Chinese APT Group Vixen Panda Targets Iranian Government Entities

China’s Advanced Persistent Threat (APT) known as vixen panda is linked to a new series of attacks targeting the Iranian government between July and December 2022.

This claim comes from the following cybersecurity researchers: Palo Alto NetworksUnit 42 who shared a report about them Information security on mail.

Nicknamed “Playful Taurus” in Unit 42, Vixen Panda is also known as APT15, Backdoor Diplomacy, KeChang, and NICKEL. This actor has been active since at least 2010 and often targets government and diplomatic organizations in the Americas, Africa, and the Middle East.

“In June 2021, ESET will announce that this group Upgraded toolkit To include a new backdoor called Turian.

“This backdoor is still in active development, and we believe it is only used by Playful Taurus actors. Identified the and control infrastructure.”

Both variants with additional obfuscation and modified network protocols were deployed in attacks against multiple Iranian government networks.

Unit 42 wrote: C2 server. “

According to Palo Alto Networks, Turian backdoor upgrades and new C2 infrastructure suggest Vixen Panda continues to be successful in its cyber espionage campaigns.

in available advisories herethe company also shared file samples and indicators of compromise (IoCs) from the new malicious campaign, along with various protection and mitigation suggestions.

This includes using advanced URL filtering and DNS security practices to identify domains associated with Playful Taurus as malicious.

Unit 42’s recommendation is that new data from Recorded Future suggests that China’s regulatory A new monetization method.

Source link

Leave a Reply

Your email address will not be published. Required fields are marked *