{"id":4877,"date":"2024-08-14T14:46:52","date_gmt":"2024-08-14T19:46:52","guid":{"rendered":"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/eastwind-cyber-spy-campaign-chinese-apt-tools"},"modified":"2024-08-14T14:46:52","modified_gmt":"2024-08-14T19:46:52","slug":"eastwind-cyber-spy-campaign-combines-various-chinese-apt-tools","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/08\/14\/eastwind-cyber-spy-campaign-combines-various-chinese-apt-tools\/","title":{"rendered":"&#8216;EastWind&#8217; Cyber-Spy Campaign Combines Various Chinese APT Tools"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt983b9c3102cd2db0\/66bd15f2456402020dbc7b4c\/dragon-Photos_from_Ireland-Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/eastwind-cyber-spy-campaign-combines-various-chinese-apt-tools.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/eastwind-cyber-spy-campaign-combines-various-chinese-apt-tools.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">A likely China-nexus threat actor is using popular cloud services such as Dropbox, GitHub, Quora, and Yandex as command-and-control (C2) servers in a new cyber espionage campaign targeting government organizations in Russia.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Researchers at Kaspersky are tracking the campaign as &#8220;EastWind,&#8221; after uncovering it while investigating devices that had been infected via phishing emails with malicious shortcuts attachments.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Dropbox-Hosted C2 Servers\">Dropbox-Hosted C2 Servers<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Kaspersky&#8217;s analysis showed the malware was communicating with and receiving commands from a C2 server on Dropbox. The researchers also found the attackers using the initial payload to download additional malware associated with two different China-sponsored groups \u2014 APT31 and APT27 \u2014 on infected systems. In addition, the threat actor used the C2 servers to download a newly modified version of &#8216;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/securelist.com\/cloudsorcerer-new-apt-cloud-actor\/113056\/\" rel=\"noopener\">CloudSorcerer,<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8216; a sophisticated cyber espionage tool that Kaspersky spotted a new, eponymously named group using in attacks earlier this year that also targeted Russian government entities.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Kaspersky has perceived the use of tools from different threat actors in the EastWind campaign as a sign of how APT groups often collaborate and share malware tools and knowledge with each other.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;In attacks on government organizations, threat actors often use toolkits that implement a wide variety of techniques and tactics,&#8221; Kaspersky researchers said in a <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/securelist.com\/eastwind-apt-campaign\/113345\/\" rel=\"noopener\">blog post<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> this week. &#8220;In developing these tools, they go to the greatest lengths possible to hide malicious activity in network traffic.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">APT31 is an advanced persistent threat group that US officials have identified as working on behalf of China&#8217;s Ministry of State Security in Wuhan. Earlier this year, the US Department of Justice <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyber-risk\/chinese-state-hackers-slapped-with-us-charges-sanctions\" rel=\"noopener\">indicted seven members of the group<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> for their role in cyber-spy campaigns that victimized thousands of entities globally, over a period spanning 14 years. <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.mandiant.com\/resources\/insights\/apt-groups\" rel=\"noopener\">Mandiant<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, one of several security vendors tracking APT31 has described the threat actor&#8217;s mission as gathering information from rival nations that could be of economic, military, and political benefit to China. The group&#8217;s most frequent targets have included government and financial organizations, aerospace companies and entities in the defense, telecommunication, and high tech sectors.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/chinese-apt-targets-hong-kong-in-supply-chain-attack\" rel=\"noopener\">APT27<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, or Emissary Panda, is another China-linked goal engaged in the theft of intellectual property from organizations in sectors that China perceives as being of vital strategic interest. Like APT31, the group has relied heavily on malware delivered via phishing emails for initial access.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Kaspersky did not tie either group specifically to the new EastWind campaign that it spotted targeting Russian government entities, but pointed out that it had observed the use of both groups&#8217; malware in the attacks.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Tools From Different China-Nexus Actors\">Tools From Different China-Nexus Actors<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Kaspersky has dubbed the APT31 malware that the threat actor behind EastWind is using in its campaign as &#8220;GrewApacha,&#8221; a Trojan that APT31 has been using since at least 2021. The security vendor observed the threat actor behind the EastWind campaign using GrewApacha to collect information about infected systems and to install additional malicious payloads on them. The adversary meanwhile has been using the aforementioned CloudSorcerer \u2014 a backdoor that the attacker executes manually \u2014 to download PlugY, an implant with code that overlaps with APT27.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Kaspersky found the implant communicating with the the Dropbox hosted C2 servers via the TCP and UDP protocols and via named pipes \u2014 a Windows method for inter process communications. &#8220;The set of commands this implant can handle is quite extensive, and implemented commands range from manipulating files and executing shell commands to logging keystrokes and monitoring the screen or the clipboard,&#8221; Kaspersky said.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/eastwind-cyber-spy-campaign-chinese-apt-tools\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A likely China-nexus threat actor is using popular cloud services<\/p>\n","protected":false},"author":12,"featured_media":4878,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-4877","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/eastwind-cyber-spy-campaign-combines-various-chinese-apt-tools-scaled.jpg?fit=2560%2C1440&ssl=1",2560,1440,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/eastwind-cyber-spy-campaign-combines-various-chinese-apt-tools-scaled.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/eastwind-cyber-spy-campaign-combines-various-chinese-apt-tools-scaled.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/eastwind-cyber-spy-campaign-combines-various-chinese-apt-tools-scaled.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/eastwind-cyber-spy-campaign-combines-various-chinese-apt-tools-scaled.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/eastwind-cyber-spy-campaign-combines-various-chinese-apt-tools-scaled.jpg?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/eastwind-cyber-spy-campaign-combines-various-chinese-apt-tools-scaled.jpg?fit=2048%2C1152&ssl=1",2048,1152,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/eastwind-cyber-spy-campaign-combines-various-chinese-apt-tools-scaled.jpg?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/eastwind-cyber-spy-campaign-combines-various-chinese-apt-tools-scaled.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/eastwind-cyber-spy-campaign-combines-various-chinese-apt-tools-scaled.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/eastwind-cyber-spy-campaign-combines-various-chinese-apt-tools-scaled.jpg?fit=2560%2C1440&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4877","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=4877"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4877\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/4878"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=4877"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=4877"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=4877"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}