Chinese Hackers
#73

Quote:Chinese-speaking users are the target of a "highly organized and sophisticated attack" campaign that is likely leveraging phishing emails to infect Windows systems with Cobalt Strike payloads.

"The attackers managed to move laterally, establish persistence and remain undetected within the systems for more than two weeks," Securonix researchers Den Iuzvyk and Tim Peck said in a new report.

The covert campaign, codenamed SLOW#TEMPEST and not attributed to any known threat actor, commences with malicious ZIP files that, when unpacked, activates the infection chain, leading to the deployment of the post-exploitation toolkit on compromised systems.

Present with the ZIP archive is a Windows shortcut (LNK) file that disguises itself as a Microsoft Word file, "违规远程控制软件人员名单.docx.lnk," which roughly translates to "List of people who violated the remote control software regulations."

"Given the language used in the lure files, it's likely that specific Chinese related business or government sectors could be targeted as they would both employ individuals who follow 'remote control software regulations,'" the researchers pointed out.
...
"The attackers further enabled themselves to hide in the weeds in compromised systems by manually elevating the privileges of the built-in Guest user account," the researchers said.

"This account, typically disabled and minimally privileged, was transformed into a powerful access point by adding it to the critical administrative group and assigning it a new password. This backdoor allows them to maintain access to the system with minimal detection, as the Guest account is often not monitored as closely as other user accounts."

The unknown threat actor subsequently proceeded to move laterally across the network using Remote Desktop Protocol (RDP) and credentials obtained via the Mimikatz password extraction tool, followed by setting up remote connections back to their command-and-control (C2) server from each of those machines.

The post-exploitation phase is further characterized by the execution of several enumeration commands and the use of the BloodHound tool for active directory (AD) reconnaissance, the results of which were then exfiltrated in the form of a ZIP archive.
...
The connections to China are reinforced by the fact that all of the C2 servers are hosted in China by Shenzhen Tencent Computer Systems Company Limited. On top of that, a majority of the artifacts connected with the campaign have originated from China.

"Although there was no solid evidence linking this attack to any known APT groups, it is likely orchestrated by a seasoned threat actor who had experience using advanced exploitation frameworks such as Cobalt Strike and a wide range of other post-exploitation tools," the researchers concluded.
"For God has not destined us for wrath, but for obtaining salvation through our Lord Jesus Christ," 1 Thessalonians 5:9

Maranatha!

The Internet might be either your friend or enemy. It just depends on whether or not she has a bad hair day.

[Image: SP1-Scripter.png]
[Image: SP1-Writer.png]
[Image: SP1-Poet.png]
[Image: SP1-PixelArtist.png]
[Image: SP1-Reporter.png]

My Original Stories (available in English and Spanish)

List of Compiled Binary Executables I have published...
HiddenChest & Roole

Give me a free copy of your completed game if you include at least 3 of my scripts! Laughing + Tongue sticking out

Just some scripts I've already published on the board...
KyoGemBoost XP VX & ACE, RandomEnkounters XP, KSkillShop XP, Kolloseum States XP, KEvents XP, KScenario XP & Gosu, KyoPrizeShop XP Mangostan, Kuests XP, KyoDiscounts XP VX, ACE & MV, KChest XP VX & ACE 2016, KTelePort XP, KSkillMax XP & VX & ACE, Gem Roulette XP VX & VX Ace, KRespawnPoint XP, VX & VX Ace, GiveAway XP VX & ACE, Klearance XP VX & ACE, KUnits XP VX, ACE & Gosu 2017, KLevel XP, KRumors XP & ACE, KMonsterPals XP VX & ACE, KStatsRefill XP VX & ACE, KLotto XP VX & ACE, KItemDesc XP & VX, KPocket XP & VX, OpenChest XP VX & ACE
Reply }


