HomeSecurityCloudflare: Warns of hacking gang targeting Asia

Cloudflare: Warns of hacking gang targeting Asia

A hacking gang has been observed in India, which uses cloud providers to facilitate credential collection, malware distribution, and command and control (C2) activities.

SloppyLemming

Internet infrastructure and security company Cloudflare is tracking this activity, known as SloppyLemming, which is also referred to as Outrider Tiger and Fishing Elephant.

See related: Predator spyware – USA: New sanctions on Intellexa executives

“Since late 2022, SloppyLemming has been regularly using Cloudflare Workers, likely as part of a spyware hacking ring targeting countries in South and East Asia,” Cloudflare said. SloppyLemming has been active since at least July 2021, with previous campaigns using malware such as Ares RAT and WarHawk, which is linked to the notorious SideWinder hacking ring. The use of Ares RAT has also been linked to SideCopy, which is likely of Pakistani origin.

SloppyLemming's targets include government and legal entities, as well as energy, education, telecommunications, and technology sectors in Pakistan, Sri Lanka, Bangladesh, China, Nepal, and Indonesia.

The attacks include phishing emails that attempt to trick recipients into clicking on a malicious link, creating a sense of urgency to complete a mandatory process within 24 hours. By clicking on the URL, the victim is taken to a credential collection page, allowing the hacker gang to gain unauthorized access to targeted email accounts within organizations.

Read more: USA: Bill to address threats from Chinese hackers

"The actor uses a custom tool called CloudPhish to create a malicious Cloudflare Worker, which handles the credential logging logic and injects victims' credentials into the threat actor," the company said.

Some attacks carried out by SloppyLemming leverage similar techniques to steal Google OAuth tokens, including the use of RAR files rigged with explosives (“CamScanner 06-10-2024 15.29.rar”). These files likely exploit a WinRAR flaw (CVE-238831), which allows remote code execution.

Inside the RAR file is an executable file that, in addition to displaying the decoy document, secretly loads “CRYPTSP.dll.” This file acts as a downloader to retrieve a remote access trojan hosted on Dropbox.

Cloudflare: Warns of hacking gang targeting Asia

It is important to mention that cybersecurity firm SEQRITE described a similar hacking campaign carried out by SideCopy actors last year, targeting the Indian government and defense sector. This campaign involved distributing the Ares RAT via ZIP files with names like “DocScanner_AUG_2023.zip” and “DocScanner-Oct.zip,” which exploited the same vulnerability.

See more: SloppyLemming group targets Pakistani government

A third infection method used by SloppyLemming involved phishing, leading potential targets to a fake website that pretended to be the Punjab Information Board (PITB) in Pakistan. Users were then redirected to another website, which contained a shortcut to a URL file.

The URL was embedded with code that downloaded an executable file named PITB-JR5124.exe from the same server. This binary is a legitimate file that is used to side-load a malicious DLL, known as profapi.dll, which then communicates with a Cloudflare employee.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The company noted that Cloudflare Worker URLs act as proxies, forwarding requests to the actual C2 domain used by the adversary, which is “aljazeerak[.]online.”.

Cloudflare: Warns of hacking gang targeting Asia

Cloudflare said it had “observed coordinated efforts by SloppyLemming to target Pakistani police departments and other law enforcement organizations.” It added that “there are indications that the hacking gang is targeting entities related to the operation and maintenance of Pakistan’s only nuclear facility.”.

Read also: Arkansas City: Cyberattack on water treatment facility

Additionally, some of the other targets of the credential collection activity include Sri Lankan and Bangladeshi government and military organizations, as well as, to a lesser extent, entities from China's energy and academic sectors.

Source: thehackernews

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS