Posts

Showing posts from November, 2020

BANDOOK(RAT)

Image
    BANDOOK(RAT)-Malware   The payload in this attack is a variant of an old full-featured RAT named Bandook. Written in both Delphi and C++, Bandook has a long history, starting in 2007 as a commercially available RAT that was developed by a Lebanese individual nicknamed PrinceAli.Bandook’s execution flow starts with a loader, written in Delphi, that uses the Process Hollowing technique to create a new instance of an Internet Explorer process and inject a malicious payload into it. The payload contacts the C&C server sends basic information about the infected machine and waits for additional commands from the server. Indicators of Compromise File Hash MD5 27f8d8bbbeeda5fc439ee18d9d4da343 44584c8d010242fddb44afe5ce860872 a6501c62b3a6ffa8d028a88138fe509f 7c15ee5b9a12dacaace8fb62271f12f1 4e9e12c98cfbc5f3aa3c1345bd063fa0 7ef261c151519e66ec369c63e4b1aed4 6effed1b1bb5e9ed6aafacb075c1d4e2 0475771b8bc3efc28b1834f3add608f3 045ce6679ed4086e2ded58470e24c15a 28ad9ace11919b57bf54...

TA416 Returns back with a Golang PlugX Malware Loader

Image
  TA416 Returns back with a Golang PlugX Malware Loader   APT group TA416 reemerges with new changes to its documented toolsets so it can continue launching espionage campaigns. Chinese advanced persistent threat (APT) group TA416, whose previous activity has been attributed to "Mustang Panda" and "RedDelta," has resumed attack activity. This new activity appears to be a continuation of previously reported campaigns that have targeted entities associated with diplomatic relations between the Vatican and the Chinese Communist Party, as well as entities in Myanmar and groups conducting diplomacy in Africa. Based on the available information, the actor's tool set, which they used to deliver PlugX malware payloads is detected as a new Golang variant of TA416's PlugX malware loader and noticed the PlugX malware is consistently used in targeted campaigns. This signifies the group's persistence in changing its toolset to evade detection. Indicators of Compromi...

South East Asian government Targeting by Chinese APT Group

Image
    South East Asian government Targeting by Chinese APT Group   A sophisticated advanced persistent threat (APT) group believed to be operating out of China has been stealthily targeting Southeast Asian governments. The FunnyDream campaign has been previously linked to high-profile government entities in Malaysia, Taiwan, and the Philippines, with a majority of victims located in Vietnam.           In this campaign, the group was using numerous malware families, a complex and complete arsenal of droppers, including the Chinoxy backdoor, PCShare RAT, and the FunnyDream backdoor. According to the available information, not only around 200 machines exhibited attack indicators associated with the campaign, evidence points to the fact the threat actor may have compromised domain controllers on the victim's network, allowing them to move laterally and potentially gain control of other systems. There are no clues as to how the infec...