HomeSecurityBlackTech targets government sectors with Deuterbear

BlackTech targets government sectors with Deuterbear

The technology, research, and government sectors in the Asia-Pacific region have been targeted by a threat actor called BlackTech as part of a recent wave of cyberattacks usingthe Deuterbear backdoor.

See also: HackerOne: Has given away over $300 million in bug bounty programs

BlackTech Deuterbear

intrusions way for an updated version of the modular backdoor called Waterbear as well as its improved successor referred to as Deuterbear.

" Waterbear is known for its sophistication, as it uses various evasion mechanisms to minimize the likelihood of detection and analysis ," Trend Micro researchers Cyris Tseng and Pierre Lee said in an analysis last week.

The cybersecurity firm is tracking the threat actor under the name Earth Hundun, which is known to have been active since at least 2007. It also hears other names such as Circuit Panda, HUAPI, Manga Taurus, Palmerworm, Red Djinn, and Temp.Overboard .

In a joint advisory published last September, cybersecurity and intelligence agencies from Japan and the US discovered that the attackers originated in China, describing their ability to modify router firmware and exploit routers' domain-trust relationships to move from international subsidiaries to their corporate headquarters based in the two countries.

See also: North Korean hackers target blockchain engineers with Kandykorn malware

BlackTech targets government sectors with Deuterbear

"BlackTech actors use custom malware (Deuterbear), dual-use tools, and tactics, such as disabling logging on routers, to conceal their operations," the governments said.

One of the critical tools in his versatile arsenal is Waterbear (also known as DBGPRINT), which has been in use since 2009 and has been continuously updated over the years with improved defensive evasion features.

The trojan is obtained from a command and control (C2) server via a downloader, which is launched using a loader that, in turn, is executed via a well-known technique called DLL sideloading.

The newest version of the implant supports nearly 50 commands, allowing it to perform a wide range of activities, such as enumerating and terminating processes, file operations, window management, starting and exiting a remote shell, taking a screenshot, and modifying the Windows, among others.

See also: Ukrainian hackers destroy Moscollector's IT infrastructure

Deuterbear, used by the BlackTech group, is also delivered using a similar infection stream from 2022, and its downloader implements a number of obfuscation methods to resist analysis and uses HTTPS for C2 communications.

Source: thehackernews

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS