HomeSecurityGelsemium hackers spotted in attack against Asian government

Gelsemium hackers spotted in attack against Asian government

A new hacking group called Gelsemium has been identified in attacks targeting a government in Southeast Asia during a six-month period from 2022 to 2023.

Gelsemium

The Gelsemium cyberespionage group has been operating since 2014 and targets governments, education, and electronics businesses in East Asia and the Middle East.

ESET's 2021 report characterizes the hacking group as "quiet," highlighting the exceptional technical ability and programming knowledge that has helped them go unnoticed for many years.

A new report from Palo Alto Networks' Unit 42 team reveals how a new offensive campaign called Gelsemium uses backdoors that are rarely seen and are linked to hackers with moderate certainty.

Gelsemium hackers spotted in attack against Asian government

Recent Gelsemium attacks

The initial breach of Gelsemium's targets was achieved through the installation of a web shell, likely after exploiting vulnerabilities in servers accessible from the internet.

Unit 42 reports that the websites 'reGeorg,' 'China Chopper,' and 'AspxSpy,' which are publicly available and used by multiple hacking groups, have been identified, making them difficult to trace.

Using these web shells, Gelsemium performed basic network reconnaissance, moved laterally via SMB, and retrieved additional payload.

These additional tools that aid in lateral movement, data collection, and privilege escalation include OwlProxy, SessionManager, Cobalt Strike, SpoolFool, and EarthWorm.

Cobalt Strike is a widespread penetration testing package, EarthWorm is a shared SOCKS tunneler, and SpoolFool is an local privilege , so these three are not specific to the Gelsemium team.

Gelsemium hackers spotted in attack against Asian government

However, OwlProxy is a unique, custom HTTP proxy and backdoor tool that Unit 42 reports that the Gelsemium group used in a previous attack targeting the Taiwanese government.

In the most recent campaign, the hacking group used an executable file that stored an embedded DLL (wmipd.dll) on the compromised system's disk and created a service that runs it.

The DLL is a variant of OwlProxy, which creates an HTTP service that listens for incoming requests for specific URL patterns that hide commands.

Researchers report that security products on the targeted system prevented OwlProxy from running, so the attackers reverted to using EarthWorm.

The second custom implant associated with the Gelsemium group is SessionManager, an IIS backdoor that Kaspersky linked to the hacking group last summer.

The sample in the recent attack monitored incoming HTTP requests, looking for a specific Cookie field that carries commands to execute on the host.

These commands involve uploading files to or from the C2 server, executing commands, launching applications, or establishing proxy connections to additional systems.

The proxy functionality in OwlProxy and SessionManager indicates the hackers' intent to use the compromised server as a gateway for communicating with other systems on the targeted network.

In conclusion, Unit 42 notes the persistence of the Gelsemium group, with the hackers introducing multiple tools and adapting the attack as needed, even after security solutions stopped some of backdoors .

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS