{"id":3712,"date":"2024-05-23T05:00:00","date_gmt":"2024-05-23T10:00:00","guid":{"rendered":"https:\/\/www.darkreading.com\/threat-intelligence\/china-apt-stole-geopolitical-secrets-from-middle-east-africa-and-asia"},"modified":"2024-05-23T05:00:00","modified_gmt":"2024-05-23T10:00:00","slug":"china-apt-stole-geopolitical-secrets-from-middle-east-africa-amp-asia","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/05\/23\/china-apt-stole-geopolitical-secrets-from-middle-east-africa-amp-asia\/","title":{"rendered":"China APT Stole Geopolitical Secrets From Middle East, Africa &amp;amp; Asia"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt1f8a92136c647095\/6601e0608607da040a8ed144\/china_hacker_Rokas_Tenys_Alamy_.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/china-apt-stole-geopolitical-secrets-from-middle-east-africa-amp-asia.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/china-apt-stole-geopolitical-secrets-from-middle-east-africa-amp-asia.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">A Chinese state-aligned threat group has been exfiltrating emails and files from high-level government and military targets across the Middle East, Africa, and Southeast Asia on a daily basis since late 2022.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Operation Diplomatic Specter, a brazen espionage campaign <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/unit42.paloaltonetworks.com\/operation-diplomatic-specter\" rel=\"noopener\">described in a new report<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> by Palo Alto Networks&#8217; Unit 42, targets ministries of foreign affairs, military entities, embassies, and more, in at least seven countries on three continents. Its goal is to obtain classified and otherwise sensitive information about geopolitical conflicts, diplomatic and economic missions, military operations, political meetings and summits, high-ranking politicians and military personnel, and, most of all, embassies and foreign affairs ministries.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The campaign is ongoing, and the attackers have already demonstrated a willingness to continue spying, even after being exposed and booted from compromised networks.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Diplomatic Specter's Tools\">Diplomatic Specter&#8217;s Tools<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Diplomatic Specter attacks begin by targeting Web servers and Microsoft Exchange servers. The attackers exploit these Internet-facing assets using two critical but 3-year-old vulnerabilities \u2014 <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/china-backed-apt-pwns-building-automation-proxylogon\" rel=\"noopener\">ProxyLogon<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, and <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/attackers-now-exploiting-proxyshell-exchange-server-flaws-for-business-email-compromise\" rel=\"noopener\">ProxyShell<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> \u2014 and in-memory VBScript implants.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">With initial access in hand, the group has made use of a total of 16 malicious tools. Some are common open source programs, like the nbtscan scanning tool JuicyPotatoNG, a privilege escalation tool for Windows, and Mimikatz for credential theft. Some are more singular, like Yasso, a relatively new and powerful Chinese pen-testing tool attackers can use for brute forcing, scanning, interactive shell, arbitrary command execution, and more. Never before have threat actors been recorded using Yasso in the wild.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Diplomatic Specter also makes use of some notorious Chinese malware families like <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cloud-security\/plugx-rat-armed-with-time-bomb-leverages-dropbox-in-attack\" rel=\"noopener\">PlugX<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> and <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/threat-intelligence\/cisa-updates-microsoft-exchange-advisory-to-include-china-chopper\" rel=\"noopener\">China Chopper<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. Most notably, it uses Gh0st RAT, both as a means of cementing its foothold in targeted systems and as an inspiration for Diplomatic Specter&#8217;s own custom backdoors.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">First there&#8217;s SweetSpecter, a new variant of <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/threat-intelligence\/new-spookier-gh0st-rat-uzbekistan-south-korea\" rel=\"noopener\">2023&#8217;s reemerged Gh0st RAT<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, largely designed for effective command-and-control (C2) communications. Then there&#8217;s TunnelSpecter, which, in addition to C2 tunneling, fingerprints victim machines and enables arbitrary command execution. TunnelSpecter is hardcoded with the username SUPPORT_388945c0, an open-faced attempt to mimic the default account SUPPORT_388945a0 associated with Windows&#8217; Remote Assistance feature.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The point of all this is to reach a high-value target&#8217;s email inbox, from which Diplomatic Specter will begin silently exfiltrating sensitive emails and files. Sometimes, the group exfiltrates a victim&#8217;s entire inbox. Other times it&#8217;s more specific, using keyword searches to filter matters of interest to the People&#8217;s Republic of China \u2014 military data, telecommunications and energy info, material related to Xi Jinping, Joe Biden, and other political leaders, and so on.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"The Case for Layered Defense\">The Case for Layered Defense<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Defending against Diplomatic Specter begins with blocking its means of initial access, by patching and otherwise hardening Internet-facing assets. After all, its very important victims seem to have fallen to vulnerabilities known to the public for quite a while before any attacks occurred.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">After that, says Assaf Dahan, director of Cortex threat research at Palo Alto Networks, it&#8217;s all about defense in depth.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;We see organizations from all over the world that don&#8217;t practice good cyber hygiene, and they leave huge windows for hackers to walk in,&#8221; he says. &#8220;[You need] all the layers of security that you can get: good network monitoring, detection and response, cloud email solutions.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Once you&#8217;ve put up enough fences, it&#8217;s really making it harder for bad actors to waltz into your network.&#8221;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/threat-intelligence\/china-apt-stole-geopolitical-secrets-from-middle-east-africa-and-asia\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A Chinese state-aligned threat group has been exfiltrating emails and<\/p>\n","protected":false},"author":12,"featured_media":3713,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-3712","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/china-apt-stole-geopolitical-secrets-from-middle-east-africa-amp-asia-scaled.jpg?fit=2560%2C1707&ssl=1",2560,1707,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/china-apt-stole-geopolitical-secrets-from-middle-east-africa-amp-asia-scaled.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/china-apt-stole-geopolitical-secrets-from-middle-east-africa-amp-asia-scaled.jpg?fit=300%2C200&ssl=1",300,200,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/china-apt-stole-geopolitical-secrets-from-middle-east-africa-amp-asia-scaled.jpg?fit=640%2C427&ssl=1",640,427,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/china-apt-stole-geopolitical-secrets-from-middle-east-africa-amp-asia-scaled.jpg?fit=640%2C427&ssl=1",640,427,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/china-apt-stole-geopolitical-secrets-from-middle-east-africa-amp-asia-scaled.jpg?fit=1536%2C1024&ssl=1",1536,1024,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/china-apt-stole-geopolitical-secrets-from-middle-east-africa-amp-asia-scaled.jpg?fit=2048%2C1365&ssl=1",2048,1365,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/china-apt-stole-geopolitical-secrets-from-middle-east-africa-amp-asia-scaled.jpg?fit=1024%2C683&ssl=1",1024,683,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/china-apt-stole-geopolitical-secrets-from-middle-east-africa-amp-asia-scaled.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/china-apt-stole-geopolitical-secrets-from-middle-east-africa-amp-asia-scaled.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/china-apt-stole-geopolitical-secrets-from-middle-east-africa-amp-asia-scaled.jpg?fit=2560%2C1707&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3712","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=3712"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3712\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/3713"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=3712"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=3712"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=3712"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}