HT TECH wants to start sending you push notifications. Click allow to subscribe

Hackers are targeting govt, military sectors in Vietnam and taking control over remote devices

Kaspersky researchers have uncovered an advanced espionage campaign that is targeting the government and military sector in Vietnam.

By: HT TECH
Updated on: Aug 21 2022, 16:32 IST
Dozens of computers have been affected by this campaign, with 80% of them based in Vietnam. Most of these machines belonged to the government or military sector, however, there were other targets as well related to health, diplomacy, education, and politics. There were also occasional targets in Central Asia and in Thailand. (Pixabay)

Earlier in June last year, Kaspersky discovered an advanced cyberespionage campaign that was targeting entities in the government and military sectors in Vietnam. The final aim of these hackers is to put in a remote administration tool that gives them full control over the infected device. Analysis suggested that this attack was being conducted by a group of threat actors related to Cycldek. Cycldek is a Chinese-speaking threat group that’s been active since 2013 and they are known for their sophisticated and advanced methods of cyberattacks.

As Kaspersky revealed in their report, these Chinese-speaking threat actors “often share their techniques and methodologies with each other” which makes it easier for cybercrime researchers like Kaspersky to hunt for advanced persistent threat (APT) activity. And going by this research, Kaspersky has discovered how well-known cyberespionage groups like LuckyMouse, HoneyMyte, and Cycldek work. And that’s exactly why the very moment one of the most well-known tactics of these threat actors, the DLL side-loading triad, was spotted in the attacks targeting government and military entities in Vietnam, it was immediately brought to notice.

You may be interested in

Mobiles Tablets Laptops
7% OFF
Apple iPhone 15 Pro Max
  • Black Titanium
  • 8 GB RAM
  • 256 GB Storage
₹148,900₹159,900
Buy now
28% OFF
Samsung Galaxy S23 Ultra 5G
  • Green
  • 12 GB RAM
  • 256 GB Storage
₹107,999₹149,999
Buy now
Google Pixel 8 Pro
  • Obsidian
  • 12 GB RAM
  • 128 GB Storage
₹106,998
Check details
Apple iPhone 15 Plus
  • Black
  • 6 GB RAM
  • 128 GB Storage
₹87,900
Check details
21% OFF
Acer Swift Go SFG14 41 NX KG3SI 002 Laptop
  • Pure Silver
  • 8 GB RAM
  • 512 GB SSD
₹58,999₹74,999
Buy now
41% OFF
Acer Aspire 5 A515 57G Laptop
  • Gray
  • 16 GB RAM
  • 512 GB SSD
₹52,990₹89,999
Buy now
22% OFF
Acer Aspire 3 A315 24 NX KDESI 004 Laptop
  • Silver
  • 8 GB RAM
  • 512 GB SSD
₹33,499₹42,999
Buy now
40% OFF
Asus VivoBook 15 X515JA BQ322WS Laptop
  • Transparent Silver
  • 8 GB RAM
  • 512 GB SSD
₹31,350₹51,990
Buy now
35% OFF
Xiaomi Pad 6
  • Mist Blue
  • 6 GB RAM
  • 128 GB Storage
₹25,999₹39,999
Buy now
55% OFF
Lenovo Tab M10 5G
  • Abyss Blue
  • 6 GB RAM
  • 128 GB Storage
₹20,999₹47,000
Buy now
32% OFF
Realme Pad 2
  • Imagination Grey
  • 6 GB RAM
  • 128 GB Storage
₹19,718₹28,999
Buy now
Honor Pad X9
  • Gray
  • 4 GB RAM
  • 128 GB Storage
₹14,999
Check details

DLL, or dynamic-link libraries, are pieces of code meant to be used by other programs on a computer. In DLL side-loading, a legitimate file (such as from Microsoft Outlook) is tricked into loading a malicious DLL. This allows attackers to bypass security products. In this recently discovered campaign involving the entities in Vietnam, the DLL side-loading infection chain executes a shellcode that decrypts the final payload, which is a remote access Trojan that’s been named FoundCore by Kaspersky researchers. FoundCore gives attackers full control over the infected device.

Also, the method used to protect this malicious code from analysis is rather interesting. These threat actors are using a method that signals a major advancement in sophistication for attackers in this region. The headers (the destination and source for the code) for the final payload were completely stripped away, and the few that remained contained incoherent values. With this, the attackers are making it significantly more difficult for researchers to reverse engineer the malware for analysis. The components of the infection chain are also tightly coupled, which means that single pieces are difficult, sometimes almost impossible, to analyse in isolation, thereby preventing a full picture of malicious activity.

Kaspersky researchers also discovered that this infection chain was downloading two additional malware. The first is called DropPhone which collects environment information from the victim machine and sends it to DropBox. The second is called CoreLoader which runs code that helps the malware evade detection by security products.

Dozens of computers have been affected by this campaign, with 80% of them based in Vietnam. Most of these machines belonged to the government or military sector, however, there were other targets as well related to health, diplomacy, education, and politics. There were also occasional targets in Central Asia and in Thailand.

Catch all the Latest Tech News, Mobile News, Laptop News, Gaming news, Wearables News , How To News, also keep up with us on ,Twitter, Facebook, , and Instagram. For our latest videos, subscribe to our YouTube channel.

First Published Date: 14 Apr, 12:35 IST
Tags:

Sale

Mobiles Tablets Laptops
7% OFF
Apple iPhone 15 Pro Max
  • Black Titanium
  • 8 GB RAM
  • 256 GB Storage
₹148,900₹159,900
Buy now
13% OFF
Xiaomi 14
  • Matte Black
  • 12 GB RAM
  • 512 GB Storage
₹69,999₹79,999
Buy now
11% OFF
Apple iPhone 15 Plus
  • Black
  • 6 GB RAM
  • 128 GB Storage
₹79,800₹89,900
Buy now
3% OFF
Samsung Galaxy Z Fold5
  • Icy Blue
  • 12 GB RAM
  • 256 GB Storage
₹154,999₹159,999
Buy now
57% OFF
Lenovo Tab M10 5G
  • Abyss Blue
  • 6 GB RAM
  • 128 GB Storage
₹19,999₹47,000
Buy now
38% OFF
Realme Pad 2
  • Imagination Grey
  • 6 GB RAM
  • 128 GB Storage
₹17,999₹28,999
Buy now
20% OFF
Samsung Galaxy Tab S9 5G 256GB
  • Graphite
  • 8 GB RAM
  • 256 GB Storage
₹88,400₹110,998
Buy now
38% OFF
realme Pad 2 WiFi
  • Imagination Grey
  • 6 GB RAM
  • 128 GB Storage
₹17,999₹28,999
Buy now
23% OFF
Infinix INBook X1 Neo XL22 Laptop Intel Celeron Quad Core 8 GB 256 GB SSD Windows 11
  • Blue
  • 4 GB RAM
  • 128 GB SSD
₹22,990₹29,990
Buy now
25% OFF
Asus TUF Gaming F15 FX506HF HN076W Laptop
  • Graphite Black
  • 16 GB RAM
  • 512 GB SSD
₹56,390₹74,990
Buy now
22% OFF
Asus ROG Strix G15 G513QC HN088TS Laptop
  • Black
  • 8 GB RAM
  • 1 TB SSD
₹70,990₹90,990
Buy now
30% OFF
Asus VivoBook S14 OLED S3402ZA KM502WS Laptop
  • Indie Black
  • 16 GB RAM
  • 512 GB SSD
₹64,990₹92,990
Buy now
NEXT ARTICLE BEGINS