HomeSecurityChinese hackers distribute SpiceRAT and SugarGh0st malware

Chinese hackers distribute SpiceRAT and SugarGh0st malware

Chinese hackers, codenamed SneakyChef, have been linked to an espionage campaign that primarily targets government entities in Asia and the EMEA region (Europe, Middle East, and Africa) and distributes the SpiceRAT and SugarGh0st malware.

Chinese hackers SneakyChef

" SneakyChef uses government documents as bait. Most of them are related to foreign ministries or embassies of various countries ," said Cisco Talos researchers Chetan Raghuprasad and Ashley Shen

The activities of this group were first highlighted by the cybersecurity in late November 2023. Analysts had identified a campaign that infected systems with a custom variant of the Gh0st RAT, called SugarGh0st.

See also: NiceRAT malware targets users through cracked software

A more recent analysis by Proofpoint revealed the use of SugarGh0st malware against American organizations working with artificial intelligence.

Talos said it has since observed the same malware targeting various government entities across Angola, India, Latvia, Saudi Arabia, and Turkmenistan.

Until now, the SugarGh0st malware was delivered via Windows Shortcut (LNK) files embedded in RAR archives. In the most recent attacks, however, a self-extracting RAR archive (SFX)as the initial infection vector, launching a Visual Basic Script (VBS) that ultimately executes the malware via a loader while simultaneously displaying the decoy file.

The attacks against Angola also saw the use of a new remote access trojan codenamed SpiceRAT.

SpiceRAT is distributed via two different infection chains. One uses a LNK file contained within a archive . This deploys the malware using DLL side-loading techniques.

See also: New Cross-Platform “Noodle RAT” Malware Targets Windows and Linux

“When the victim extracts the RAR file, it installs the LNK and a hidden folder on their computer,” the researchers said. “After the victim opens the shortcut file, which appears as a PDF document, it executes an embedded command to run the malicious executable from the hidden folder.”

Then, a decoy document is displayed to the victim and a legitimate binary (“dxcap.exe”) is executed, which loads a malicious DLL, responsible for loading the SpiceRAT malware.

SpiceRAT and SugarGh0st malware
Chinese hackers distribute SpiceRAT and SugarGh0st malware

The second infection method uses an HTML Application (HTA) that installs a Windows batch script and a Base64-encoded downloader binary, with the former launching the executable file via a scheduled task every five minutes.

The batch script is also designed to run another legitimate executable “ChromeDriver.exe” every 10 minutes, which then loads a DLL that, in turn, loads SpiceRAT.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: ValleyRAT malware resurfaces with new data-stealing tactics

The emergence of new hacking groups such as SneakyChef highlights the ever-evolving nature of cybersecurity threats and the need for constant vigilance and proactive measures to protect against them. As cybercriminals continue to develop new techniques and tools, it is important for organizations to stay informed and adopt strong security measures to protect their sensitive data and assets. It is important for governments, companies and individuals to invest in cybersecurity that can help mitigate the risks posed by such threat actors.

Source: thehackernews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS