Chinese Hacker Group ‘Flea’ Targets American Ministries with Graphican Backdoor

June 21, 2023Ravi LakshmananCyber ​​Threat / APT

Chinese hacker group

The Foreign Ministry in the Americas has been targeted by the Chinese government-backed organization ‘Actor’. fleas As part of a recent campaign that ran from late 2022 to early 2023.

According to Broadcom’s Symantec, the cyberattack involved a new backdoor codenamed Graphican. Other targets included government finance departments and companies selling products in the Americas, and an unspecified victim in a European country.

“Flea used a number of tools in this campaign,” the company said in a report shared with HackerNews, noting that the attacker was “large and well-resourced.” “The attacker utilized not only his new Graphican backdoor, but also various ground-based tools and tools he had previously linked to Flea.”

Also known as APT15, BackdoorDiplomacy, ke3chang, Nylon Typhoon (formerly Nickel), Playful Taurus, Royal APT, and Vixen Panda, Flea is a high-altitude threat that has been known to attack governments, diplomatic missions and embassies since at least 2004. persistent threat group.

cyber security

Earlier this year, the group was said to be behind a series of attacks targeting Iranian government entities from July to late December 2022.

And last month, it emerged that the Kenyan government had been the target of a broad three-year intelligence-gathering operation targeting key ministries and state agencies in the country.

As Lookout detailed in July 2020 and November 2022, respectively, nation-state crews were also involved in multiple Android surveillance campaigns (SilkBean and BadBazaar) targeting Uyghurs in the People’s Republic of China and abroad. allegedly involved.

Graphican is said to be an evolution of a known Flea backdoor called Ketrum, whose functionality was later merged with another implant known as Okrum, resulting in a new malware called Ketrum.

This backdoor has the same functionality, but differs from Ketrican in that it leverages the Microsoft Graph API and OneDrive to retrieve command and control (C&C) server details.

“The observed Graphian samples did not have a hard-coded C&C server, they connected to OneDrive via the Microsoft Graph API and obtained the encrypted C&C server address from a child folder within the “person” folder. ,” said Symantec.

upcoming webinars

🔐 Mastering API Security: Understanding Your True Attack Surface

Discover untapped vulnerabilities in your API ecosystem and take proactive steps towards ironclad security. Join us for an insightful webinar!

join the session

“The malware then decoded the folder name and used it as the malware’s C&C server.”

It is worth pointing out that Microsoft Graph API and OneDrive abuse has been previously observed in cases of both Russian and Chinese threat actors such as APT28 (aka Sofacy or Swallowtail) and Bad Magic (aka Red Stinger). .

Graphican has the ability to poll a C&C server for new commands to execute. This includes creating interactive command lines that can be controlled from the server, downloading files to the host, and setting up covert processes to collect desired data.

One of the other notable tools used in this campaign consisted of an updated version of the EWSTEW backdoor for extracting emails sent and received on compromised Microsoft Exchange servers.

“Flea’s use of new backdoors shows that despite years of activity, the group continues to actively develop new tools,” Symantec said. “This group has developed multiple custom tools over the years.”

“The similarities in functionality between Graphican and the known Ketrican backdoor may indicate that this group is less concerned that there is activity from it.”

Did you enjoy this article? Follow us twitter You can read more exclusive content we post on LinkedIn.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *