Chinese 'Aoqin Dragon' gang runs undetected ten-year espionage spree
- Reference: 1654837085
- News link: https://www.theregister.co.uk/2022/06/10/aoqin_dragon_china_apt/
- Source link:
Chen has [1]named the group Aoqin Dragon, says its goal is espionage, and that it prefers targets in Australia, Cambodia, Hong Kong, Singapore, and Vietnam.
The gang is fond of attacks that start by inducing users to open poisoned Word documents that install a backdoor – often a threat named Mongall or a modified version of the open source Heyoka project.
[2]
The group's lures have changed over the years. Sometimes its lures are document on regional political topics, while on other occasions the gang has used pornographic content as a lure.
[3]
[4]
The initial incursion sometimes installs a fake removable device that, when clicked, installs malware. Fake anti-virus apps are another tool the group deploys.
Once the gang compromises a machine, it seeks wider network access so the gang can find juicy info.
[5]China-linked Twisted Panda caught spying on Russian defense R&D
[6]APT gang 'Sidewinder' goes on two-year attack spree across Asia
[7]China turns cyber-espionage eyes to Russia as Ukraine invasion grinds on
Chen wrote that he's seen Aoqin Dragon target "government, education, and telecommunication organizations."
"The targeting of Aoqin Dragon closely aligns with the Chinese government's political interests," he wrote, adding "Considering this long-term effort and continuous targeted attacks for the past few years, we assess the threat actor's motives are espionage-oriented."
[8]
China is often credibly accused of using foul means to acquire secrets from private sector and government organizations. Chen thinks Aoqin Dragon will continue its work. "We assess it is likely they will also continue to advance their tradecraft, finding new methods of evading detection and stay longer in their target network," he wrote.
News of the group's activities follows three US government agencies – the NSA, FBI and CISA – jointly announcing that China-backed actors are attacking routers and network attached storage devices to exfiltrate data from carriers and network services providers.
The three agencies stated that the attacks target devices that haven't patched flaws identified between 2017 and 2021. Aoqin Dragon's method of using malicious Microsoft Word documents also relies on users not doing the right thing and either patching or upgrading their apps to safe editions. ®
Get our [9]Tech Resources
[1] https://www.sentinelone.com/labs/aoqin-dragon-newly-discovered-chinese-linked-apt-has-been-quietly-spying-on-organizations-for-10-years/
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YqMWS95rNPW9yosgOqq6GQAAAA4&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YqMWS95rNPW9yosgOqq6GQAAAA4&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YqMWS95rNPW9yosgOqq6GQAAAA4&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://www.theregister.com/2022/05/20/china_twisted_panda/
[6] https://www.theregister.com/2022/05/12/sidewinder_apt_attack_spree/
[7] https://www.theregister.com/2022/04/27/china-bronze-president-malware-russia/
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YqMWS95rNPW9yosgOqq6GQAAAA4&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[9] https://whitepapers.theregister.com/
Re: Once again
Sophisticated scammers seem to look at your activity and personalize the "hook". A friend of mine was travelling in Spain and Portugal recently and was sending me photos through email. I got an email that appeared to be from him with a link that said it was an overlooked photo. The email wasn't the usual form of those from my friend, and the link was to something in Iceland.
Beware.
Re: Once again
How the heck did the scammers get to know what sort of emails you were getting? Your friends PC may already be compromised, or the email service that you or they are using has been cracked.
Re: Once again
Why do they need to know? After all, if you work on X or are involved in the Y department, there are possible generic hooks they can use. Otherwise, they might use the p0rn method, or the possible side interest, they do not care what they send out. Like the telephone scammers or text scammers who pepper the world with a grape shot of pure rubbish, hoping that the right fish will swallow the lure.
Re: Once again
If you have "attachment preview" turned on in your email client, you could be toast without even being aware there's a problem.
Ultimately, it's the now long established blurring of distinctions between:
[a] code and data
[b] local and remote access
plus an insistence on 'convenience' that have enabled this whole disaster.
[quote]...Aoqin Dragon's method of using malicious Microsoft Word documents also relies on users not doing the right thing and either patching or upgrading their apps to safe editions.[/quote]
Alternatively they can rely on Microsoft not actually fixing the vulnerability...
https://www.theregister.com/2022/06/09/symantec-follina-microsoft/
When customers' PCs get compromised I get replies to email messages that I sent five years ago.
They're pretty easy to spot.
Once again
When will people learn that nobody sends you an attachment without even knowing you ?