HomeSecurityHackers target global infrastructure with ransomware attacks

Hackers target global infrastructure with ransomware attacks

Hackers with suspected links to China and North Korea have been involved in ransomware attacks and encryption , targeting critical global infrastructure between 2021 and 2023.

ransomware infrastructure

According to a joint report by cybersecurity firms SentinelOne and Recorded Future, shared with The Hacker News, one cluster of activity is associated with the ChamelGang group (also known as CamoFei), while the second cluster overlaps with activity attributed to groups funded by China and North Korea.

Read more: The importance of encryption in cloud data

ChamelGang's attacks include targeting the All India Institute of Medical Sciences (AIIMS) and the Brazilian Presidency in 2022 using the CatB ransomware, as well as attacks on a government entity in East Asia and an aviation organization in the Indian subcontinent.

" Cyber-espionage threat actors are engaging in an increasingly worrying trend of using ransomware as the final stage in their operations, for financial purposes, disruption, distraction, and destruction or removal of evidence," security researchers Aleksandar Milenkoski and Julian-Ferdinand Vögele said.

Ransomware attacks in this context not only serve as a means of sabotage but also allow threat actors to cover their tracks by destroying objects that could alert them to their presence.

ChamelGang, first documented by Positive Technologies in 2021, is considered a China-linked group with diverse motivations, including intelligence gathering, data theft, financial gain, denial-of-service (DoS) attacks , and intelligence operations. According to Taiwanese cybersecurity firm TeamT5, the organization has a wide range of tools in its arsenal.

See also: RansomHub ransomware: New variant targets VMware ESXi VMs

These include BeaconLoader, Cobalt Strike, backdoors such as AukDoor and DoorMe, as well as a ransomware strain known as CatB. CatB has been identified as being used in attacks targeting Brazil and India, with common features in the ransom note, the format of the contact email address, the cryptocurrency wallet address, and the filename extension of the encrypted files.

Attacks recorded in 2023 used an updated version of BeaconLoader to deliver Cobalt Strikein order to perform reconnaissance and post-exploit activities, such as dropping additional tools and extracting the NTDS.dit database file.

Additionally, it is worth noting that the custom malware used by ChamelGang, such as DoorMe and MGDrive (with its macOS variant known as Gimmick), has also been linked to other Chinese threat groups such as REF2924 and Storm Cloud. This once again highlights the possibility of a “digital manufacturer” providing malware to various operational groups.

See also: Neiman Marcus confirms data breach after Snowflake

Another set of hacking attacks involves the use of Jetico BestCrypt and Microsoft BitLocker in cyberattacks affecting various industry sectors in North America, South America, and Europe. It is estimated that up to 37 organizations have been targeted, primarily in the US manufacturing sector.

ransomware infrastructure

The tactics observed in the cluster, according to two cybersecurity firms, are consistent with those attributed to a Chinese hacking called APT41 and a North Korean hacker known as Andariel. The presence of tools such as the China Chopper web shell and a backdoor known as DTrack reinforces this connection.

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

"Cyber ​​espionage operations disguised as ransomware activities allow adversaries to disavow responsibility by attributing the actions to independent cybercriminals rather than state entities," the researchers note.

Read more: Botnet exploits vulnerability in Zyxel NAS devices

"The use of ransomware by cyberespionage groups blurs the lines between cybercrime and cyberespionage, offering adversaries both strategic and operational advantages.".

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS