Threat Advisory

A Unique Malicious Maldoc Targeting Chinese-Speaking Users

Threat: Malware
Criticality: High
[subscribe_to_unlock_form]

Summary:

Researcher has discovered a series of maldoc samples indicative of a potential malicious campaign. The attack begins with a Chinese phishing attempt, targeting Chinese-speaking users. The maldoc masquerades as a Curriculum Vitae belonging to a 28-year-old finance professional specialized in software development for banking systems and NCR. The infection chain bears similarities to the tactics used by APT29, a known threat actor. However, there are significant deviations from APT29's typical infection chain, leading experts to believe that this is not the work of APT29.[/subscribe_to_unlock_form]

Summary:

Researcher has discovered a series of maldoc samples indicative of a potential malicious campaign. The attack begins with a Chinese phishing attempt, targeting Chinese-speaking users. The maldoc masquerades as a Curriculum Vitae belonging to a 28-year-old finance professional specialized in software development for banking systems and NCR. The infection chain bears similarities to the tactics used by APT29, a known threat actor. However, there are significant deviations from APT29's typical infection chain, leading experts to believe that this is not the work of APT29.[emaillocker id="1283"]

The malicious file is compressed and labelled with Chinese characters referring to "Sun Jichao - Peking University - Master." Inside the compressed file are a PDF file and a hidden directory. The directory contains a batch file, two hidden .tmp files, and another PDF file. It appears that the threat actors behind this campaign are specifically targeting Chinese-speaking individuals with social engineering techniques. Although resembling APT29's tactics, the unique aspects of the infection chain suggest the involvement of a different threat actor.

Infection flow

In Stage 0, the infection begins with a disguised ".lnk" file named "Sun Jichao - Peking University - Master.pdf," which executes a binary "aaa.bat" located in "__MACOSX\.DOCX" directory. The "aaa.bat" file is obfuscated but is decrypted using a tool called Batch Encryption Decoder. The script performs actions like copying and unhiding files "wda.tmp" and "mbp.tmp" to "C:\ProgramData," renaming them to "OfficeUpdate.exe" and "appvisvsubsystems64.dll," executing the PDF decoy, and then executing "OfficeUpdate.exe" to proceed to Stage 1. Afterward, it deletes the Stage 0 files to leave only the contents in "C:\ProgramData."In Stage 1, the execution continues with the legitimate "WinWord" binary, and a malicious library called "appvisvsubsystems64.dll," which uses DLL Side-Load to load "WinWord." The DLL is written in Go and appears to be a CobaltStrike beacon, serving as a post-exploitation framework.

Comparing the campaign with APT29's tactics, there are similarities, such as Side-Load DLL usage, writing the DLL in Go, and deploying CobaltStrike. However, there are significant differences, including the encrypted ".bat" used in the infection chain, the presence of Chinese characters and a Beijing reference in the decoy, and the storage of files in the "%ProgramData%" folder instead of "%AppData%."Overall, while some elements resemble APT29's techniques, the unique aspects suggest a different threat actor is behind this campaign.

 

Threat Profile:

References:

 

The following reports contain further technical details:

https://lab52.io/blog/beyond-appearances-unknown-actor-using-apt29s-ttp-against-chinese-users/

[/emaillocker]
crossmenu