Businesses in China are being targeted by a highly organized and sophisticated campaign, which is likely using phishing emails to infect Windows systems with Cobalt Strike Payloads.

"The hackers managed to operate in such a way that they remained undetected within the systems for more than two weeks," said Securonix researchers Den Iuzvyk and Tim Peck in a recent report.
The stealth campaign, codenamed SLOW#TEMPEST, is not associated with any known threat actor. It starts with malicious ZIP files, which, once unzipped, trigger the infection chain, leading to the deployment of an exploit kit on compromised systems.
Read more: North Korean hackers target developers with malicious npm packages
Included with the ZIP file is a Windows shortcut (LNK) file that pretends to be a Microsoft Word document, named “違规负间机推设计件人发动机分发.docx.lnk”, which translates to “List of people who violated the control software regulations.”
"Given the language used in the decoy files, it is possible that some Chinese businesses or government sectors related to China could be targeted, as both employ individuals who adhere to 'control software regulations,'" the researchers noted.
The LNK file acts as a conduit to launch a legitimate Microsoft binary known as “LicensingUI.exe,” which uses DLL sideloading to execute a malicious DLL called “dui70.dll.” Both files are included in a ZIP archive located in a directory named “\其他信息\.__MACOS__\._MACOS_\__MACOSX\MACOS.” This attack represents the first documented case of DLL sideloading via LicensingUI.exe.
The DLL file is an installation in Cobalt Strike that allows permanent and discreet access to the infected computer, while simultaneously connecting to a remote server (“123.207.74[.]22”).
Remote access allows hackers to perform a variety of activities, such as deploying additional Cobalt Strike Payloads and creating man-in-the-middle connections.
The infection chain is also notable for setting up scheduled tasks that allow the periodic execution of a malicious executable file, named “lld.exe.” This file can execute arbitrary shell code directly in memory, thus leaving minimal traces on the hard drive.
See more: Hackers exploit zero-day vulnerability to target US internet service providers
" Hackers exploited their presence on the compromised systems by manually elevating the privileges of the built-in Guest user account," the researchers said.
This account, normally inactive and with limited privileges, was transformed into a powerful access point after being added to the critical administration group and assigned a new password. This backdoor allows them to maintain access to the system with minimal detection, as the Guest account is less tightly monitored than other user accounts.
The unknown threat actor continued to move laterally, using Remote Desktop Protocol (RDP) and credentials obtained through the Mimikatz password extractor . It then set up remote connections back to the command and control (C2) server from each of these machines.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
The post-exploitation phase involves running various enumeration commands and using the BloodHound tool to identify the Active Directory (AD). The results of this process are then exported in a ZIP file format.

Read also: Apache vulnerability allows hackers to steal sensitive data from Unix systems
The connections to China are strengthened as all C2 servers are hosted in China by Shenzhen Tencent Computer Systems Company Limited. Furthermore, the majority of the data related to the campaign originates from China.
The researchers concluded that "While there was no hard evidence linking this attack to known APT groups, it is likely that it was organized by an experienced threatwho was knowledgeable in the use of advanced exploit frameworks such as Cobalt Strike, as well as a wide range of other post-exploit tools."
Source: thehackernews
