HomeSecurityBlackwood: They compromised WPS Office update to install malware

Blackwood: They compromised WPS Office update to install malware

A previously unknown advanced threat actor, known as 'Blackwood', is using sophisticated malware called NSPX30 in attacks against companies and individuals.

See also: Malicious Google ads trick Mac users into installing Atomic Stealer malware

Blackwood

The threat actor has been around since 2018, using the NSPX30 malware, an implant with code based on a backdoor from 2005.

Researchers at cybersecurity firm ESET discovered Blackwood and the NSPX30 implant in a 2020 campaign and believe the group's activities align with the interests of the Chinese state.

Blackwood's targets are located in China , Japan, and the United Kingdom , and it delivered the malware through the update mechanisms of legitimate software such as WPS Office (office suite) , Tencent QQ instant messaging platform , and Sogou Pinyin document editor .

According to researchers, the underlying threat agent conducts AitM attacks and intercepts traffic generated by NSPX30 to hide its activities and hide command and control (C2) servers

ESET points out that Blackwood likely shares access with other Chinese APT groups, as it observed one company's system being targeted by tools associated with multiple actors, including Evasive Panda, LuoYu , and LittleBear.

The NSPX30 is a sophisticated implant based on a backdoor code named 'Project Wood', which had basic capabilities for system data collection, keylogging , and screenshot capture.

Among other implants that emerged from the Wood Project was the DCM (Dark Specter), which first saw the light of day in 2008, offering multiple functional improvements.

See also: Malware and ransomware still pose the biggest threats in cyberspace

ESET believes that NSPX30 evolved from DCM with the first known malware sample documented in 2018.

Blackwood: They compromised WPS Office update to install malware

Unlike its predecessors, NSPX30 is characterized by its multi-stage architecture, which includes components such as a repository, a DLL installer with extensive UAC bypass capabilities, a loader, an organizer, and a backdoor, each with its own set of add-ons.

The NSPX30 demonstrates significant technical advancements, with capabilities for packet interception to hide its infrastructure, allowing it to operate stealthily. It also has mechanisms that add it to China's anti-malware whitelists to avoid detection.

The main function of NSPX30 is to collect information from the compromised system, including files, screenshots, keystrokes, hardware and network data, as well as credentials.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

In addition, the backdoor can also steal chat logs and contact lists from Tencent QQ, WeChat, Telegram, Skype, CloudChat, RaidCall, YY, and AliWangWang.

Additionally, the backdoor can also terminate processes by PID, create a reverse shell, move files to specified paths, or uninstall itself from the infected system.

See also: Mobile malware: A major risk for businesses

How is sophisticated malware detected and dealt with?

Sophisticated malware is detected through the use of sophisticated security solutions, such as intrusion prevention systems (IPS), antivirus , and threat detection tools. These systems use multiple techniques to detect and remove malware, such as behavioral analysis, offensive detection, and signature detection.

Dealing with sophisticated malware requires a multi-layered approach. This may include isolating infected systems, restoring data from backups, updating security software, and applying the latest patches and fixes.

Additionally, educating users about the techniques used by malware attackers is critical. This can include learning the symptoms of a malware attack, recognizing suspicious emails and online threats, and understanding the importance of keeping security software up to date.

Finally, using data protection tools, such as encryption and least privilege access policies, can help protect sensitive information from being compromised by sophisticated malware

Source: bleepingcomputer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS