Threat Advisory

Blackfly: Espionage group targets materials technology

Threat: Malware
Threat Actor Name: APT41
Threat Actor Type: State-Sponsored
Targeted Region: Asia
Alias: G0044/G0096, Wicked Panda, APT41 / Double Dragon, Barium/Brass Typhoon, Blackfly/Grayfly, TAG-28, Bronze Atlas, Earth Baku, Red Kelpie, TG-2633 , REF2924 , Hoodoo , amoeba , SparklingGoblin
Threat Actor Region: China
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

Summary:

The Blackfly espionage group, also known as APT41, Winnti Group, and Bronze Atlas, has continued to launch attacks against targets in Asia. Most recently, the group targeted two Asian conglomerate subsidiaries that are both involved in the materials and composites industry, raising the possibility that the group is trying to steal intellectual property. The Blackfly espionage group, which has a history of attacking targets in Asia, has targeted two companies of an Asian conglomerate that both work in the materials and composites industry, raising the possibility that the group may be attempting to steal intellectual property.[/subscribe_to_unlock_form]

Summary:

The Blackfly espionage group, also known as APT41, Winnti Group, and Bronze Atlas, has continued to launch attacks against targets in Asia. Most recently, the group targeted two Asian conglomerate subsidiaries that are both involved in the materials and composites industry, raising the possibility that the group is trying to steal intellectual property. The Blackfly espionage group, which has a history of attacking targets in Asia, has targeted two companies of an Asian conglomerate that both work in the materials and composites industry, raising the possibility that the group may be attempting to steal intellectual property.[emaillocker id="1283"]

Attackers are using the WINKIT rootkit for launching an attack. The APT41 group's unique rootkit is called WINNKIT. Its function is to act as a kernel-mode agent, interacting with the user-mode agent and intercepting TCP/IP requests by communicating directly to the network card. The Driver Signature Enforcement (DSE) mechanism, which necessitates that drivers be correctly signed with digital signatures in order to be successfully loaded, is circumvented by WINNKIT, which has an expired digital signature. After successfully loading, WINNKIT hooks network traffic and runs using the aforementioned user-mode agent, DEPLOYLOG, which sends specific commands. In order to ensure that Windows Vista or later is installed on the system, the driver verifies the NDIS version before starting its execution. It bypasses more advanced communication methods by communicating with the network card directly using the NDIS (National Disability Insurance Agency) API. After connecting to the network card, the rootkit attempts to open the event, creates the event, and then hooks the device. This device is frequently targeted by a current rootkit, making it rather vulnerable to discovery, so hooking it is somewhat dangerous.

 

Threat Profile:

Tactics Technique Id Technique
Privilege-escalation T1055 Process Injection
Credential-access T1003 OS Credential Dumping
Collection T1113 Screen Capture
Command-and-control T1090 Proxy

 

References:

The following reports contain further technical details:

https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/blackfly-espionage-materials

[/emaillocker]
crossmenu