Threat Intelligence

Russian IT firm subjected to covert Chinese APT compromise

China map outline, flag colors red, yellow glowing. Futuristic circuit board digital technology backdrop. High-tech data streams, innovation, modern design, connectivity global network.

Chinese advanced persistent threat operation Jewelbug, also known as Earth Alux, CL-STA-0049, and REF7707, has targeted a Russian IT service provider in an attack spanning five months after previously breaching organizations across the Asia-Pacific and Latin America, reports The Hacker News.

Initial exploitation of a renamed Microsoft Console Debugger enabled Jewelbug to facilitate clandestine shellcode execution and executable and DLL deployment in the network of the Russian IT firm, according to an analysis from the Symantec Threat Hunter Team.

Such an attack also involved credential dumpping, scheduled task-enabled persistence, and Windows Event Log deletion. Additional findings revealed Jewelbug's exploitation of Microsoft Graph API and various other tools in attacks aimed at a South American government entity and a Taiwanese firm.

"Jewelbug's preference for using cloud services and other legitimate tools in its operations indicates that remaining under the radar and establishing a stealthy and persistent presence on victim networks is of utmost importance to this group," said Symantec researchers.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds