Thứ Hai, Tháng Hai 6, 2023
  • Home
  • Health
  • News
  • Software
  • Tech
  • Travel
  • Gen Z
NATuts
  • Home
  • Health
  • News
  • Software
  • Tech
  • Travel
  • Gen Z
No Result
View All Result
NATuts
  • Home
  • Health
  • News
  • Software
  • Tech
  • Travel
  • Gen Z
No Result
View All Result
NATuts
No Result
View All Result
Home Tech

State-backed hackers use Ransomware as bait for cyber espionage attacks

24 Tháng Sáu, 2022
in Tech
0
State-backed hackers use Ransomware as bait for cyber espionage attacks
585
SHARES
3.2k
VIEWS
Share on FacebookShare on Twitter

Các bài viết liên quan:

How to get travel insurance

Guide on how to get travel insurance with 4 options

24 Tháng Một, 2023
Software Asset Management for Websites: How to Keep Your Sites Running Smoothly

Software Asset Management for Websites: How to Keep Your Sites Running Smoothly

8 Tháng Một, 2023
5 Best Software to Stream Games

5 Best Software to Stream Games

2 Tháng Một, 2023
IBM Bridge To Cloud For Power

IBM Bridge To Cloud For Power- Everything You Should Know

2 Tháng Một, 2023
Top 10 CRM Software For Construction 

Top 10 CRM Software For Construction Enterprises All The Time

31 Tháng Mười Hai, 2022
What Is IBM Software

What Is IBM Software? 4 Business Segments at IBM You Should Know

26 Tháng Mười Hai, 2022

Ransomware as bait for cyber espionage attacks

An Advanced Persistent Threat (APT) Team based in China may be deploying families ransomware short-lived as a decoy to cover up the real operational and tactical goals behind their campaigns.

Active cluster, attributed to an attack group named Bronze starlight by Secureworks, involved in deploying post-intrusion ransomware such as LockFile, Atom Silo, Rook, Night Sky, Pandora, and LockBit 2.0.

Ransomware can distract incident responders from determining the true intentions of threat actors and reduce activity attribution, the researchers said in a new report. malicious to a government-sponsored China threat group,” the researchers said in a new report. “In each case, the ransomware targeted a small number of victims for a relatively short period of time before it stopped working, seemingly permanently.”

Bronze Starlight, in operation since mid-2021, is also tracked by Microsoft under the emerging threat cluster moniker DEV-0401, with the tech giants emphasizing their involvement in all phases of the cycle. ransomware attack from initial access to payload deployment.

Unlike other RaaS groups that buy access from initial access brokers (IABs) to the network, agent-driven attacks are characterized by the use of unpatched vulnerabilities. affects Exchange Server, Zoho ManageEngine ADSelfService Plus, Atlassian Confluence (including newly disclosed vulnerability), and Apache Log4j.

Since August 2021, the team is said to have performed multiple cycles to 6 different ransomware strains such as LockFile (August), Atom Silo (October), Rook (November), Night Sky (December), Pandora (February 2022) and most recently LockBit 2.0 (April).

Furthermore, similarities have been discovered between LockFile and Atom Silo as well as between Rook, Night Sky and Pandora – the latter three stemming from the Babuk ransomware, whose source code was leaked in September 2021 – indicating the work of a common actor.

Ransomware as bait

“Because DEV-0401 maintains and frequently rebrands their own ransomware payloads, they can appear as different groups in payload-oriented reporting and evade anti-virus detection and actions. return them,” Microsoft noted last month.

When it comes to gaining ground in the network, Bronze Starlight is known to rely on techniques like using Cobalt Strike and Windows Management Instrumentation (WMI) to move sideways, although starting this month the team has begun replacing Cobalt Strike with the Sliver frame in their attacks. .

Ransomware as bait

Other observed transactions related to using HUI Loader to launch payloads encode at next stages like PlugX and Cobalt Strike Beacons, the latter are used to distribute ransomware, but not before obtaining privileged Domain Administrator credentials.

“Using the HUI Loader to load the Cobalt Strike Beacon, Cobalt Strike Beacon configuration information, C2 infrastructure, and duplicated code suggest that the same threat group is associated with five related threats,” the researchers explain. this ransomware family”.

It should be pointed out that both HUI Loader and PlugX, along with ShadowPad, are malware historically used by rival Chinese nationalist collectives, suggesting Bronze Starlight’s potential for espionage rather than benefits. immediate monetary benefits.

On top of that, victim patterns spanning different strains of ransomware suggest that the majority of targets are likely to be targeted by Chinese government-sponsored groups focused on long-term intelligence gathering.

