HomeSecurityChinese hackers collaborate for cyber espionage

Chinese hackers collaborate for cyber espionage

Different groups of Chinese state hackers have targeted a government agency since at least March 2023 in a cyberespionage campaign tracked as Crimson Palace.

Chinese hackers cyber espionage

Sophos researchers have observed that the campaign was based on new malware variants and the different groups involved indicate a coordinated attack .

Although the initial access to the government agency has not been determined, researchers have observed related activity since early 2022 using the custom Nupakage malware which has been associated with the Chinese threat group Mustang Panda.

See also: Chinese hackers turn to ORB proxy networks

Different groups of Chinese hackers

Sophos identified three activity clusters linked to known Chinese groups such as “BackdoorDiplomacy”, “REF5961”, “Worok”, “TA428” and the APT41 subgroup, “Earth Longzhi”.

The researchers found that these activity clusters are coordinated by a single organization.

Cluster Alpha (STAC1248): active from early March to August 2023. Focused on developing new variants of the 'EAGERBEE' malware that were able to disrupt security agency network communications.

The main goal of the Chinese hackers was cyberespionage, specifically mapping server subnets and enumerating administrator accounts by conducting reconnaissance on the Active Directory infrastructure

The activity was based on multiple command and control (C2) channels, including the Merlin Agent, PhantomNet backdoor, RUDEBIRD malware, and PowHeartBeat backdoor.

To evade detection, the Chinese hackers used living-off-the-land binaries (LOLBins) to maintain persistence with elevated SYSTEM privileges. They also performed DLL side-loading with eight unique DLLs, exploiting Windows Services and legitimate Microsoft binaries.

Cluster Bravo (STAC1807): active for only three weeks in March 2023. It focused on lateral movement and persistence, using a new backdoor called “CCoreDoor.” This backdoor created external C2 communications and stole credentials.

Chinese hackers used renamed versions of signed side-loadable binaries to conceal the deployment of the backdoor and facilitate lateral movement on systems.

Cluster Charlie (SCAT1305): Active from March 2023 to April 2024 (at least). The attackers deployed multiple samples of a previously unknown malware called “PocoProxy.” They also used the HUI loader to inject a Cobalt Strike Beacon into mstsc.exe, although these attempts were blocked.

See also: Chinese hackers breach networks through ScreenConnect and F5 BIG-IP vulnerabilities

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Chinese hackers collaborate for cyber espionage

Additionally, an interception tool credentials LSASS login and a bulk Event Logs analysis and automated ping scans were conducted to map users and endpoints across the network.

The Crimson Palace campaign by Chinese hackers targeted a Southeast Asian government agency for cyberespionage purposes.

Sophos said that various groups of Chinese state hackers have targeted this service since at least March 2022.

“While we are not currently able to confidently attribute or confirm the nature of the relationship between these clusters, our current research indicates that the activities reflect the work of separate actors tasked by a central authority with parallel goals in pursuit of Chinese state interests,” the cybersecurity firm said.

Sophos found that malicious activity increased on certain occasions, such as on June 12, 2023, which was a holiday in the target country (holidays usually don't have as many staff available to scan).

Although Sophos blocked the attackers' C2 implants in August 2023 and Cluster Alpha activity has not appeared since then, researchers say that Cluster Charlie activity has been detected again after a few weeks of silence.

See also: Chinese hackers Earth Krahang have breached 70 organizations

Sophos continues to monitor activity on the target network.

Crimson Palace is a complex and highly sophisticated cyber espionage campaign . The collaboration of Chinese state hackers, the use of advanced tactics and techniques, and the potential impact on cybersecurity and international relations make this campaign a significant concern for governments and organizations around the world. It serves as a reminder of the ongoing threat posed by state-sponsored cyberattacks and the need for enhanced cybersecurity measures to protect against them. Therefore, it is vital that government agencies and organizations remain vigilant and take the necessary steps to strengthen their cybersecurity defenses . Cooperation between countries to share threat intelligence and implement strong security protocols can also help mitigate the risk of such attacks in the future.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS