Threat Advisory

FlowCloud malware infection via USB Flash Drive

Threat: Malware
Criticality: High
[subscribe_to_unlock_form]

Summary:

FlowCloud, a malware associated with the TA410 attack group, has been active since approximately 2019. Recent attacks utilizing FlowCloud have targeted multiple Japanese organizations within the same industry over several months, indicating a specific focus on Japanese companies. Various versions of FlowCloud have been employed over the years, with a series of attacks occurring between June and August 2022. the recent campaign initiated attacks using USB flash drives. By running an executable file from the USB drive, FlowCloud is deployed and executed.[/subscribe_to_unlock_form]

Summary:

FlowCloud, a malware associated with the TA410 attack group, has been active since approximately 2019. Recent attacks utilizing FlowCloud have targeted multiple Japanese organizations within the same industry over several months, indicating a specific focus on Japanese companies. Various versions of FlowCloud have been employed over the years, with a series of attacks occurring between June and August 2022. the recent campaign initiated attacks using USB flash drives. By running an executable file from the USB drive, FlowCloud is deployed and executed.[emaillocker id="1283"]

Execution Flow

Upon execution, FlowCloud loads an installation configuration into memory, defining embedded resources and file paths. The configuration contains explanatory comments in Simplified Chinese. The backdoor module serves as the malware’s main component and is a decrypted version of responsor.dat. It invokes the startModule export function, reads and decrypts the file, and subsequently deploys the Config in memory. The attacker installs a rootkit to evade detection by deploying a custom driver. This rootkit conceals processes by removing their entries from the process list of an undocumented EPROCESS structure.

FlowCloud contains destination IP addresses directly listed in the malware's configuration. These IP addresses predominantly reside in China, and the communication ports utilized are non-standard, deviating from commonly used ports. Based on these characteristics, such as the infection method via USB flash drives and the appearance of Chinese messages during file execution, it is plausible that the FlowCloud attacks primarily target China. However, conclusive evidence is still lacking according to the researchers.

Threat Profile:

References:

The following reports contain further technical details:

https://insight-jp.nttsecurity.com/post/102ifpu/flowcloud-malware-infection-via-usb-flash-drive

[/emaillocker]
crossmenu