HomeSecurityChinese hackers target Japanese companies with LODEINFO and NOOPDOOR Malware

Chinese hackers target Japanese companies with LODEINFO and NOOPDOOR Malware

Japanese companies are being targeted by Chinese hackers, who are using the malware LODEINFO and NOOPDOOR.

LODEINFO and NOOPDOOR

These attacks aim to collect sensitive information from compromised hosts.

Israeli cybersecurity Cybereason is tracking the malicious campaign called Cuckoo Spear, which it links to other well-known campaigns such as APT10, which is also called Bronze Riverside, ChessMaster, Cicada, Cloudhopper, MenuPass, MirrorFace, Purple Typhoon, and Stone Panda.

See also: China's Chang'e 5 rover detects water molecules on the moon

"The hackers behind NOOPDOOR not only used LODEINFO during this campaign, but also exploited the new backdoor to extract data from compromised corporate networks," it said.

This information came to light weeks after JPCERT/CC warned of cyberattacks by hackers targeting Japanese entities through two malware strains.

In January, ITOCHU Cyber ​​& Intelligence revealed an updated version of the LODEINFO backdoor that incorporates anti-analysis techniques, highlighting the use of spear-phishing emails to spread the malware.

Trend Micro, which first coined the term MenuPass to describe this hacking campaign, has characterized APT10 as a protective group, comprising two subgroups: Earth Tengshe and Earth Kasha. This hacking gang has been known to be active since at least 2006.

Earth Tengshe is associated with malicious gangs distributing SigLoader and SodaMaster, while Earth Kasha focuses exclusively on the use of LODEINFO and NOOPDO. Both subgroups have been observed targeting consumer-facing applications with the aim of extracting data and information from the network.

Read more: Chinese hackers APT41 target Italy, Spain, Turkey and the UK

Additionally, Earth Tengshe appears to be linked to another campaign called Bronze Starlight (also known as Emperor Dragonfly or Storm-0401). This campaign has a history of operating ransomwaresuch as LockFile, Atom Silo, Rook, Night Sky, Pandora, and Cheerscrypt.

On the other hand, Earth Kasha has been found to have modified its original access methods, exploiting applications targeted at the public since April 2023. This is achieved through unpatched vulnerabilities in platforms such as Array AG (CVE-2023-28461), Fortinet (CVE-2023-27997), and Proself instances (CVE-2023-45727), with the aim of distributing the malware , also known as HiddenFace.

LODEINFO NOOPDOOR

LODEINFO comes with a number of commands that allow for the execution of arbitrary shellcode, keystroke logging, screenshot capture, process termination, and sending files to a server under the hackers. Similarly, NOOPDOOR, which shares code similarities with the APT10 backdoor known as ANEL Loader, offers functions for uploading and downloading files, executing shellcode, and the ability to run additional programs.

See also: Chinese hackers target ships with malware on USB sticks

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Cybereason states: “LODEINFO appears to operate as the primary backdoor, while NOOPDOOR operates as a secondary one, ensuring its presence in the compromised corporate network for over two years.”

Source: thehackernews

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS