New SPECTRALVIPER Backdoor Targeting Vietnamese Public Companies

June 10, 2023Ravi LakshmananCyber ​​Attack/Malware

SPECTRALPIPER BACKDOOR

Publicly traded companies in Vietnam have been targeted as part of an ongoing campaign to deploy a novel backdoor called . Spectra Viper.

In a report on Friday, Elastic Security Labs said, “SPECTRALVIPER is a highly obfuscated, previously undisclosed x64 backer that provides PE loading and injection, file upload and download, file and directory manipulation, and token impersonation capabilities. It’s the door,” he said.

The attack is believed to be by the actor tracked as REF2754 and overlaps with Vietnamese threat groups known as APT32, Canvas Cyclone (formerly Bismuth), Cobalt Kitty, and OceanLotus.

In December 2020, Meta linked the hacking group’s activities to a cybersecurity firm called CyberOne Group.

cyber security

The latest infection flow discovered by Elastic utilizes the SysInternals ProcDump utility to load an unsigned DLL file containing DONUUTLOADER. This file is configured to load SPECTRALVIPER and other malware such as P8LOADER and POWERSEAL.

SPECTRALVIPER is designed to connect to attacker-controlled servers and await further commands, while also employing obfuscation techniques such as control flow flattening to prevent analysis.

SPECTRALPIPER BACKDOOR

Written in C++, P8LOADER can launch arbitrary payloads from files or memory. It also uses a dedicated PowerShell runner named POWERSEAL that is instrumented to run the provided PowerShell scripts or commands.

REF2754 is said to have tactical commonalities with another group called REF4322, which primarily targets entities in Vietnam to deploy a post-exploitation implant called PHOREAL (aka Rizzo). Are known.

This link raises the possibility that “both the REF4322 and REF2754 activity groups represent campaigns planned and carried out by Vietnam state-related threats.”

upcoming webinars

🔐 Mastering API Security: Understanding Your True Attack Surface

Discover untapped vulnerabilities in your API ecosystem and take proactive steps towards ironclad security. Join us for an insightful webinar!

join the session

The discovery came to light because the intrusion set, dubbed REF2924, is associated with yet another malware called SOMNIRECORD that uses DNS queries to communicate with remote servers and bypass network security controls.

SOMNIRECORD, like NAPLISTENER, leverages existing open source projects and refines its functionality to retrieve information about infected machines, list all running processes, deploy web shells, and extract files already present in the system. Allows launching of executable files.

“The use of open source projects by attackers indicates that attackers are taking steps to customize existing tools for their specific needs, and may be trying to counter attribution attempts. Yes,” the company said.

Did you enjoy this article? Follow us twitter You can read more of the exclusive content we post on LinkedIn.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *