Threat Advisory

Chinese APT 40 Uses SOHO Routers for Cyberespionage and Targets Vulnerabilities

Threat: Malware
Threat Actor Name: APT40
Threat Actor Type: State-Sponsored
Targeted Region: Australia & U.S.
Alias: G0065, Kryptonite Panda, Temp.Periscope/Temp.Jumper/APT40, Gadolinium/Gingham Typhoon, TA423, Pickleworm, ITG09, Bronze Mohawk, Red Ladon, ATK29, Flaccid Rose , Nanhaishu , Mudcarp , ISLANDDREAMS , Leviathan
Threat Actor Region: China
Targeted Sector: Technology & IT, Government & Defense
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY

It outlines the activities of a People's Republic of China, state-sponsored cyber group targeting Australian networks. Also Known as Advanced Persistent Threat (APT) 40, also referred to as Kryptonite Panda, GINGHAM TYPHOON, Leviathan, and Bronze Mohawk, this group conducts operations for the PRC Ministry of State Security. APT40 has targeted organizations in various countries, including Australia and the United States, and their techniques are commonly used by other PRC state-sponsored actors.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY

It outlines the activities of a People's Republic of China, state-sponsored cyber group targeting Australian networks. Also Known as Advanced Persistent Threat (APT) 40, also referred to as Kryptonite Panda, GINGHAM TYPHOON, Leviathan, and Bronze Mohawk, this group conducts operations for the PRC Ministry of State Security. APT40 has targeted organizations in various countries, including Australia and the United States, and their techniques are commonly used by other PRC state-sponsored actors.[emaillocker id="1283"]

 

APT40 has consistently targeted Australian networks and possesses the capability to rapidly exploit of new vulnerabilities. They regularly conduct reconnaissance against networks, identifying vulnerable, end-of-life, or unmaintained devices for exploitation. APT40 has exploited vulnerabilities such as Log4J CVE-2021-44228, Atlassian Confluence CVE-2021-31207, CVE-2021-26084, and Microsoft Exchange CVE-2021-31207, CVE-2021-34523, CVE-2021-34473. They prioritize obtaining valid credentials for follow-on activities and use web shells for persistence. APT40 has evolved their tradecraft to use compromised small-office/home-office (SOHO) devices as operational infrastructure and last-hop redirectors, blending their activities with legitimate traffic and challenging network defenders.

 

The group utilized a combination of web shells, compromised credentials, and custom exploits to gain and maintain access to the networks. The compromised devices facilitated host enumeration, privilege escalation, data exfiltration, and lateral movement within the networks. Measures were undertaken, including IP blocking and infrastructure updates, to mitigate the threat and prevent future exploitation it emphasizes the ongoing threat posed by APT40 and the need for vigilant practices to counter their evolving tactics.

THREAT PROFILE:

Tactic Technique Id Technique
Reconnaissance T1594 Search Victim-Owned Websites
 Initial Access T1190 Exploit Public-Facing Application
 Execution T1059 Command and Scripting Interpreter
 T1072 Software Deployment Tools
Persistence  T1505 Server Software Component
Privilege Escalation T1068 Exploitation for Privilege Escalation
Defense Evasion T1078 Valid Accounts
Credential Access T1552 Unsecured Credentials
T1558 Steal or Forge Kerberos Tickets
T1040 Network Sniffing
T1539 Steal Web Session Cookie
T1003 OS Credential Dumping
T1111 Multi-Factor Authentication Interception
Discovery  T1082 System Information Discovery
T1046 Network Service Discovery
Lateral Movement T1021 Remote Services
Collection  T1213 Data from Information Repositories
 T1056 Input Capture
Command and Control T1090 Proxy
T1071 Application Layer Protocol
T1572 Protocol Tunneling
T1001 Data Obfuscation
 Exfiltration T1041 Exfiltration Over C2 Channel

REFERENCES:

The following reports contain further technical details:
https://www.bleepingcomputer.com/news/security/chinese-apt40-hackers-hijack-soho-routers-to-launch-attacks/

[/emaillocker]
crossmenu