Threat Advisory

CeranaKeeper: Relentless Cloud-Driven Attacks Target Thailand

Threat: Malicious Campaign
Threat Actor Name: CeranaKeeper
Targeted Region: Thailand, Myanmar, Philippines, Japan, Taiwan
Threat Actor Region: China-aligned
Targeted Sector: Government & Defense
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY

CeranaKeeper, a newly tracked China-aligned advanced persistent threat (APT), has orchestrated a relentless campaign against governmental entities in Thailand since early 2023. Initially, the tools used in these attacks were believed to be associated with Mustang Panda, a known China-affiliated APT, due to similarities in code and techniques. However, analysis revealed organizational and technical distinctions that led to the separation of CeranaKeeper as an independent actor. Leveraging popular cloud and file-sharing services such as Dropbox, OneDrive, and GitHub, CeranaKeeper skillfully integrates legitimate services into its custom malware toolkit, enhancing its ability to bypass security measures. This campaign underscores the threat actor’s alignment with China’s geopolitical interests in Asia, with operations extending to targets in Thailand, Myanmar, the Philippines, Japan, and Taiwan. CeranaKeeper’s unique approach emphasizes data exfiltration at scale, achieved by turning compromised machines into update servers and deploying a range of custom backdoors tailored for massive data extraction.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY

CeranaKeeper, a newly tracked China-aligned advanced persistent threat (APT), has orchestrated a relentless campaign against governmental entities in Thailand since early 2023. Initially, the tools used in these attacks were believed to be associated with Mustang Panda, a known China-affiliated APT, due to similarities in code and techniques. However, analysis revealed organizational and technical distinctions that led to the separation of CeranaKeeper as an independent actor. Leveraging popular cloud and file-sharing services such as Dropbox, OneDrive, and GitHub, CeranaKeeper skillfully integrates legitimate services into its custom malware toolkit, enhancing its ability to bypass security measures. This campaign underscores the threat actor’s alignment with China’s geopolitical interests in Asia, with operations extending to targets in Thailand, Myanmar, the Philippines, Japan, and Taiwan. CeranaKeeper’s unique approach emphasizes data exfiltration at scale, achieved by turning compromised machines into update servers and deploying a range of custom backdoors tailored for massive data extraction.[emaillocker id="1283"]

CeranaKeeper’s sophisticated toolset includes several customized components, each designed for specific stages of infiltration and exfiltration. Notably, the group uses TONESHELL, TONEINS, and PUBLOAD backdoors to maintain persistence and leverage cloud services for discreet command-and-control (C&C) functions. The group developed tools like WavyExfiller, DropboxFlop, and OneDoor to abuse Dropbox, PixelDrain, and OneDrive, demonstrating versatility and adaptability in their operations. WavyExfiller, for instance, is a Python-based exfiltration tool that creates password-protected archives and uploads them to Dropbox. DropboxFlop acts as a Python backdoor, using Dropbox to receive commands, while OneDoor, written in C++, abuses OneDrive’s REST API for encrypted communication and file exfiltration. Additionally, the Python-based BingoShell demonstrates innovative use of GitHub’s pull request functionality for stealthy C&C, showing the group’s ingenuity in deploying unorthodox techniques for covert data exfiltration.

The CeranaKeeper campaign exemplifies a sophisticated strategy for long-term infiltration and sustained data exfiltration against governmental targets. By exploiting popular cloud services that generally evade detection, CeranaKeeper increases its chances of persistence in target networks while minimizing exposure. The group’s persistent updates to its tools and reliance on cloud platforms suggest a strategy designed to bypass traditional security measures and adapt quickly to emerging defenses. As observed through its activity in Thailand and other Asian countries, CeranaKeeper’s objectives align closely with China’s intelligence-gathering goals in the region. By tracking CeranaKeeper independently from Mustang Panda, researchers highlight the importance of detailed attribution, underscoring differences in toolsets and operational practices. This case illustrates the evolving landscape of cyber threats where APTs innovate continuously, underscoring the need for vigilance against evolving TTPs that leverage trusted cloud and online service infrastructures.

THREAT PROFILE:

Tactic Technique Id Technique
Resource Development T1583 Acquire Infrastructure
T1587 Develop Capabilities
T1585 Establish Accounts
Execution T1072 Software Deployment Tools
Persistence T1547 Boot or Logon Autostart Execution
T1574 Hijack Execution Flow
Defense Evasion T1140 Deobfuscate/Decode Files or Information
T1036 Masquerading
Collection T1560 Archive Collected Data
T1005 Data from Local System
T1039 Data from Network Shared Drive
T1074 Data Staged
Command and Control T1071 Application Layer Protocol
T1132 Data Encoding
T1573 Encrypted Channel
T1090 Proxy
T1102 Web Service
Exfiltration T1567 Exfiltration Over Web Service

REFERENCES:

The following reports contain further technical details:
https://www.welivesecurity.com/en/eset-research/separating-bee-panda-ceranakeeper-making-beeline-thailand/

[/emaillocker]
crossmenu