HomeSecurityCeranaKeeper hackers target Southeast Asia

CeranaKeeper hackers target Southeast Asia

CeranaKeeper hackers , a previously unknown group that appears to be linked to China , are behind a series of attacks targeting Southeast Asia to steal data.

hackers CeranaKeeper

Cybersecurity firm ESET, which has monitored campaigns targeting government institutions in Thailand since 2023, believes the hackers are linked to China and are using tools previously seen in Mustang Panda hackers.

“The group is constantly updating its backdoor to evade detection and diversifying its methods to enhance mass data,” said security researcher Romain Dumont.

See also: North Korean hackers Andariel attacks are financially motivated

“CeranaKeeper hackers abuse popular, legitimate cloud and file sharing services, such as Dropbox and OneDrive, to install custom backdoors and data extraction tools“.

In addition to Thailand, Myanmar, the Philippines, Japan and Taiwan have also been targeted . These regions have been targeted by Chinese hackers in the past.

ESET described the CeranaKeeper hackers as relentless, creative, and able to quickly change and adapt their methods to different conditions . The hackers are also aggressive and greedy, spreading across networks and trying to steal as much information as possible, according to the researchers.

The initial access method is not yet known.

The CeranaKeeper hackers' attacks are characterized by the use of malware such as TONESHELL, TONEINS, and PUBLOAD (all of which have been linked to the Mustang Panda group) and some new tools that aid in data theft.

“After gaining privileged access, the attackers installed the TONESHELL backdoor, developed a tool to steal credentials, and used a legitimate Avast driver and a custom application to disable security products on the target machine,” Dumont said.

See also: Beware! Hackers exploit critical Zimbra vulnerability

“From this compromised server, they used a remote administration console to deploy and execute backdoor on other computers on the network. In addition, the CeranaKeeper hackers used the compromised server to store updates for TONESHELL, turning it into an update server.“.

Some of the custom tools discovered by the researchers are: WavyExfiller, DropboxFlop, OneDoor and BingoShell.

CeranaKeeper hackers target Southeast Asia

Regarding the commonalities between Mustang Panda and CeranaKeeper, the researcher said: “The Mustang Panda group and the CeranaKeeper hackers appear to operate independently and each has its own set of tools. Both groups may rely on a common digital leader, which is not uncommon among groups linked to China. Alternatively, they may be exchanging information, which would explain the links that have been observed.”

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The CeranaKeeper attacks highlight the ever-evolving nature of cyber threats, with new actors and techniques emerging on a regular basis. As such, it is vital for organizations to adopt a proactive approach to cybersecurity, constantly monitoring for potential risks and staying up-to-date with the latest threats. By implementing comprehensive security measures and fostering a culture of security within their workforce, organizations can better protect themselves from cyberthreats.

See also: Storm-0501 hackers target hybrid cloud environments with ransomware

They must also be ready to respond quickly to potential incidents and work closely with law enforcement to bring perpetrators to justice.

The emergence of the CeranaKeeper hackers also highlights the importance of a global approach to cybersecurity .While attacks may target specific regions (e.g. Southeast Asia), the interconnected nature of our digital world means they can have far-reaching consequences. Therefore, it is essential for countries to work together and share information and resources in order to effectively combat cybercrime.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS