Beijing-backed attackers use ransomware as a decoy while they conduct espionage
(2022/06/24)
- Reference: 1656054249
- News link: https://www.theregister.co.uk/2022/06/24/ransomware_as_espionage_distraction/
- Source link:
A state-sponsored Chinese threat actor has used ransomware as a distraction to help it conduct electronic espionage, according to security software vendor Secureworks.
The China-backed group, which Secureworks labels Bronze Starlight, has been active since mid-2021. It uses an HUI loader to install ransomware, such as LockFile, AtomSilo, Rook, Night Sky and Pandora. But cybersecurity firm Secureworks [1]asserts that ransomware is probably just a distraction from the true intent: cyber espionage.
"The ransomware could distract incident responders from identifying the threat actors' true intent and reduce the likelihood of attributing the malicious activity to a government-sponsored Chinese threat group," the company argues.
[2]If you didn't store valuable data, ransomware would become impotent
[3]Chinese 'Aoqin Dragon' gang runs undetected ten-year espionage spree
[4]Beijing-backed baddies target unpatched networking kit to attack telcos
[5]China-linked Twisted Panda caught spying on Russian defense R&D
Secureworks offers its distraction theory after observing Bronze Starlight deploying different ransomware variants for short periods of time – unusual behaviour, as ransomware gangs generally don't change their attacks unless it's necessary to retain their potency. The company also feels that frequent changes to the gang's ransomwares are a deterrent to researchers, who have little reason to analyze code that's not in use.
But the gang has changed its methods at least once, moving from "traditional ransomware" in which infections lead to a demand for payments, to a name-and-shame model in which the gang threatens to expose data if it is not paid.
[6]
"It is possible that the change provided a more plausible means of exfiltrating data. The threat actors may also have decided that the public profile would be more effective as a distraction from their true operational objectives," opined Secureworks.
[7]
Secureworks believes the group has infected 21 victims, 75 percent of which would be of interest to Beijing. Among its haul are pharmaceutical companies, electronic component designers and manufacturers, a US law firm, and an aerospace and defense division of an Indian conglomerate. But there were also some seemingly random victims – like a small interior design company in Europe and two US real estate companies.
Even if none yielded info Beijing wanted, the evil genius of this plan is that the gang may still have made a profit if victims paid the ransom. ®
Get our [8]Tech Resources
[1] https://www.secureworks.com/research/bronze-starlight-ransomware-operations-use-hui-loader
[2] https://www.theregister.com/2022/06/23/the_price_of_data/
[3] https://www.theregister.com/2022/06/10/aoqin_dragon_china_apt/
[4] https://www.theregister.com/2022/06/08/cisa_fbi_nsa_china_attack_advisory/
[5] https://www.theregister.com/2022/05/20/china_twisted_panda/
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YrWLSeOcmiJvRmBkXogrvQAAAEg&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YrWLSeOcmiJvRmBkXogrvQAAAEg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[8] https://whitepapers.theregister.com/
The China-backed group, which Secureworks labels Bronze Starlight, has been active since mid-2021. It uses an HUI loader to install ransomware, such as LockFile, AtomSilo, Rook, Night Sky and Pandora. But cybersecurity firm Secureworks [1]asserts that ransomware is probably just a distraction from the true intent: cyber espionage.
"The ransomware could distract incident responders from identifying the threat actors' true intent and reduce the likelihood of attributing the malicious activity to a government-sponsored Chinese threat group," the company argues.
[2]If you didn't store valuable data, ransomware would become impotent
[3]Chinese 'Aoqin Dragon' gang runs undetected ten-year espionage spree
[4]Beijing-backed baddies target unpatched networking kit to attack telcos
[5]China-linked Twisted Panda caught spying on Russian defense R&D
Secureworks offers its distraction theory after observing Bronze Starlight deploying different ransomware variants for short periods of time – unusual behaviour, as ransomware gangs generally don't change their attacks unless it's necessary to retain their potency. The company also feels that frequent changes to the gang's ransomwares are a deterrent to researchers, who have little reason to analyze code that's not in use.
But the gang has changed its methods at least once, moving from "traditional ransomware" in which infections lead to a demand for payments, to a name-and-shame model in which the gang threatens to expose data if it is not paid.
[6]
"It is possible that the change provided a more plausible means of exfiltrating data. The threat actors may also have decided that the public profile would be more effective as a distraction from their true operational objectives," opined Secureworks.
[7]
Secureworks believes the group has infected 21 victims, 75 percent of which would be of interest to Beijing. Among its haul are pharmaceutical companies, electronic component designers and manufacturers, a US law firm, and an aerospace and defense division of an Indian conglomerate. But there were also some seemingly random victims – like a small interior design company in Europe and two US real estate companies.
Even if none yielded info Beijing wanted, the evil genius of this plan is that the gang may still have made a profit if victims paid the ransom. ®
Get our [8]Tech Resources
[1] https://www.secureworks.com/research/bronze-starlight-ransomware-operations-use-hui-loader
[2] https://www.theregister.com/2022/06/23/the_price_of_data/
[3] https://www.theregister.com/2022/06/10/aoqin_dragon_china_apt/
[4] https://www.theregister.com/2022/06/08/cisa_fbi_nsa_china_attack_advisory/
[5] https://www.theregister.com/2022/05/20/china_twisted_panda/
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YrWLSeOcmiJvRmBkXogrvQAAAEg&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YrWLSeOcmiJvRmBkXogrvQAAAEg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[8] https://whitepapers.theregister.com/
Minor change of tactics?
Mike 137
DDoS used to be (and probably still is) used like this, to distract from data exfiltration.
Diversification
Some interesting points for any business hoping to survive. Diversification needs to apply to both the nature of the business in terms of having a number of profitable lines, but also having a diverse population of customers, or at least those supplying you with cash. Sometimes a low margin, mass product that is sold to huge numbers of different customers can work, if it carries almost all the business overhead. This leave speciality products to carve their own niches while needing to support little mass overhead. A great model for an espionage enterprise, though in such a case the master prize come from the niche product, neat.