Daggerfly Cyberattack Campaign Hits African Telecom Services Providers

April 20, 2023Rabbi LakshmananCyber ​​Attack/Malware

Communication service provider in Africa

African telecom service providers have been the target of a new campaign orchestrated by China-linked threat actors since at least November 2022.

The intrusion was traced to a hacking crew tracked by Symantec. dagger flyand is tracked by the broader cybersecurity community as Bronze Highland and Evasive Panda.

The campaign utilizes “a previously unseen plugin for the MgBot malware framework,” the cybersecurity firm said in a report shared with The Hacker News. “The attacker was also observed using the PlugX loader to exploit his legitimate AnyDesk remote desktop software.”

Daggerfly’s use of the MgBot loader (aka BLame or MgmBot) was highlighted by Malwarebytes in July 2020 as part of a phishing campaign targeting Indian government officials and individuals in Hong Kong.

According to Secureworks, attackers use spear phishing as the initial infection vector to drop other tools such as MgBot and Cobalt Strike, an Android Remote Access Trojan (RAT) named KsRemote.

The group is suspected of spying on human rights and democracy defenders in China, as well as neighboring countries, dating back to 2014.

The attack chain analyzed by Symantec uses Living Off The Land (LotL) tools such as BITSAdmin and PowerShell to deliver next-stage payloads such as the legitimate AnyDesk executable and credential harvesting utilities. is shown.

The attacker then creates a local account, sets persistence on the victim’s system, and deploys the MgBot modular framework. The MgBot modular framework includes browser data collection, keystroke logging, screenshot capturing, audio recording, and an active directory service.

upcoming webinars

Defending with Deception: Driving Zero Trust Security

See how Deception can detect advanced threats, stop lateral movement, and strengthen your Zero Trust strategy. Join us for an insightful webinar!

Save my seat!

“All of these features would have allowed the attacker to gather a large amount of information from the victim’s machine,” said Symantec. “The functionality of these plugins also demonstrates that information gathering is the primary goal of the attackers during this campaign.”

The comprehensive nature of MgBot indicates that it is actively maintained and updated by operators to gain access to the victim’s environment.

The disclosure arrives almost a month after SentinelOne detailed a campaign called Tainted Love targeting telecom providers in the Middle East in Q1 2023. This was due to a Chinese cyber espionage group with overlaps with Gallium (aka Othorene).

Symantec further said it has identified three additional victims of the same activity cluster located in Asia and Africa. His two victims, compromised in November 2022, are subsidiaries of telecommunications companies in the Middle East.

Symantec said:

Did you find this article interesting?Please follow us twitter and LinkedIn to read more exclusive content we post.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *