HomeSecurityBudworm hackers target telcos and government organizations with custom malware

Budworm hackers target telcos and government organizations with custom malware

A Chinese hacking group identified as Budworm attacked a telecommunications company in the Middle East and a government entity in Asia, using a new version of the custom backdoor ‘SysUpdate’.

Budworm

The SysUpdate malware is a remote access trojan (RAT) that is linked to Budworm (also known as APT27 or Emissary Panda) since 2020. It supports the management of Windows services, processes and files, the execution of commands, data retrieval, and screen capture.

In March 2023, Trend Micro reported on a variant of SysUpdate for Linux, which had been widely distributed since October 2022.

The most recent variant of the SysUpdate backdoor was detected by Symantec's Threat Hunter team, part of Broadcom, in the latest attack that took place in August 2023.

According to Symantec's report, the backdoor is installed on systems via DLL sideloading, exploiting the legitimate executable ‘INISafeWebSSO.exe’.

The malicious DLL file used in Budworm attacks is identified as ‘inicore_v2.3.30.dll’, which is placed in the working directory so that it runs before the legitimate version due to the “Windows search order hijacking”.

By loading SysUpdate within the context of a legitimate program process, attackers can evade detection by security tools running on the compromised computer.

Together with SysUpdate, Symantec reports that several publicly available tools used in the most recent Budworm attacks were identified, such as AdFind, Curl, SecretsDump and PasswordDumper.

These tools help attackers perform various actions, including credential storage, network logging, lateral propagation across a compromised network, and data theft.

Telecommunications companies have become a frequent target among APT hacking groups.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS