Skip to content

Cyber Security And Bitcoin Blockchain News

The World

  • SEC Chair Gensler Affirms Bitcoin Is a Commodity — ‘That’s the Only One I’m Going to Say’ – Regulation Bitcoin News bitcoin news
  • Atlassian Releases Patch for Confluence Zero-Day Flaw Exploited in the Wild cyber security news
  • New York Bill That Aims to Establish a Bitcoin Mining Moratorium Awaits Governor Hochul’s Signature – Mining Bitcoin News bitcoin news
  • Billionaire Ricardo Salinas Fires Back At Warren Buffett’s Bitcoin Slander bitcoin news
  • Jed McCaleb’s Ripple Stash Down to 81 Million — Co-Founder’s XRP Cache Likely to Dry Up This Year – Altcoins Bitcoin News bitcoin news
  • SEC, State Regulators Probe Crypto Lender Celsius Over Accounts Freeze – Regulation Bitcoin News bitcoin news
  • Thousands of WordPress Sites Hacked to Redirect Visitors to Scam Sites cyber security news
  • Co-founder of Argentinian Tech Giant Globant Thinks Companies Should Take Metaverse, NFTs, and Crypto Seriously – Bitcoin News bitcoin news

Chinese LuoYu Hackers Using Man-on-the-Side Attacks to Deploy WinDealer Backdoor

Posted on June 3, 2022 By root


WinDealer Backdoor

An “extremely sophisticated” Chinese-speaking advanced persistent threat (APT) actor dubbed LuoYu has been observed using a malicious Windows tool called WinDealer that’s delivered by means of man-on-the-side attacks.

“This groundbreaking development allows the actor to modify network traffic in-transit to insert malicious payloads,” Russian cybersecurity company Kaspersky said in a new report. “Such attacks are especially dangerous and devastating because they do not require any interaction with the target to lead to a successful infection.”

Known to be active since 2008, organizations targeted by LuoYu are predominantly foreign diplomatic organizations established in China and members of the academic community as well as financial, defense, logistics, and telecommunications companies.

CyberSecurity

LuoYu’s use of WinDealer was first documented by Taiwanese cybersecurity firm TeamT5 at the Japan Security Analyst Conference (JSAC) in January 2021. Subsequent attack campaigns have used the malware to target Japanese entities, with isolated infections reported in Austria, Germany, India, Russia, and the U.S.

Other tools that are part of the adversary’s malware arsenal include PlugX and its successor ShadowPad, both of which have been used by a variety of Chinese threat actors to enable their strategic objectives. Additionally, the actor is known to target Linux, macOS, and Android devices.

WinDealer, for its part, has been delivered in the past via websites that act as watering holes and in the form of trojanized applications masquerading as instant messaging and video hosting services like Tencent QQ and Youku.

But the infection vector has since been traded for another distribution method that makes use of the automatic update mechanism of select legitimate applications to serve a compromised version of the executable on “rare occasions.”

WinDealer, a modular malware platform at its core, comes with all the usual bells and whistles associated with a backdoor, allowing it to hoover sensitive information, capture screenshots, and execute arbitrary commands.

But where it also stands apart is its use of an IP-generation algorithm to select a command-and-control (C2) server to connect to at random from a pool of 48,000 IP addresses.

“The only way to explain these seemingly impossible network behaviors is by assuming the existence of a man-on-the-side attacker who is able to intercept all network traffic and even modify it if needed,” the company said.

CyberSecurity

A man-on-the-side attack, similar to a man-in-the-middle attack, enables a rogue interloper to read and inject arbitrary messages into a communications channel, but not modify or delete messages sent by other parties.

Such intrusions typically bank on strategically timing their messages such that the malicious reply containing the attacker-supplied data is sent in response to a victim’s request for a web resource before the actual response from the server.

The fact that the threat actor is able to control such a massive range of IP addresses could also explain the hijacking of the update mechanism associated with genuine apps to deliver the WinDealer payload, Kaspersky pointed out.

“Man-on-the-side-attacks are extremely destructive as the only condition needed to attack a device is for it to be connected to the internet,” security researcher Suguru Ishimaru said.

“No matter how the attack has been carried out, the only way for potential victims to defend themselves is to remain extremely vigilant and have robust security procedures, such as regular antivirus scans, analysis of outbound network traffic, and extensive logging to detect anomalies.”





TheHackersNews/

cyber security news

Post navigation

Previous Post: Report Reveals Terra Holders Liquidated Their Holding When Crash Started
Next Post: GitLab Issues Security Patch for Critical Account Takeover Vulnerability

Related Posts

  • Experts Sound Alarm on DCRat Backdoor Being Sold on Russian Hacking Forums cyber security news
  • Researchers Disclose 10-Year-Old Vulnerabilities in Avast and AVG Antivirus cyber security news
  • Researchers Find New Malware Attacks Targeting Russian Government Entities cyber security news
  • New Saitama backdoor Targeted Official from Jordan’s Foreign Ministry cyber security news
  • Even the Most Advanced Threats Rely on Unpatched Systems cyber security news
  • Google’s New Safety Section Shows What Data Android Apps Collect About Users cyber security news

Archives

  • July 2022
  • June 2022
  • May 2022

Categories

  • bitcoin news
  • cyber security news

Recent Posts

  • Cumberland Says Financially Burdened Crypto Firms Are ‘Hanging Over the Market Like a Cloud’ – Bitcoin News
  • Worst Quarterly Bitcoin Crash In A Decade Closes Above Key Support
  • Bitmain Launches 2,400 Megahash E9 Ethereum Miner Ahead of The Merge – Mining Bitcoin News
  • How This Company Lost 99% Of Its Clients Funds Shorting LUNA
  • NIST Announces First Four Quantum-Resistant Cryptographic Algorithms

Recent Comments

No comments to show.
  • Report – Taxes Bitcoin News bitcoin news
  • Recession Is Inevitable and Crypto Is Here to Stay – Bitcoin News bitcoin news
  • Luna Foundation Acquires $1.4 Billion in Bitcoin, Decentralized Reserve Stash Rises to 80,394 BTC – Bitcoin News bitcoin news
  • Microsoft Warns of Cryptomining Malware Campaign Targeting Linux Servers cyber security news
  • Rich Dad Poor Dad’s Robert Kiyosaki Thinks Bitcoin Could Bottom Out at $9K — Reveals Why He Remains Bullish – Markets and Prices Bitcoin News bitcoin news
  • Cardano (ADA) Moved Upwards After Consolidation, What To Expect Next? bitcoin news
  • How is SAI.TECH, a recently listed Bitcoin mining operator, driving towards carbon neutrality? bitcoin news
  • LUNA2 Recovers 70% In Nine Days From Historic Lows bitcoin news

Copyright © 2022 Cyber Security And Bitcoin Blockchain News.

Powered by PressBook News Dark theme