Skip to content

Cyber Security And Bitcoin Blockchain News

The World

  • South Korea Launches ‘Emergency’ Investigation Into Collapse of LUNA and UST – Regulation Bitcoin News bitcoin news
  • Masterminds Behind South African Bitcoin Ponzi Scheme Told to Pay Back Over $291 Million – Regulation Bitcoin News bitcoin news
  • European Commission Has ‘Serious Doubts’ About Markets in Crypto Assets Draft, Report Reveals – Regulation Bitcoin News bitcoin news
  • Stablecoin Implosion — LUNA and UST Lose Significant Value, Downturn Ripples Across the Crypto Economy – Bitcoin News bitcoin news
  • What Could Trigger Another Decline bitcoin news
  • New RIG Exploit Kit Campaign Infecting Victims’ PCs with RedLine Stealer cyber security news
  • LBank and Adanian Labs Kickstarts a ‘Crypto Accelerator Program’ in Kenya – Press release Bitcoin News bitcoin news
  • India’s Central Bank RBI Warns Crypto Could Lead to Dollarization of Economy – Economics Bitcoin News bitcoin news

Chinese Hackers Targeting Russian Military Personnel with Updated PlugX Malware

Posted on May 2, 2022 By root


PlugX Malware

A China-linked government-sponsored threat actor observed striking European diplomatic entities in March may have been targeting Russian government officials with an updated version of a remote access trojan called PlugX.

Secureworks attributed the attempted intrusions to a threat actor it tracks as Bronze President, and by the wider cybersecurity community under the monikers Mustang Panda, TA416, HoneyMyte, RedDelta, and PKPLUG.

“The war in Ukraine has prompted many countries to deploy their cyber capabilities to gain insight about global events, political machinations, and motivations,” the cybersecurity firm said in a report shared with The Hacker News. “This desire for situational awareness often extends to collecting intelligence from allies and ‘friends.'”

Bronze President, active since at least July 2018, has a history of conducting espionage operations by leveraging custom and publicly available tools to compromise, maintain long-term access, and collect data from targets of interest.

Chief among its tools is PlugX, a Windows backdoor that enables threat actors to execute a variety of commands on infected systems and which has been employed by several Chinese state-sponsored actors over the years.

The latest findings from Secureworks suggest an expansion of the same campaign previously detailed by Proofpoint and ESET last month, which has involved the use of a new variant of PlugX codenamed Hodur, so labeled owing to its overlaps with another version called THOR that emerged on the scene in July 2021.

PlugX Malware

The attack chain commences with a malicious executable named “Blagoveshchensk – Blagoveshchensk Border Detachment.exe” that masquerades as a seemingly legitimate document with a PDF icon, which, when opened, leads to the deployment of an encrypted PlugX payload from a remote server.

“Blagoveshchensk is a Russian city close to the China border and is home to the 56th Blagoveshchenskiy Red Banner Border Guard Detachment,” the researchers said. “This connection suggests that the filename was chosen to target officials or military personnel familiar with the region.”

The fact that Russian officials may have been the target of the March 2022 campaign indicates that the threat actor is evolving its tactics in response to the political situation in Europe and the war in Ukraine.

CyberSecurity

“Targeting Russian-speaking users and European entities suggests that the threat actors have received updated tasking that reflects the changing intelligence collection requirements of the [People’s Republic of China],” the researchers said.

The findings come weeks after another China-based nation-state group known as Nomad Panda (aka RedFoxtrot) was linked with medium confidence to attacks against defense and telecom sectors in South Asia by leveraging yet another version of PlugX dubbed Talisman.

“PlugX has been associated with various Chinese actors in recent years,” Trellix noted last month. “This fact raises the question if the malware’s code base is shared among different Chinese state-backed groups.”

“On the other hand, the alleged leak of the PlugX v1 builder, as reported by Airbus in 2015, indicates that not all occurrences of PlugX are necessarily tied to Chinese actors,” the cybersecurity company added.





TheHackersNews/

cyber security news

Post navigation

Previous Post: U.S. Offers $10 Million Bounty for Information on 6 Russian Military Hackers
Next Post: Google’s New Safety Section Shows What Data Android Apps Collect About Users

Related Posts

  • Microsoft Documents Over 200 Cyberattacks by Russia Against Ukraine cyber security news
  • NIST Releases Updated Guidance for Managing Software Supply Chain Risks cyber security news
  • Hackers Using PrivateLoader PPI Service to Distribute New NetDooka Malware cyber security news
  • NPM Bug Allowed Attackers to Distribute Malware as Legitimate Packages cyber security news
  • Hackers Deploy IceApple Exploitation Framework on Hacked MS Exchange Servers cyber security news
  • Microsoft Warns of “CryWare” Info-Stealing Malware Targeting Crypto Wallets cyber security news

Archives

  • May 2022

Categories

  • bitcoin news
  • cyber security news

Recent Posts

  • Hackers Trick Users with Fake Windows 11 Downloads to Distribute Vidar Malware
  • Cyprus Drafts Crypto Rules, May Introduce Them Before EU Regulations – Regulation Bitcoin News
  • MetaOasis AVAX Hackathon News Report – Press release Bitcoin News
  • Pakistan Can Generate $90 Million Annually if It Introduces a 15% Tax on Crypto Transactions – Emerging Markets Bitcoin News
  • QNAP Urges Users to Update NAS Devices to Prevent Deadbolt Ransomware Attacks

Recent Comments

No comments to show.
  • YOANN․IO Seed Launch on KICK․IO – Press release Bitcoin News bitcoin news
  • AXS Jumps Over 20%, as MATIC Falls to 13-Month Low – Market Updates Bitcoin News bitcoin news
  • Putin Obliges Election Candidates to Report Crypto Holdings Outside Russia – Regulation Bitcoin News bitcoin news
  • Crypto Analyst Predicts 1 Altcoin Will Fall Down Hard – Is It Cardano? bitcoin news
  • Iranian Hackers Leveraging BitLocker and DiskCryptor in Ransomware Attacks cyber security news
  • Crypto Exchange Coinbase Halts Service in India Due to ‘Informal Pressure’ From Central Bank RBI – Exchanges Bitcoin News bitcoin news
  • Bitcoin Price Continues Struggle, But Miners Refuse To Sell bitcoin news
  • Central African Banking Regulator Says Crypto Ban Still Effective – Featured Bitcoin News bitcoin news

Copyright © 2022 Cyber Security And Bitcoin Blockchain News.

Powered by PressBook News Dark theme