An actor known as Alloy Taurus has been observed deploying a new variant of the PingPull malware targeting Linux systems.
Rated by Palo Alto Networks’ Unit 42 to be a Chinese Advanced Persistent Threat (APT) group focused on espionage, Alloy Taurus has been active since at least 2012.
Read more about China-based attackers: EU Cybersecurity Agency warns against Chinese APTs
“Historically, this group has targeted telecommunications companies with operations in Asia, Europe and Africa,” Unit 42 wrote in an advisory released today. “Over the past few years, we have also seen this group expand its targets to include financial institutions and government agencies.”
As part of the new campaign, security researchers say they have also confirmed that Alloy Taurus is targeting individuals in South Africa and Nepal.
The Linux samples observed by Unit 42 were initially identified as benign by most vendors. However, further analysis revealed that it matched the communication structure, parameters, and commands of known PingPull malware.
Malicious tools are designed to communicate with command and control (C2) servers using encrypted data, allowing them to receive and execute commands from them. The results of these commands are sent back to the server for further action.
According to Unit 42, this Linux variant of PingPull malware uses the same AES key as the original Windows PE (Preinstallation Environment) variant to encrypt communications with its C2 server.
While investigating the C2 domain of the PingPull Linux variant, researchers also identified additional samples communicating with the same domain.
This malware turned out to be a backdoor from a team called Sword2033. The backdoor supports her three key functions: uploading files to and downloading files from the system, and executing commands. The values and functionality of these commands are the same as those used by the PingPull malware. Further analysis of the C2 infrastructure revealed links to Alloy Taurus activity.
“The identification of a Linux variant of the PingPull malware and the recent use of the Sword2033 backdoor suggest that this group continues to evolve its operations to aid in espionage,” the advisory said. It is written
“We encourage all organizations to use our findings to inform the deployment of protective measures to defend against this threat group.”
The findings come as Russian-backed hackers turn their attention to cyber espionage in Ukraine.