{"id":4084,"date":"2024-06-17T11:56:55","date_gmt":"2024-06-17T16:56:55","guid":{"rendered":"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/china-velvet-ant-apt-multiyear-espionage"},"modified":"2024-06-17T11:56:55","modified_gmt":"2024-06-17T16:56:55","slug":"chinas-velvet-ant-apt-nests-inside-multiyear-espionage-effort","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/06\/17\/chinas-velvet-ant-apt-nests-inside-multiyear-espionage-effort\/","title":{"rendered":"China&#8217;s &#8216;Velvet Ant&#8217; APT Nests Inside Multiyear Espionage Effort"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blta958077cfe54fc2a\/667069a8db6edf382eee11e2\/Velvet_ant%281800%29_RyanPictures_Shutterstock.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/chinas-velvet-ant-apt-nests-inside-multiyear-espionage-effort.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/chinas-velvet-ant-apt-nests-inside-multiyear-espionage-effort.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Researchers have uncovered a quiet multiyear campaign by China&#8217;s Velvet Ant cyber-espionage group to steal critical data from a large company in East Asia.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">What makes the campaign noteworthy is the extent to which the threat actor managed to maintain persistence on the victim&#8217;s network despite repeated eradication attempts.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Researchers from Sygnia who finally booted the threat actor out of the organization&#8217;s environment attributed at least part of Velvet Ant&#8217;s persistence to its success at finding and infecting numerous legacy and unmonitored systems on the target network.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;The threat actor achieved <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/how-nation-state-ddos-attacks-impact-us-all\" rel=\"noopener\">remarkable persistence<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> by establishing and maintaining multiple footholds within the victim company\u2019s environment,&#8221; Sygnia said in a <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.sygnia.co\/blog\/china-nexus-threat-group-velvet-ant\/ \" rel=\"noopener\">report released today<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. &#8220;Even after one foothold was discovered and remediated, the threat actor swiftly pivoted to another, demonstrating agility and adaptability in evading detection.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Sygnia discovered the intrusion at a customer location in late 2023. The security vendor&#8217;s investigation showed the threat actor had likely gained access to the victim environment some three years previously and had remained undetected using multiple persistence and defense evasion mechanisms.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">After identifying what they thought were all the attack sources, vectors and tools, Sygnia researchers initiated measures to eradicate Velvet Ant and associated artifacts from the victim&#8217;s network and systems. But far from being shut out, Velvet Ant quickly resurfaced on the victim network just a few days later, this time via malware the group had previously planted as a Plan B on legacy systems in the target environment.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Sygnia&#8217;s investigation showed the threat actor had installed the highly modular \u2014 and once widely popular \u2014 PlugX remote access Trojans on some legacy Windows Server 2003 systems.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">From those infected systems, Velvet Ant actors moved laterally to newer Windows systems by first tampering with their endpoint detection and remediation (EDR) protections and then installing PlugX on those, too. Once Velvet Ant gained access to targeted systems, the threat actor leveraged a commonly used open source penetration testing and exploit development tool called &#8220;Impacket&#8221; to laterally transfer more malware tools and to execute arbitrary commands on the compromised hosts.&nbsp;For remote command execution, the attackers used Impacket\u2019s wmiexec.py, Windows Management Instrumentation (WMI) tool.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Playing Whack-a-Mole\">Playing Whack-a-Mole<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">As part of the second-round threat eradication process, Sygnia&#8217;s team worked with the victim organization to re-image dozens of compromised system and to decommission many (but not all) legacy systems. In all, Sygnia&#8217;s researchers identified hundreds of indicators of compromise (IoCs).<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">But once again, as with the first time, just a few days later, Sygnia observed fresh signs of Velvet Ant activity in the form of new PlugX infected hosts on the organization&#8217;s network. This time around, however, the researchers could find no signs of the PlugX-infected hosts communicating with an external command-and-communication (C2) server, leaving them to wonder how the threat actor might be communicating with the systems. A subsequent investigation showed Velvet Ant had previously configured a legacy file server to work as an internal C2 server for compromised hosts on the network.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;This meant that the threat actor deployed two versions of PlugX within the network. The first version, configured with an external C2 server, was installed on endpoints with direct internet access, facilitating the exfiltration of sensitive information,&#8221; according to the Sygnia report. &#8220;The second version did not have a C2 configuration, and was deployed exclusively on legacy servers.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">To access the internal C2 server, the threat actors were using backdoors and other malicious binaries they had previously installed on two unmonitored legacy F5 Big-IP load-balancing systems that were not supposed to be operational on the production network. An internal team had deployed the F5 appliances as part of a disaster recovery project that never was completed, and as a result, they were running outdated and vulnerable OS versions.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Their operation was objective-oriented,&#8221; says a researcher spokesperson from Sygnia. &#8220;Therefore, they did not spread throughout the victim&#8217;s entire network but accessed only specific servers and workstations which were required [for] technical reconnaissance&#8221; at the application and network level.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Multiple Strongholds for Cyber Espionage\">Multiple Strongholds for Cyber Espionage<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">As part of its strategy to achieve this goal, the threat actor created several &#8220;strongholds&#8221; in different locations on the target organization&#8217;s network. Some of them were dormant and were utilized only as a fallback in case the activity in another network location was detected. In addition, the threat actively tampered with the installed EDR environment by disabling it and by remotely deleting locally saved logs, the Sygnia researcher says.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Among the several steps that the security vendor recommends organizations take to <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/how-to-protect-against-nation-state-apt-attackers-leveraging-mobile-users\" rel=\"noopener\">mitigate exposure to APT and nation-state actors<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> is decommissioning and replacing legacy systems. State-sponsored actors often use infrequently monitored legacy network devices and systems to hide and to persist.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;This is due to lack of auditing and partial support of EDR products or logging implementations,&#8221; the researcher says. &#8220;Threat actors can be very creative. It is important to make sure that every observed abnormal activity can be explained and verified in a reasonable manner.&#8221;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/china-velvet-ant-apt-multiyear-espionage\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Researchers have uncovered a quiet multiyear campaign by China&#8217;s Velvet<\/p>\n","protected":false},"author":12,"featured_media":4085,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-4084","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/chinas-velvet-ant-apt-nests-inside-multiyear-espionage-effort.jpg?fit=1807%2C1021&ssl=1",1807,1021,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/chinas-velvet-ant-apt-nests-inside-multiyear-espionage-effort.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/chinas-velvet-ant-apt-nests-inside-multiyear-espionage-effort.jpg?fit=300%2C170&ssl=1",300,170,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/chinas-velvet-ant-apt-nests-inside-multiyear-espionage-effort.jpg?fit=640%2C362&ssl=1",640,362,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/chinas-velvet-ant-apt-nests-inside-multiyear-espionage-effort.jpg?fit=640%2C362&ssl=1",640,362,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/chinas-velvet-ant-apt-nests-inside-multiyear-espionage-effort.jpg?fit=1536%2C868&ssl=1",1536,868,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/chinas-velvet-ant-apt-nests-inside-multiyear-espionage-effort.jpg?fit=1807%2C1021&ssl=1",1807,1021,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/chinas-velvet-ant-apt-nests-inside-multiyear-espionage-effort.jpg?fit=1024%2C579&ssl=1",1024,579,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/chinas-velvet-ant-apt-nests-inside-multiyear-espionage-effort.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/chinas-velvet-ant-apt-nests-inside-multiyear-espionage-effort.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/chinas-velvet-ant-apt-nests-inside-multiyear-espionage-effort.jpg?fit=1807%2C1021&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4084","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=4084"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4084\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/4085"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=4084"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=4084"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=4084"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}