State-sponsored Chinese crims targeted India with tax and COVID phishing

Blackberry’s Research and Intelligence Team has uncovered three phishing schemes targeting Indian nationals, and says a Chinese state-sponsored malware gang is the culprit.

Blackberry identified the responsible party as APT41 – a prolific Chinese state-sponsored cyberthreat group that has carried out what Fireye called “espionage activity in parallel with financially motivated operations” since at least 2012. The group targets many industries, including travel, telecommunications, healthcare, news, and education.

Blackberry says it joined the dots between phishing in India and APT41 by monitoring previously documented activity associated with commercial malware called “Cobalt Strike”. The action Blackberry spotted used a bespoke, malleable command-and-control (C2) profile that displayed similarities to other attacks.

The researchers found sufficient grounds to associate past and new campaigns by identifying nearly identical HTTP GET profile blocks and mapping out similarities in Beacon configuration data. A few clusters with unique configuration metadata suggested association with APT41.

The cyber attackers didn’t vary the domains used in their raids, with themes evident in naming naming conventions. Some posed as legitimate Microsoft sites, replacing an “i” with an “l” or sometimes omitting a letter. Those similarities provided further hints of connections between campaigns.

Through their investigation tactics, the Blackberry squad uncovered three phishing lures targeting Indian nationals, masquerading as government communications about taxes or COVID-19.

The phishing lures – an favourite APT41 tactic typically used in conjunction with information stealers, keyloggers and backdoors – loaded and executed Cobalt Strike Beacons onto the target’s network. Once on the user’s machine, the threat blended in, using a customized profile to shield its network traffic.

The three phishing lures came in the form of PDFs to distract the user while shady activity went on in the background. One scheme used an embedded PowerShell script, one a self-extracting archive, and another a zip file.

“We were able to uncover what we believe is additional APT41 infrastructure by taking these unique aspects and following the trail of digital breadcrumbs. Overlapping indicators of compromise (IOCs) linked the trail of our findings to those of two additional campaigns documented by Positive Technologies and Prevailion,” wrote Blackberry in a blog post.

“These findings show that the APT41 group is still regularly conducting new campaigns, and that they will likely continue to do so in the future,” Blackberry’s researchers warned. ®

Note: This article have been indexed to our site. We do not claim legitimacy, ownership or copyright of any of the content above. To see the article at original source Click Here

Related Posts
FCC tacks China Unicom onto list of Chinese telcos banned in the US thumbnail

FCC tacks China Unicom onto list of Chinese telcos banned in the US

Image: Costfoto/Barcroft Media via Getty Images The United States Federal Communications Commission (FCC) has removed the authority for China Unicom to operate in the US for national security reasons. The agency's four commissioners voted unanimously to revoke the licence of China Unicom's US subsidiary, with the agency explaining that the telco's presence in the US…
Read More
Sony won’t stop making Android phones thumbnail

Sony won’t stop making Android phones

Sony’s Xperia lineup of Android phones has never been particularly popular, and despite the sky-high pricing making them almost impossible to recommend, the company isn’t throwing in the towel any time soon, as Sony has just committed to years of further Android releases. In a press release, Sony and Qualcomm announced a “multi-year” deal to
Read More
Copil de 13 ani, salvat de neurochirurgii din Iași după ce a fost diagnosticat cu o tumoră rară. Intervenția chirurgicală a durat 5 ore thumbnail

Copil de 13 ani, salvat de neurochirurgii din Iași după ce a fost diagnosticat cu o tumoră rară. Intervenția chirurgicală a durat 5 ore

Un copil de doar 13 ani a fost diagnosticat de medici cu o tumoră foarte rară, numită „fratele care nu s-a născut”. Din fericire, a fost salvat în urma unei intervenții chirurgicale care a avut loc la Spitalul „Prof. Dr. Nicolae Oblu” din Iași. Copil salvat de neurochirurgii din Iași Dr. Lucian Eva, managerul Spitalului…
Read More
BMW is investing millions in the charging station startup Heycharge thumbnail

BMW is investing millions in the charging station startup Heycharge

Elektromobilität BMW steigt mit Millionen bei Ladesäulen-Startup Heycharge ein Auch wenn die Netzverbindung schwach ist, ermöglicht Heycharge das Laden von Elektroautos. Für ihre neue Technologie bekommen sie nun Millionen. Robert Lasowski, Mitgründer von Heycharge, lädt sein E-Auto auch bei schwacher NetzverbindungHeycharge Der Verkauf von E-Autos zieht weiterhin kräftig an. Das heißt auch, dass die Ladeinfrastruktur…
Read More
Soon a vaccine in the form of a patch? thumbnail

Soon a vaccine in the form of a patch?

L’un des obstacles à la vaccination de masse contre la Covid-19 est la peur des piqures. Appelée blénophobie, elle touche environ 10 % de la population. Pour contourner ce problème, des chercheurs ont conçu un minuscule « patch vaccinal » à microaiguilles. Le dispositif est imprimé en 3D, ce qui permet une production standardisée et à grande…
Read More
Marvel's Guardians of the Galaxy for free for laptops and desktops with NVIDIA GeForce RTX 3000 graphics cards thumbnail

Marvel's Guardians of the Galaxy for free for laptops and desktops with NVIDIA GeForce RTX 3000 graphics cards

Kilka dni temu omawialiśmy nowy zwiastun gry Marvel's Guardians of the Galaxy, który skupiał się na najważniejszych aspektach komputerowej wersji gry. Wiemy, że w przypadku tego tytułu, ze studiem Eidos Montreal współpracuje NVIDIA, co skutkuje implementacją nie tylko Ray Tracingu (jednak wyłącznie w formie zaawansowanych odbić), lecz także techniki DLSS. Premiera gry odbędzie się już…
Read More
Index Of News
Consider making some contribution to keep us going. We are donation based team who works to bring the best content to the readers. Every donation matters.
Donate Now

Subscription Form

Liking our Index Of News so far? Would you like to subscribe to receive news updates daily?

Total
0
Share