Enigmatic cyber espionage campaign revives source code from old foe APT1
Summary
A newly discovered cyber espionage campaign targeting South Korea, the U.S. and Canada features malware that reuses old source code associated with the seemingly dormant or disbanded APT1 threat group. The findings raise the possibility that the reputed Chinese threat actor has resumed operations, especially because its source code was never released to the public, according to a McAfee blog post and corresponding research paper published yesterday. The Oceansalt first-stager features a small footprint and is designed to communicate infected systems’ data to a C&C server, as well as execute numerous commands, although at this time it’s unclear for what purpose. “The impact of these operations could be huge: Oceansalt gives the attackers full control of any system they manage to compromise and the network it is connected to. By August, a fourth wave began targeting multiple industries (including financial, health care, agriculture and telecom) in the U.S. and Canada — although McAfee notes that this could be considered a separate campaign altogether.