Skip to content

Cyber Security And Bitcoin Blockchain News

The World

  • Blockchain Data Indicates $10M Worth Of Ether From The Ronin Exploit In Rotation bitcoin news
  • Mad Money’s Jim Cramer Offers Advice on Cryptocurrency Investing – Featured Bitcoin News bitcoin news
  • BTC Back Above $20,000 as Cryptos Rebound – Market Updates Bitcoin News bitcoin news
  • The Future Is Now Film Shows What Blockchain Leaders Think About Governance bitcoin news
  • Can Bitcoin Bounce Back To $35K? Here’s What Stands In The Way bitcoin news
  • Bitcoin Open Interest Falls As Price Dips Below $31,000 bitcoin news
  • 1k-10k BTC Holders Have Been Buying Recently bitcoin news
  • making sense of the BTC bear market with StormGain bitcoin news

Chinese Hackers Distributing SMS Bomber Tool with Malware Hidden Inside

Posted on June 23, 2022 By root


Free SMS Bomber Tool

A threat cluster with ties to a hacking group called Tropic Trooper has been spotted using a previously undocumented malware coded in Nim language to strike targets as part of a newly discovered campaign.

The novel loader, dubbed Nimbda, is “bundled with a Chinese language greyware ‘SMS Bomber’ tool that is most likely illegally distributed in the Chinese-speaking web,” Israeli cybersecurity company Check Point said in a report.

“Whoever crafted the Nim loader took special care to give it the same executable icon as the SMS Bomber that it drops and executes,” the researchers said. “Therefore the entire bundle works as a trojanized binary.”

SMS Bomber, as the name indicates, allows a user to input a phone number (not their own) so as to flood the victim’s device with messages and potentially render it unusable in what’s a denial-of-service (DoS) attack.

CyberSecurity

The fact that the binary doubles up as SMS Bomber and a backdoor suggests that the attacks are not just aimed at those who are users of the tool — a “rather unorthodox target” — but also highly targeted in nature.

Tropic Trooper, also known by the monikers Earth Centaur, KeyBoy, and Pirate Panda, has a track record of striking targets located in Taiwan, Hong Kong, and the Philippines, primarily focusing on government, healthcare, transportation, and high-tech industries.

Calling the Chinese-speaking collective “notably sophisticated and well-equipped,” Trend Micro last year pointed out the group’s ability to evolve their TTPs to stay under the radar and rely on a broad range of custom tools to compromise its targets.

The latest attack chain documented by Check Point begins with the tampered SMS Bomber tool, the Nimbda loader, which launches an embedded executable, in this case the legitimate SMS bomber payload, while also also injecting a separate piece of shellcode into a notepad.exe process.

This kicks off a three-tier infection process that entails downloading a next-stage binary from an obfuscated IP address specified in a markdown file (“EULA.md”) that’s hosted in an attacker-controlled GitHub or Gitee repository.

CyberSecurity

The retrieved binary is an upgraded version of a trojan named Yahoyah that’s designed to collect information about local wireless networks in the victim machine’s vicinity as well as other system metadata and exfiltrate the details back to a command-and-control (C2) server.

Yahoyah, for its part, also acts as a conduit to fetch the final-stage malware, which is downloaded in the form of an image from the C2 server. The steganographically-encoded payload is a backdoor known as TClient and has been deployed by the group in previous campaigns.

“The observed activity cluster paints a picture of a focused, determined actor with a clear goal in mind,” the researchers concluded.

“Usually, when third-party benign (or benign-appearing) tools are hand-picked to be inserted into an infection chain, they are chosen to be the least conspicuous possible; the choice of an ‘SMS Bomber’ tool for this purpose is unsettling, and tells a whole story the moment one dares to extrapolate a motive and an intended victim.”





TheHackersNews/

cyber security news

Post navigation

Previous Post: Alameda Ventures Bails Out Voyager With $200M & 15K BTC
Next Post: Are Small Cap Crypto Assets Rebounding A Sign Risk Appetite Returning?

Related Posts

  • Over a Dozen Flaws Found in Siemens’ Industrial Network Management System cyber security news
  • Microsoft Warns of “CryWare” Info-Stealing Malware Targeting Crypto Wallets cyber security news
  • Google Releases Android Update to Patch Actively Exploited Vulnerability cyber security news
  • Cloudflare Thwarts Record DDoS Attack Peaking at 15 Million Requests Per Second cyber security news
  • SEC Plans to Hire More Staff in Crypto Enforcement Unit to Fight Frauds cyber security news
  • Cybersecurity Experts Warn of Emerging Threat of “Black Basta” Ransomware cyber security news

Archives

  • July 2022
  • June 2022
  • May 2022

Categories

  • bitcoin news
  • cyber security news

Recent Posts

  • Russian Media Censor Roskomnadzor Blocks Major Crypto News Website – Bitcoin News
  • Jed McCaleb’s Ripple Stash Down to 81 Million — Co-Founder’s XRP Cache Likely to Dry Up This Year – Altcoins Bitcoin News
  • Exploit Forces Crema Finance to Temporarily Suspend Services, $8.7 Million Stolen – Bitcoin News
  • Blockfi CEO Says FTX Has an ‘Option to Acquire’ Crypto Lender at a Price of up to $240M – Bitcoin News
  • Dogecoin (DOGE) Could Use Some Lift

Recent Comments

No comments to show.
  • Coinbase Reveals European Expansion Plan — Seeks Licenses in Spain, Italy, France, Netherlands – Exchanges Bitcoin News bitcoin news
  • Coinbase Reduces the Size of the Firm’s Workforce by 18% – Bitcoin News bitcoin news
  • ‘Mathematics Don’t Account for Human Emotions’ – News Bitcoin News bitcoin news
  • US Economy Is Probably in Recession That Could Last 18 Months — Warns It ‘Will Get Worse’ – Economics Bitcoin News bitcoin news
  • Dubai Creates Committee to Help Cement Its Position as ‘Key City in the Metaverse’ – Metaverse Bitcoin News bitcoin news
  • Veteran Investor Bill Miller Remains Bullish on Bitcoin — Confirms He Has a Lot of BTC – Markets and Prices Bitcoin News bitcoin news
  • The PIP Button Brings New Lifeblood To The Creator Economy With Blockchain Technology bitcoin news
  • SOL Slips Again as ATOM Drops 10% to Start the Weekend – Market Updates Bitcoin News bitcoin news

Copyright © 2022 Cyber Security And Bitcoin Blockchain News.

Powered by PressBook News Dark theme