Chinese hackers, codenamed SneakyChef, have been linked to an espionage campaign that primarily targets government entities in Asia and the EMEA region (Europe, Middle East, and Africa) and distributes the SpiceRAT and SugarGh0st malware.

" SneakyChef uses government documents as bait. Most of them are related to foreign ministries or embassies of various countries ," said Cisco Talos researchers Chetan Raghuprasad and Ashley Shen
The activities of this group were first highlighted by the cybersecurity in late November 2023. Analysts had identified a campaign that infected systems with a custom variant of the Gh0st RAT, called SugarGh0st.
See also: NiceRAT malware targets users through cracked software
A more recent analysis by Proofpoint revealed the use of SugarGh0st malware against American organizations working with artificial intelligence.
Talos said it has since observed the same malware targeting various government entities across Angola, India, Latvia, Saudi Arabia, and Turkmenistan.
Until now, the SugarGh0st malware was delivered via Windows Shortcut (LNK) files embedded in RAR archives. In the most recent attacks, however, a self-extracting RAR archive (SFX)as the initial infection vector, launching a Visual Basic Script (VBS) that ultimately executes the malware via a loader while simultaneously displaying the decoy file.
The attacks against Angola also saw the use of a new remote access trojan codenamed SpiceRAT.
SpiceRAT is distributed via two different infection chains. One uses a LNK file contained within a archive . This deploys the malware using DLL side-loading techniques.
See also: New Cross-Platform “Noodle RAT” Malware Targets Windows and Linux
“When the victim extracts the RAR file, it installs the LNK and a hidden folder on their computer,” the researchers said. “After the victim opens the shortcut file, which appears as a PDF document, it executes an embedded command to run the malicious executable from the hidden folder.”
Then, a decoy document is displayed to the victim and a legitimate binary (“dxcap.exe”) is executed, which loads a malicious DLL, responsible for loading the SpiceRAT malware.

The second infection method uses an HTML Application (HTA) that installs a Windows batch script and a Base64-encoded downloader binary, with the former launching the executable file via a scheduled task every five minutes.
The batch script is also designed to run another legitimate executable “ChromeDriver.exe” every 10 minutes, which then loads a DLL that, in turn, loads SpiceRAT.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: ValleyRAT malware resurfaces with new data-stealing tactics
The emergence of new hacking groups such as SneakyChef highlights the ever-evolving nature of cybersecurity threats and the need for constant vigilance and proactive measures to protect against them. As cybercriminals continue to develop new techniques and tools, it is important for organizations to stay informed and adopt strong security measures to protect their sensitive data and assets. It is important for governments, companies and individuals to invest in cybersecurity that can help mitigate the risks posed by such threat actors.
Source: thehackernews.com
