EXECUTIVE SUMMARY
It outlines the activities of a People's Republic of China, state-sponsored cyber group targeting Australian networks. Also Known as Advanced Persistent Threat (APT) 40, also referred to as Kryptonite Panda, GINGHAM TYPHOON, Leviathan, and Bronze Mohawk, this group conducts operations for the PRC Ministry of State Security. APT40 has targeted organizations in various countries, including Australia and the United States, and their techniques are commonly used by other PRC state-sponsored actors.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY
It outlines the activities of a People's Republic of China, state-sponsored cyber group targeting Australian networks. Also Known as Advanced Persistent Threat (APT) 40, also referred to as Kryptonite Panda, GINGHAM TYPHOON, Leviathan, and Bronze Mohawk, this group conducts operations for the PRC Ministry of State Security. APT40 has targeted organizations in various countries, including Australia and the United States, and their techniques are commonly used by other PRC state-sponsored actors.[emaillocker id="1283"]
APT40 has consistently targeted Australian networks and possesses the capability to rapidly exploit of new vulnerabilities. They regularly conduct reconnaissance against networks, identifying vulnerable, end-of-life, or unmaintained devices for exploitation. APT40 has exploited vulnerabilities such as Log4J CVE-2021-44228, Atlassian Confluence CVE-2021-31207, CVE-2021-26084, and Microsoft Exchange CVE-2021-31207, CVE-2021-34523, CVE-2021-34473. They prioritize obtaining valid credentials for follow-on activities and use web shells for persistence. APT40 has evolved their tradecraft to use compromised small-office/home-office (SOHO) devices as operational infrastructure and last-hop redirectors, blending their activities with legitimate traffic and challenging network defenders.
The group utilized a combination of web shells, compromised credentials, and custom exploits to gain and maintain access to the networks. The compromised devices facilitated host enumeration, privilege escalation, data exfiltration, and lateral movement within the networks. Measures were undertaken, including IP blocking and infrastructure updates, to mitigate the threat and prevent future exploitation it emphasizes the ongoing threat posed by APT40 and the need for vigilant practices to counter their evolving tactics.
THREAT PROFILE:
| Tactic | Technique Id | Technique |
| Reconnaissance | T1594 | Search Victim-Owned Websites |
| Initial Access | T1190 | Exploit Public-Facing Application |
| Execution | T1059 | Command and Scripting Interpreter |
| T1072 | Software Deployment Tools | |
| Persistence | T1505 | Server Software Component |
| Privilege Escalation | T1068 | Exploitation for Privilege Escalation |
| Defense Evasion | T1078 | Valid Accounts |
| Credential Access | T1552 | Unsecured Credentials |
| T1558 | Steal or Forge Kerberos Tickets | |
| T1040 | Network Sniffing | |
| T1539 | Steal Web Session Cookie | |
| T1003 | OS Credential Dumping | |
| T1111 | Multi-Factor Authentication Interception | |
| Discovery | T1082 | System Information Discovery |
| T1046 | Network Service Discovery | |
| Lateral Movement | T1021 | Remote Services |
| Collection | T1213 | Data from Information Repositories |
| T1056 | Input Capture | |
| Command and Control | T1090 | Proxy |
| T1071 | Application Layer Protocol | |
| T1572 | Protocol Tunneling | |
| T1001 | Data Obfuscation | |
| Exfiltration | T1041 | Exfiltration Over C2 Channel |
REFERENCES:
The following reports contain further technical details:
https://www.bleepingcomputer.com/news/security/chinese-apt40-hackers-hijack-soho-routers-to-launch-attacks/