The main victims include pharmaceutical companies in Brazil and the US, a US-based media organization with offices in China and Hong Kong, designers and manufacturers of electronic components in Lithuania and Japan, a law firm in the US, and an aviation and defense division of an Indian corporation.

To that end, ransomware operations, besides providing a means to filter data as part of a “name and shame” dual blackmail scheme, offer a dual advantage in that it allowing threat actors to destroy forensic evidence of their malicious activities and act as a distraction from data theft.

“It makes sense for Bronze Starlight to deploy ransomware as a smokescreen rather than for financial gain, with the underlying motive of stealing intellectual property or performing espionage,” the researchers said.

.

Previous Post

Download StitchGenerator for 3ds Max

Next Post

Learn how to best sell a certain product

Megusta

Megusta

Related Posts

5 Best Software to Stream Games

5 Best Software to Stream Games

2 Tháng Một, 2023
Top 10 CRM Software For Construction 

Top 10 CRM Software For Construction Enterprises All The Time

31 Tháng Mười Hai, 2022
Instruction how to use OBS streaming software

Features, settings and how to use OBS streaming software through 9 simple steps

25 Tháng Mười Hai, 2022
What is Trans woman?  What is Transgender Women?

What is Trans woman? What is Transgender Women?

23 Tháng Mười Hai, 2022
Christmas gift: Genuine Windows 10 Pro for only $6.63 and Office 2021 for $14.22

Christmas gift: Genuine Windows 10 Pro for only $6.63 and Office 2021 for $14.22

22 Tháng Mười Hai, 2022
How to get 50 free coins of SkyJoy App to redeem

How to get 50 free coins of SkyJoy App to redeem

21 Tháng Mười Hai, 2022
Load More
Next Post
Learn how to best sell a certain product

Learn how to best sell a certain product

Trả lời Hủy

Email của bạn sẽ không được hiển thị công khai. Các trường bắt buộc được đánh dấu *

Bài viết mới

How to get travel insurance
Đời sống

Guide on how to get travel insurance with 4 options

24 Tháng Một, 2023
Software Asset Management for Websites: How to Keep Your Sites Running Smoothly
Phần mềm

Software Asset Management for Websites: How to Keep Your Sites Running Smoothly

8 Tháng Một, 2023
5 Best Software to Stream Games
Software

5 Best Software to Stream Games

2 Tháng Một, 2023
IBM Bridge To Cloud For Power
Software

IBM Bridge To Cloud For Power- Everything You Should Know

2 Tháng Một, 2023
Top 10 CRM Software For Construction 
Tech

Top 10 CRM Software For Construction Enterprises All The Time

31 Tháng Mười Hai, 2022
What Is IBM Software
Software

What Is IBM Software? 4 Business Segments at IBM You Should Know

26 Tháng Mười Hai, 2022
W3Schools

Ads

Contact: [email protected]

DMCA.com Protection Status

Categories

  • Android
  • Cạm bẫy tâm lí
  • Chưa được phân loại
  • Đồ họa
  • Đời sống
  • Gen Z
  • Health
  • iOS
  • Kĩ năng mềm
  • News
  • Nhà mạng
  • Phần mềm
  • Phần mềm đồ họa
  • Review sách
  • Software
  • Tech
  • Thiết kế ảnh
  • Thiết kế video
  • Thủ thuật
  • Travel
  • Văn hóa Nam Bộ
  • Văn học
  • Window

Browse by Tag

ai là triệu phú android Apple browser Bullet Journal bản thân chai pin Chỉnh ảnh data domain download fshare game game show giả lập màu hosting IKEA ios khuyến mãi kinh doanh kiến thức kiểm tra pin messenger miễn phí mua sắm Máy ảnh mạng network nghệ thuật ngôn ngữ nhà Trần pin laptop quảng cáo tiếng anh trạng thái Trần Thủ Độ tên miền tắt hoạt động từ vựng video viettel window 10 word zalo Đơn giản

Recent News

How to get travel insurance

Guide on how to get travel insurance with 4 options

24 Tháng Một, 2023
Software Asset Management for Websites: How to Keep Your Sites Running Smoothly

Software Asset Management for Websites: How to Keep Your Sites Running Smoothly

8 Tháng Một, 2023

Trang tin nóng hổi - vừa thổi vừa xem

No Result
View All Result
  • Home
  • Health
  • News
  • Software
  • Tech
  • Travel
  • Gen Z

Trang tin nóng hổi - vừa thổi vừa xem