

DLL side-loading

The attacks begin by dropping .NET executables (agentupdate_plugins.exe and AdventureQuest.exe) onto the target system, possibly via trojanized chat applications, which receive password-protected ZIP files from Alibaba buckets.

The AdventureQuest.exe malware sample was initially detected by security researcher MalwareHunterteam in May, when he noticed that the code signing certificate was the same as the one used for the official Ivacy VPN installers.

These files contain vulnerable versions of software, such as Adobe Creative Cloud, Microsoft Edge, and McAfee VirusScan, which are vulnerable to DLL exploits. Bronze Starlight hackers use these vulnerable applications to install Cobalt Strike beacons on targeted systems.

The malicious DLLs (libcef.dll, msedge_elf.dll, and LockDown.dll) are compressed inside files next to the legitimate program executables, and Windows prioritizes their execution over safer versions of the same DLLs stored in C:\Windows\System32, thus allowing the malicious code to execute.

SentinelLabs notes that the .NET executables have a geo-protection restriction that prevents the malware from executing in the United States, Germany, France, Russia, India, Canada, or the United Kingdom.

These countries are outside the scope of the campaign and are excluded to avoid detection and analysis. However, due to a bug in the geofencing implementation, it is not working.

See also: HiatusRAT malware: Attacks Taiwanese companies and the US military

Bronze Starlight team attacks gaming companies

Abuse of a valid certificate

An interesting aspect of the attacks observed is the use of an encryption certificate owned by PMG PTE LTD, the company behind Ivacy VPN.

Indeed, the same certificate is used to sign the official Ivacy VPN installer linked from the VPN provider's website.

If the certificate was stolen, security researchers are concerned about what else the threat actors had access to on the VPN provider.

PMG PTE LTD has not responded to this revelation with a public statement, so the exact ways in which the hackers gained access to the certificate remain unclear.

At the same time, DigiCert revoked and canceled the certificate in June 2023 due to violation of the “Baseline Requirements” guidelines.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS