{"id":4184,"date":"2024-06-26T05:00:00","date_gmt":"2024-06-26T10:00:00","guid":{"rendered":"https:\/\/www.darkreading.com\/ics-ot-security\/china-nexus-group-using-ransomware-to-disguise-cyber-espionage-activities"},"modified":"2024-06-26T05:00:00","modified_gmt":"2024-06-26T10:00:00","slug":"chamelgang-apt-disguises-espionage-activities-with-ransomware","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/06\/26\/chamelgang-apt-disguises-espionage-activities-with-ransomware\/","title":{"rendered":"&#8216;ChamelGang&#8217; APT Disguises Espionage Activities With Ransomware"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt510e7b099be9347b\/667b33de7b5221663048a434\/china_Herr_Loeffler_shutterstock.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/chamelgang-apt-disguises-espionage-activities-with-ransomware.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/chamelgang-apt-disguises-espionage-activities-with-ransomware.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">A likely China-backed advanced persistent threat (APT) group has been systematically using ransomware as a means to disguise its relatively prolific cyberespionage operations for the past three years, at least.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The threat actor, whom researchers at SentinelOne are tracking as ChamelGang (aka CamoFei), has recently targeted critical infrastructure organizations in East Asia and India. &nbsp;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Ransomware as a Distraction\">Ransomware as a Distraction<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Some of ChamelGang&#8217;s victims in that region include an aviation organization in the Indian subcontinent and the All India Institute of Medical Sciences (AIIMS). But the group&#8217;s previous victims include government and private sector organizations\ufffd\u2014including those in <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/china-infiltrates-us-critical-infrastructure-ramp-up-conflict\" rel=\"noopener\">critical infrastructure sectors<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">\u2014in the US, Russia, Taiwan and Japan.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">According to SentinelOne, what makes ChamelGang&#8217;s operations noteworthy is its regular use of a ransomware tool called CatB to distract from and to conceal its cyberespionage focus.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Cyberespionage operations disguised as ransomware activities provide an opportunity for adversarial countries to claim plausible deniability by attributing the actions to independent cybercriminal actors rather than state-sponsored entities,&#8221; the security vendor said in a report shared with Dark Reading. &#8220;Furthermore, misattributing cyberespionage activities as cybercriminal operations can result in strategic repercussions, especially in the context of attacks on government or critical infrastructure organizations.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Significantly, ransomware also gives cyberespionage actors a way to conveniently cover their tracks by destroying artifacts and evidence that would have pointed to their data theft activities, SentineOne said.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">ChamelGang is not the first China-nexus cyberespionage player to use ransomware in this manner. &nbsp;Other examples include <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/apt41-subgroup-plows-through-asia-pacific-utilizing-layered-stealth-tactics\" rel=\"noopener\">APT41<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">\u2014an umbrella group of multiple smaller subgroups\u2014and <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/chinese-apt-ransomware-attacks-cover-ip-theft\" rel=\"noopener\">Bronze Starlight<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, whose victims include organizations in the US and multiple other countries.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Current and historical evidence suggests that cyberespionage clusters use ransomware primarily for disruption or financial gain,&#8221; says Aleksandar Milenkoski, senior threat researcher at SentinelOne&#8217;s SentinelLabs.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In ChamelGang&#8217;s case, the threat actor has typically tended to deploy its ransomware towards the end of its missions where covertness is no longer an operational objective, Milenkoski says. Ransomware can be used as a cover for exfiltrating intelligence-relevant data and deflecting blame, so victims of a ransomware attack should not ignore this aspect when responding to an attack, he says: &#8220;Depending on the potential value of the targeted organization to adversaries from an intelligence perspective, these dimensions of ransomware activities should be considered when assessing the situation.&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Data Espionage &amp; Theft\">Data Espionage &amp; Theft<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">ChamelGang is a threat actor that others such as Positive Technologies and Team5 have previously identified as focused on data theft and cyberespionage. Positive Technologies <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.ptsecurity.com\/ww-en\/analytics\/pt-esc-threat-intelligence\/new-apt-group-chamelgang\/#id1-4\" rel=\"noopener\">reported on the group&#8217;s activities in September 2021<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> following a breach investigation at an energy company where the threat actor disguised its malware and infrastructure to look like legitimate Microsoft, Google, IBM, TrendMicro and McAfee services.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/stillu.cc\/assets\/slides\/2023-08-Unmasking%20CamoFei.pdf\" rel=\"noopener\">Team5<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, which tracks the group as Camo Fei, has assessed the threat actor as having been active since at least 2019 and using a variety of malware tools in its campaigns including Cobalt Strike, DoorMe, IISBeacon, MGDrive and the CatB ransomware tool. Team5&#8217;s research showed the threat actor is primarily focused on targets in the government sector and, to a lesser extent, the healthcare, telecommunications sector, energy, water and high-tech sectors as well.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">SentinelOne itself has assessed ChamelGang&#8217;s current focus on East Asia and the Indian subcontinent as resulting from geopolitical tensions, regional rivalries and a race for technological and economic superiority. The company&#8217;s investigations showed the group deployed CatB ransomware in its 2022 attacks on India&#8217;s AIIMS and against the Brazilian government after using tools such as BeaconLoader and Cobalt Strike during earlier phases of the intrusion.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The interest of threat actors in conducting both cyberespionage and financially motivated activities to actually collect a ransom depends on their objectives when targeting an organization, Milenkosi says. &#8220;Historically, a common case where threat actors have shown no interest in collecting ransom is when deploying ransomware for disruptive purposes,&#8221; he says. &#8220;But we note that interest in ransom payment may represent a cover by itself,&#8221; he adds.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/ics-ot-security\/china-nexus-group-using-ransomware-to-disguise-cyber-espionage-activities\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A likely China-backed advanced persistent threat (APT) group has been<\/p>\n","protected":false},"author":12,"featured_media":4185,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-4184","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/chamelgang-apt-disguises-espionage-activities-with-ransomware-scaled.jpg?fit=2560%2C1920&ssl=1",2560,1920,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/chamelgang-apt-disguises-espionage-activities-with-ransomware-scaled.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/chamelgang-apt-disguises-espionage-activities-with-ransomware-scaled.jpg?fit=300%2C225&ssl=1",300,225,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/chamelgang-apt-disguises-espionage-activities-with-ransomware-scaled.jpg?fit=640%2C480&ssl=1",640,480,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/chamelgang-apt-disguises-espionage-activities-with-ransomware-scaled.jpg?fit=640%2C480&ssl=1",640,480,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/chamelgang-apt-disguises-espionage-activities-with-ransomware-scaled.jpg?fit=1536%2C1152&ssl=1",1536,1152,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/chamelgang-apt-disguises-espionage-activities-with-ransomware-scaled.jpg?fit=2048%2C1536&ssl=1",2048,1536,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/chamelgang-apt-disguises-espionage-activities-with-ransomware-scaled.jpg?fit=1024%2C768&ssl=1",1024,768,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/chamelgang-apt-disguises-espionage-activities-with-ransomware-scaled.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/chamelgang-apt-disguises-espionage-activities-with-ransomware-scaled.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/chamelgang-apt-disguises-espionage-activities-with-ransomware-scaled.jpg?fit=2560%2C1920&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4184","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=4184"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4184\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/4185"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=4184"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=4184"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=4184"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}