{"id":1829,"date":"2023-10-05T21:20:00","date_gmt":"2023-10-05T21:20:00","guid":{"rendered":"https:\/\/www.darkreading.com\/threat-intelligence\/operation-jacana-dinodasrat-custom-backdoor"},"modified":"2023-10-05T21:20:00","modified_gmt":"2023-10-05T21:20:00","slug":"operation-jacana-reveals-dinodasrat-custom-backdoor","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2023\/10\/05\/operation-jacana-reveals-dinodasrat-custom-backdoor\/","title":{"rendered":"&#8216;Operation Jacana&#8217; Reveals DinodasRAT Custom Backdoor"},"content":{"rendered":"<p><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/10\/operation-jacana-reveals-dinodasrat-custom-backdoor.jpg?w=640&#038;ssl=1\"><\/p>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/10\/operation-jacana-reveals-dinodasrat-custom-backdoor-1.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<div readability=\"50.421421889616\">\n<div readability=\"49.958840037418\">\n<p>A fresh malware threat dubbed &#8220;DinodasRAT&#8221; has been uncovered, after being used in a targeted cyber-espionage campaign against a governmental entity in Guyana.<\/p>\n<p>The campaign, which ESET calls &#8220;Operation Jacana&#8221; after water birds that are native to the South American country, could be linked to (unnamed) <a href=\"https:\/\/www.darkreading.com\/threat-intelligence\/china-unleashes-flax-typhoon-apt-live-off-land-microsoft-warns\" target=\"_blank\" rel=\"noopener\">Chinese state-sponsored cyberattackers<\/a>, researchers noted.<\/p>\n<p>The campaign started with targeted spear-phishing emails that referenced recent Guyanese public and political affairs. Once in, the attackers moved laterally throughout the internal network; DinodasRAT was then used to exfiltrate files, manipulate Windows registry keys, and execute commands, according to <a href=\"https:\/\/www.welivesecurity.com\/en\/eset-research\/operation-jacana-spying-guyana-entity\/\" target=\"_blank\" rel=\"noopener\">ESET&#8217;s Thursday analysis of the Jacana operation<\/a>.<\/p>\n<p>The malware got its name based on the use of &#8220;Din&#8221; at the beginning of each of the victim identifiers it sends to the attackers, and that string&#8217;s similarity to the name of the diminutive hobbit Dinodas Brandybuck from <em>The Lord of the Rings<\/em>. Perhaps related: DinodasRAT uses the Tiny encryption algorithm to lock away its communications and exfiltration activities from prying eyes.<\/p>\n<h2 class=\"regular-text\">The Work of a Chinese APT?<\/h2>\n<p>ESET attributes the campaign and the custom RAT to a Chinese advanced persistent threat (APT) with medium confidence, based in particular on the attack&#8217;s use of the <a href=\"https:\/\/www.darkreading.com\/threat-intelligence\/china-unleashes-flax-typhoon-apt-live-off-land-microsoft-warns\" target=\"_blank\" rel=\"noopener\">Korplug RAT (aka PlugX)<\/a> \u2014 a favorite tool of <a href=\"https:\/\/www.darkreading.com\/endpoint\/group-tied-to-china-s-mustang-panda-targets-european-governments-with-smugx\" target=\"_blank\" rel=\"noopener\">China-aligned cyberthreat groups like Mustang Panda<\/a>.<\/p>\n<p>The attack could be in retaliation for recent hiccups in Guyana\u2013China diplomatic relations, according to ESET, such as Guyana&#8217;s arrest of three people in a money-laundering investigation involving Chinese companies. Those allegations were disputed by the local Chinese embassy.<\/p>\n<p>Interestingly, one lure mentioned a &#8220;Guyanese fugitive in Vietnam,&#8221; and served malware from a legitimate domain ending with gov.vn.<\/p>\n<p>&#8220;This domain indicates a Vietnamese governmental website; thus, we believe that the operators were able to compromise a Vietnamese governmental entity and use its infrastructure to host malware samples,&#8221; said ESET researcher Fernando Tavella in the report \u2014 again suggesting that the activity is the work of a more sophisticated player.<\/p>\n<\/div>\n<\/div>\n<div id=\"articleFooter-newsletterSignup\" readability=\"10.473404255319\">\n<p>Keep up with the latest cybersecurity threats, newly-discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox.<\/p>\n<p><a class=\"subscribe-btn dr-btn\" href=\"https:\/\/darkreading.tradepub.com\/c\/pubRD.mpl?secure=1&amp;sr=pp&amp;_t=pp:&amp;qf=w_defa3135&amp;ch=dr_eoa\" title=\"Subscribe\" target=\"_blank\" rel=\"noreferrer noopener\">Subscribe<\/a><\/div>\n<p><a href=\"https:\/\/www.darkreading.com\/threat-intelligence\/operation-jacana-dinodasrat-custom-backdoor\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A fresh malware threat dubbed &#8220;DinodasRAT&#8221; has been uncovered, after<\/p>\n","protected":false},"author":12,"featured_media":1830,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-1829","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/10\/operation-jacana-reveals-dinodasrat-custom-backdoor.jpg?fit=310%2C310&ssl=1",310,310,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/10\/operation-jacana-reveals-dinodasrat-custom-backdoor.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/10\/operation-jacana-reveals-dinodasrat-custom-backdoor.jpg?fit=300%2C300&ssl=1",300,300,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/10\/operation-jacana-reveals-dinodasrat-custom-backdoor.jpg?fit=310%2C310&ssl=1",310,310,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/10\/operation-jacana-reveals-dinodasrat-custom-backdoor.jpg?fit=310%2C310&ssl=1",310,310,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/10\/operation-jacana-reveals-dinodasrat-custom-backdoor.jpg?fit=310%2C310&ssl=1",310,310,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/10\/operation-jacana-reveals-dinodasrat-custom-backdoor.jpg?fit=310%2C310&ssl=1",310,310,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/10\/operation-jacana-reveals-dinodasrat-custom-backdoor.jpg?fit=310%2C310&ssl=1",310,310,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/10\/operation-jacana-reveals-dinodasrat-custom-backdoor.jpg?resize=310%2C310&ssl=1",310,310,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/10\/operation-jacana-reveals-dinodasrat-custom-backdoor.jpg?resize=310%2C310&ssl=1",310,310,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/10\/operation-jacana-reveals-dinodasrat-custom-backdoor.jpg?fit=310%2C310&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/1829","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=1829"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/1829\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/1830"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=1829"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=1829"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=1829"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}