Messages In This Thread
Chinese Hackers - by kyonides - 02-19-2020, 05:17 AM
RE: Chinese Hackers - by KDC - 02-19-2020, 08:44 AM
RE: Chinese Hackers - by kyonides - 03-01-2020, 07:31 AM
RE: Chinese Hackers - by kyonides - 03-26-2020, 01:27 AM
RE: Chinese Hackers - by kyonides - 05-03-2020, 05:20 AM
RE: Chinese Hackers - by kyonides - 05-14-2020, 06:18 AM
RE: Chinese Hackers - by kyonides - 05-21-2020, 03:29 AM
RE: Chinese Hackers - by kyonides - 07-07-2020, 06:21 AM
RE: Chinese Hackers - by kyonides - 07-22-2020, 06:33 AM
RE: Chinese Hackers - by kyonides - 08-01-2020, 03:08 AM
RE: Chinese Hackers - by kyonides - 08-20-2020, 05:01 AM
RE: Chinese Hackers - by kyonides - 09-09-2020, 01:36 AM
RE: Chinese Hackers - by kyonides - 09-17-2020, 05:38 AM
RE: Chinese Hackers - by kyonides - 09-26-2020, 05:33 AM
RE: Chinese Hackers - by kyonides - 10-02-2020, 04:21 AM
RE: Chinese Hackers - by kyonides - 10-05-2020, 10:35 PM
RE: Chinese Hackers - by kyonides - 10-08-2020, 05:12 AM
RE: Chinese Hackers - by kyonides - 10-10-2020, 01:16 AM
RE: Chinese Hackers - by kyonides - 10-20-2020, 11:48 PM
RE: Chinese Hackers - by kyonides - 11-18-2020, 04:36 AM
RE: Chinese Hackers - by kyonides - 11-19-2020, 10:36 PM
RE: Chinese Hackers - by kyonides - 11-24-2020, 08:22 AM
RE: Chinese Hackers - by kyonides - 12-18-2020, 01:34 AM
RE: Chinese Hackers - by kyonides - 01-20-2021, 11:33 AM
RE: Chinese Hackers - by kyonides - 03-11-2021, 06:36 AM
RE: Chinese Hackers - by kyonides - 07-21-2021, 07:29 PM
RE: Chinese Hackers - by kyonides - 08-07-2021, 07:38 PM
RE: Chinese Hackers - by kyonides - 03-03-2022, 06:01 AM
RE: Chinese Hackers - by kyonides - 04-04-2022, 07:37 AM
RE: Chinese Hackers - by kyonides - 07-26-2022, 07:09 AM
RE: Chinese Hackers - by kyonides - 08-24-2022, 01:04 AM
RE: Chinese Hackers - by kyonides - 09-01-2022, 04:10 AM
RE: Chinese Hackers - by kyonides - 10-17-2022, 03:50 AM
RE: Chinese Hackers - by kyonides - 11-21-2022, 03:43 AM
RE: Chinese Hackers - by kyonides - 12-15-2022, 02:15 AM
RE: Chinese Hackers - by kyonides - 02-28-2023, 11:50 PM
RE: Chinese Hackers - by kyonides - 03-06-2023, 02:36 AM
RE: Chinese Hackers - by kyonides - 03-09-2023, 07:34 AM
RE: Chinese Hackers - by kyonides - 03-12-2023, 05:45 AM
RE: Chinese Hackers - by kyonides - 03-24-2023, 07:13 PM
RE: Chinese Hackers - by kyonides - 04-03-2023, 07:08 AM
RE: Chinese Hackers - by kyonides - 05-15-2023, 11:43 PM
RE: Chinese Hackers - by kyonides - 06-04-2023, 04:58 AM
RE: Chinese Hackers - by kyonides - 06-16-2023, 11:13 PM
RE: Chinese Hackers - by kyonides - 07-17-2023, 04:52 AM
RE: Chinese Hackers - by kyonides - 07-21-2023, 07:01 AM
RE: Chinese Hackers - by kyonides - 07-25-2023, 07:24 AM
RE: Chinese Hackers - by kyonides - 07-28-2023, 06:51 AM
RE: Chinese Hackers - by kyonides - 08-24-2023, 01:09 AM
RE: Chinese Hackers - by kyonides - 09-12-2023, 06:41 AM
RE: Chinese Hackers - by kyonides - 10-23-2023, 03:49 AM
RE: Chinese Hackers - by kyonides - 12-16-2023, 07:32 AM
RE: Chinese Hackers - by kyonides - 12-31-2023, 01:23 AM
RE: Chinese Hackers - by kyonides - 01-15-2024, 02:03 AM
RE: Chinese Hackers - by kyonides - 02-02-2024, 10:44 PM
RE: Chinese Hackers - by kyonides - 02-06-2024, 07:20 AM
RE: Chinese Hackers - by kyonides - 02-08-2024, 04:38 AM
RE: Chinese Hackers - by kyonides - 02-10-2024, 06:28 AM
RE: Chinese Hackers - by kyonides - 02-19-2024, 04:07 AM
RE: Chinese Hackers - by kyonides - 02-26-2024, 05:24 AM
RE: Chinese Hackers - by kyonides - 03-11-2024, 02:42 AM
RE: Chinese Hackers - by kyonides - 03-29-2024, 06:10 AM
RE: Chinese Hackers - by kyonides - 04-04-2024, 01:59 AM
RE: Chinese Hackers - by kyonides - 04-21-2024, 06:11 AM
RE: Chinese Hackers - by kyonides - 05-10-2024, 08:17 AM
RE: Chinese Hackers - by kyonides - 05-12-2024, 06:12 AM
RE: Chinese Hackers - by kyonides - 06-17-2024, 01:19 AM
RE: Chinese Hackers - by kyonides - 06-25-2024, 07:36 AM
RE: Chinese Hackers - by kyonides - 07-11-2024, 03:16 AM
RE: Chinese Hackers - by kyonides - 08-02-2024, 09:08 AM
RE: Chinese Hackers - by kyonides - 08-25-2024, 11:01 PM
RE: Chinese Hackers - by kyonides - 08-27-2024, 06:10 PM
RE: Chinese Hackers - by kyonides - 09-02-2024, 04:53 AM
RE: Chinese Hackers - by kyonides - Yesterday, 01:14 AM



Users browsing this thread: 3 Guest(s)