HomeSecurityChinese hackers Mustang Panda abuse MAVInject.exe

Chinese hackers Mustang Panda abuse MAVInject.exe

Chinese state-sponsored hackers Mustang Panda (or Earth Preta) are using a new technique to evade detection and maintain control over infected systems. Specifically, the Mustang Panda group is abusing the legitimate Windows utility, Microsoft Application Virtualization Injector (MAVInject.exe) , to inject a malicious payload into an external process (watefor.exe) when the ESET antivirus application is running .

MAVInject.exe Chinese hackers Mustang Panda

" The attack involves installing multiple files, including legitimate executables and malicious ones. It also uses a PDF as bait to distract the victim ," Trend Micro security researchers Nathaniel Morales and Nick Dai noted

See also: Chinese hackers breach telecommunications via Cisco routers

“Additionally, Earth Preta uses Setup Factory, an installer builder for Windows software, to install and execute the payload. This allows hackers to evade detection and maintain persistence on compromised systems.“.

The attack begins with an executable file (“IRSetup.exe”) that serves as a dropper for multiple files, including a decoy document designed to target users based in Thailand. The executable is likely distributed via spear-phishing emails.

The binary then proceeds to execute a legitimate Electronic Arts (EA) application (“OriginLegacyCLI.exe”) to load a DLL named “EACore.dll.” This is a modified version of the TONESHELL backdoor that has been previously linked to Mustang Panda hackers.

See also: Chinese hackers combined RA World ransomware with spying tools

The malware’s main function is to check if two processes associated with ESET antivirus applications are running: “ekrn.exe” or “egui.exe”. If they are, “waitfor.exe” is executed and then “MAVInject.exe” is used to execute the malware, without being noticed.

Chinese hackers Mustang Panda abuse MAVInject.exe

The malware eventually decrypts the embedded shellcode which allows it to establish connections to a remote server (“www.militarytc[.]com:443”) to receive commands to create a reverse shell, move files, and delete files.

“The Earth Preta group malware, a variant of the TONESHELL backdoor, downloads with a legitimate Electronic Arts application and communicates with a command and control server to extract data,” the researchers said.

See also: Chinese cyberspies use new SSH backdoor

Chinese hackers pose a significant threat to organizations and governments around the world with highly adaptive techniques and use of advanced tools. To protect against these attacks, it is important for organizations to regularly update their systems, implement strong cybersecurity measures , and educate employees on security best practices.

In addition, governments must take steps to strengthen cyber defenses and work with other nations to combat this growing threat. It is vital that we remain vigilant to prevent attacks by Chinese hackers and protect our sensitive information.

Source: thehackernews.com

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS