Chinese APT abuses MSC files with GrimResource vulnerability

General News

Summary

has been monitoring different threat actors abusing MSC files The first APT group to use .MSC files in their attacks was #Kimsuky in April 2024, as reported by company In May 2024, the use of this technique was also observed by the APT group known as #MustangPanda, which carries the #PlugX malware as reported by In June 2024, the abuse of .MSC files was detected with the vulnerability called #GrimResource as reported by continued to monitor the situation in the following months, identifying new malware campaigns carried out by an unknown cyber-actor that is most likely of Chinese origin to target Southeast Asia Below is the timeline of the monitored attacks The first campaign we analyzed is that of August 2, 2024 . ]com/2472dca8c48ab987e632e66caabf86502bf3.xml.The 64-bit shellcode is similar to the one seen on August 2nd, the command and control server in this case isThe post used in this case is:, slightly different than the August 2 campaign.Again the shellcode downloaded the Marte Beacon with Cobalt Strike, which turned out to be the same version seen in the August 2 campaign..On August 20, 2024, the file "" was uploaded to Virus Total.The campaign targets Vietnam, translating the file name from Vietnamese would be "Instructions and requirements for inspection and supervision of the activities of each unit in 2024The MSC file is similar to those seen in previous campaigns, the ONCESVC.EXE file is replaced with MUSICV.EXE.The configuration file is the same as seen in the August 15 campaign, the same 64-bit shellcode is downloaded and the same Marte Beacon with Cobalt Strike.Interesting is the decoy displayed on theme "":On August 23, 2024, the file "" was uploaded to Virus Total.The campaign may be targeting China, as the file name translated from Chinese would be "Internal Video Evidence of Corruption of Deputy Director Zhang Qing of Guizhou TV Station.msc".The MSC file is similar to the one seen in the previous campaign on August 20, where the MUSICV.EXE program is used.During the analysis, it was not possible to download the malicious DLL from the link https://speedshare.oss-cn-hongkong.aliyuncs[.]com/af7ffc2a629a1c258336fde8a1f71e0a.json. ]com and port 443.The following decoy was used in the April 27 campaign: The cybercriminal probably needed to hit a target with a Linux OS. The campaigns appear to primarily target government agencies and critical infrastructure in Southeast Asia. With particular focus on the following countries: Philippines, Vietnam, and Taiwan.From August 2nd onwards, the threat actor inserted a new module into its infection chain containing a 64-bit shellcode which then leads to the execution of a third stage with the Marte and Cobalt Strike beacons.The modus operandi of the cyber actor reflects the techniques of APTs of Chinese origin, it has been noted that the group is operational from Monday to Friday in hours compatible with Chinese ones.Although it was not possible to make a precise attribution, it could be a subgroup ofAuthors: Ing.

Classifications

industries
No industries detected
applications
Security

AskAI Classifications

Labels
Cyber Security Software Antivirus Software Endpoint Security

Linked Companies

TG Soft
up to $1M