Threat Intelligence

Chinese Xinchuang IT ecosystem subjected to APT32 attack

System hacked warning alert on laptop computer. Cyber attack on computer network, virus, spyware, malware or malicious software. Cyber security and cybercrime concept. System security technology (3)

Vietnamese hacking group APT32, also known as OceanLotus, has leveraged multiple attack vectors to compromise China's Xinchuang IT ecosystem composed of indigenized hardware and software frameworks, according to Cyber Security News.

After achieving initial access through advanced spear-phishing emails with malicious .desktop files, PDF lures, and JAR archives purporting to be legitimate government notices, APT32 proceeds to brute-force internal security servers and subsequently harness suspected zero-day bugs to deliver nefarious update scripts that seek to achieve persistence, a report from threat intelligence analyst Blackorbird showed.

Additional findings revealed the deployment of a malicious EPUB file to execute a critical path traversal and arbitrary file write vulnerability, which allows file system restriction evasion, encrypted payload file injection, and eventual Python-based downloader execution. Such a multi-stage compromise guarantees APT32's clandestine and persistent data exfiltration operations, said Blackorbird.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds