HomeSecurityStormBamboo group hacks ISP to spread malware

StormBamboo group hacks ISP to spread malware

A Chinese hacking group known as StormBamboo has compromised an unknown Internet Service Provider (ISP) to poison automatic software updates with malware.

See also: TryCloudflare abused to spread remote access malware

StormBamboo malware

Also known as Evasive Panda, Daggerfly , and StormCloud, this cyberespionage group has been active since at least 2012, targeting organizations across mainland China, Hong Kong, Macau, Nigeria, and various countries in Southeast and East Asia.

On Friday, threat researchers at Volexity revealed that the Chinese cyberespionage gang had exploited insecure HTTP software update mechanisms that did not validate digital signatures to deploy malware payloads on victims' Windows and macOS devices

"When these apps went to retrieve their updates, instead of installing the intended update, they would install malware, including, but not limited to, MACMA and POCOSTICK (also known as MGBot)," explained in a report published Friday.

To do this, the attackers stole and modified the victims' DNS requests and poisoned them with malicious IP addresses. This delivered the malware to the systems from StormBamboo's command and control servers without requiring any user interaction.

See also: New Flame Stealer malware steals credit card data

For example, they exploited 5KPlayer 's requests to update the youtube-dl dependency to push a backdoored installer hosted on their C2 servers.

StormBamboo group hacks ISP to spread malware

After breaching the target's systems, the malicious actors installed a malicious Google Chrome extension (ReloadText), which allowed them to collect and steal the browser's cookies and mail data.

In April 2023, ESET threat researchers also observed the hacking group deploying the Pocostick (MGBot) by abusing the automatic update mechanism for the Tencent QQ in attacks targeting international NGOs (non-governmental organizations).

Almost a year later, in July 2024, Symantec's security team spotted Chinese hackers targeting an American NGO in China and multiple organizations in Taiwan with new versions of the Macma macOS backdoor and Nightdoor Windows.

In both cases, although the attackers' capability was apparent, researchers believed it was either a supply chain attack or an adversary-in-the-middle (AITM) attack, but were unable to pinpoint the exact attack method.

See also: Fake Google Authenticator sites install DeerStealer malware

Malware attacks, such as that by the StormBamboo, are malicious attempts to disrupt, damage, or gain unauthorized access to computer systems and networks. These attacks can take many forms, including viruses, worms, trojans, ransomware, and spyware. Each type of malware uses different tactics to achieve its goals, often leading to significant data breaches, financial losses, and reputational damage. As technology evolves, so do the methods used by cybercriminals, making it vital for individuals and organizations to implement strong security measures, educate users about potential threats, and remain vigilant against emerging vulnerabilities.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Source: bleepingcomputer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS