{"id":2435,"date":"2024-01-26T21:00:00","date_gmt":"2024-01-26T21:00:00","guid":{"rendered":"https:\/\/www.darkreading.com\/application-security\/chinese-apt-hides-backdoor-in-software-updates"},"modified":"2024-01-26T21:00:00","modified_gmt":"2024-01-26T21:00:00","slug":"newly-ided-chinese-apt-hides-backdoor-in-software-updates","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/01\/26\/newly-ided-chinese-apt-hides-backdoor-in-software-updates\/","title":{"rendered":"Newly ID&#8217;ed Chinese APT Hides Backdoor in Software Updates"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt2671e837ec835388\/65b400bb3bc06c040a4a7ab1\/WPS_Office-Imaginechina_Limited-Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/newly-ided-chinese-apt-hides-backdoor-in-software-updates.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/newly-ided-chinese-apt-hides-backdoor-in-software-updates.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Since 2018, a previously unknown Chinese threat actor has been using a novel backdoor in adversary-in-the-middle (AitM) cyber-espionage attacks against Chinese and Japanese targets.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Specific victims of <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.welivesecurity.com\/en\/eset-research\/nspx30-sophisticated-aitm-enabled-implant-evolving-since-2005\/\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">the group that ESET has named &#8220;Blackwood&#8221;<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> include a large Chinese manufacturing and trading company, the Chinese office of a Japanese engineering and manufacturing company, individuals in China and Japan, and a Chinese-speaking person connected with a high-profile research university in the UK.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">That Blackwood is only being outed now, more than half a decade since its earliest known activity, can be attributed primarily to two things: its ability to effortlessly <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/china-evasive-panda-hijacks-software-updates-custom-backdoor\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">conceal malware in updates for popular software products<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> like WPS Office, and the malware itself, a highly sophisticated espionage tool called &#8220;NSPX30.&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">Blackwood and NSPX30<\/span><\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The sophistication of NSPX30, meanwhile, can be attributed to nearly two whole decades of research and development.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">According to ESET analysts, NSPX30 follows from a long lineage of backdoors dating back to what they&#8217;ve posthumously named &#8220;Project Wood,&#8221; seemingly first compiled back on Jan. 9, 2005.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">From Project Wood \u2014 which, at various points, was used to target a Hong Kong politician, and then targets in Taiwan, Hong Kong, and southeast China \u2014 came further variants, including 2008&#8217;s DCM (aka &#8220;Dark Specter&#8221;), which survived in malicious campaigns until 2018.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">NSPX30, developed that same year, is the apogee of all cyber espionage that came before it.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The multistaged, multifunctional tool comprised of a dropper, a DLL installer, loaders, orchestrator, and backdoor, with the latter two coming with their own sets of additional, swappable plug-ins.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The name of the game is information theft, whether that be data about the system or network, files and directories, credentials, keystrokes, screengrabs, audio, chats, and contact lists from popular messaging apps \u2014 WeChat, Telegram, Skype, Tencent QQ, etc. \u2014 and more.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Among other talents, NSPX30 can establish a reverse shell, add itself to allowlists in Chinese antivirus tools, and intercept network traffic. This latter capability allows Blackwood to effectively conceal its command-and-control infrastructure, which may have contributed to its long run without detection.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">A Backdoor Hidden in Software Updates<\/span><\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Blackwood&#8217;s greatest trick of all, though, also doubles as its greatest mystery.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">To infect machines with NSPX30, it doesn&#8217;t use any of the typical tricks: phishing, infected webpages, etc. Instead, when certain perfectly legitimate programs attempt to download updates from equally legitimate corporate servers via unencrypted HTTP, Blackwood somehow also injects its backdoor into the mix.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In other words, this isn&#8217;t a SolarWinds-style supply chain breach of a vendor. Instead, ESET speculates that Blackwood may be using network implants. Such implants might be stored in vulnerable edge devices in targeted networks, as is <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/critical-barracuda-esg-zero-day-chinese-apt\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">common among other Chinese APTs<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The software products being used to spread NSPX30 include WPS Office (a popular free alternative to Microsoft and Google&#8217;s suite of office software), the QQ instant messaging service (developed by multimedia giant Tencent), and the Sogou Pinyin input method editor (China&#8217;s market-leading pinyin tool with hundreds of millions of users).<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">So how can organizations defend against this threat? Ensure that your endpoint protection tool blocks NSPX30, and pay attention to malware detections related to legitimate software systems, advises Mathieu Tartare, senior malware researcher at ESET. &#8220;Also, properly monitor and block AitM attacks such as ARP poisoning &#8212; modern switches have features designed to mitigate such attack,&#8221; he says. Disabling IPv6 can help thwart an IPv6 SLAAC attack, he adds.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;A well-segmented network will help as well,s as the AitM will affect only the subnet where it is performed,&#8221; Tartare says.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/application-security\/chinese-apt-hides-backdoor-in-software-updates\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Since 2018, a previously unknown Chinese threat actor has been<\/p>\n","protected":false},"author":12,"featured_media":2436,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-2435","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/newly-ided-chinese-apt-hides-backdoor-in-software-updates-scaled.jpg?fit=2560%2C1707&ssl=1",2560,1707,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/newly-ided-chinese-apt-hides-backdoor-in-software-updates-scaled.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/newly-ided-chinese-apt-hides-backdoor-in-software-updates-scaled.jpg?fit=300%2C200&ssl=1",300,200,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/newly-ided-chinese-apt-hides-backdoor-in-software-updates-scaled.jpg?fit=640%2C427&ssl=1",640,427,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/newly-ided-chinese-apt-hides-backdoor-in-software-updates-scaled.jpg?fit=640%2C427&ssl=1",640,427,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/newly-ided-chinese-apt-hides-backdoor-in-software-updates-scaled.jpg?fit=1536%2C1024&ssl=1",1536,1024,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/newly-ided-chinese-apt-hides-backdoor-in-software-updates-scaled.jpg?fit=2048%2C1365&ssl=1",2048,1365,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/newly-ided-chinese-apt-hides-backdoor-in-software-updates-scaled.jpg?fit=1024%2C683&ssl=1",1024,683,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/newly-ided-chinese-apt-hides-backdoor-in-software-updates-scaled.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/newly-ided-chinese-apt-hides-backdoor-in-software-updates-scaled.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/newly-ided-chinese-apt-hides-backdoor-in-software-updates-scaled.jpg?fit=2560%2C1707&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2435","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=2435"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2435\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/2436"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=2435"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=2435"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=2435"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}