Vietnamese hacking group APT32, also known as OceanLotus, has leveraged multiple attack vectors to compromise China's Xinchuang IT ecosystem composed of indigenized hardware and software frameworks, according to Cyber Security News.After achieving initial access through advanced spear-phishing emails with malicious .desktop files, PDF lures, and JAR archives purporting to be legitimate government notices, APT32 proceeds to brute-force internal security servers and subsequently harness suspected zero-day bugs to deliver nefarious update scripts that seek to achieve persistence, a report from threat intelligence analyst Blackorbird showed.Additional findings revealed the deployment of a malicious EPUB file to execute a critical path traversal and arbitrary file write vulnerability, which allows file system restriction evasion, encrypted payload file injection, and eventual Python-based downloader execution. Such a multi-stage compromise guarantees APT32's clandestine and persistent data exfiltration operations, said Blackorbird.
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds
