EXECUTIVE SUMMARY
An ongoing cyber espionage campaign named "EastWind," attackers have targeted Russian government organizations and IT companies through a series of spear-phishing attacks. The campaign has leveraged tactics, including the use of malicious shortcut files in phishing emails, to infiltrate systems and deploy multiple malware strains, some of which are linked to known advanced persistent threat (APT) groups like APT31 and APT27. This campaign highlights the attackers' evolving tactics, with notable updates to identified malware, including the CloudSorcerer backdoor and the introduction of a new implant, PlugY.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY
An ongoing cyber espionage campaign named "EastWind," attackers have targeted Russian government organizations and IT companies through a series of spear-phishing attacks. The campaign has leveraged tactics, including the use of malicious shortcut files in phishing emails, to infiltrate systems and deploy multiple malware strains, some of which are linked to known advanced persistent threat (APT) groups like APT31 and APT27. This campaign highlights the attackers' evolving tactics, with notable updates to identified malware, including the CloudSorcerer backdoor and the introduction of a new implant, PlugY.[emaillocker id="1283"]
The attackers initiated the infection by sending spear-phishing emails containing RAR archives with names such as "initiative group from Chernigov district of Primorsky Krai.rar." Inside these archives were a mix of legitimate and malicious files, including a malicious shortcut that executed a command to install malware from a Dropbox-hosted payload. The CloudSorcerer backdoor, updated to communicate with command servers via LiveJournal and Quora profiles, was among the tools deployed. Additionally, a Trojan known as GrewApacha, linked to APT31, was used to further infiltrate targeted systems. The campaign also introduced the PlugY implant, which features extensive backdoor capabilities and similarities to the DRBControl backdoor associated with APT27.
The "EastWind" campaign exemplifies the growing complexity of cyber espionage operations, especially those targeting high-value government and IT sectors. By leveraging a combination of updated and newly developed malware, the attackers demonstrated their ability to adapt and enhance their tactics, making detection and mitigation increasingly challenging. The use of cloud services like Dropbox and social media platforms for command and control further complicates traditional defense mechanisms, underscoring the need for enhanced security measures and vigilance against such advanced threats.
THREAT PROFILE:
| Tactic | Technique Id | Technique |
| Initial Access | T1566 | Phishing |
| Execution | T1203 | Exploitation for Client Execution |
| T1053 | Scheduled Task/Job | |
| Collection | T1213 | Data from Information Repositories |
| Command and Control | T1071 | Application Layer Protocol |
| T1132 | Data Encoding | |
| T1090 | Proxy | |
| T1105 | Ingress Tool Transfer | |
| Exfiltration | T1041 | Exfiltration Over C2 Channel |
REFERENCES:
The following reports contain further technical details:
https://www.bleepingcomputer.com/news/security/chinese-hacking-groups-target-russian-government-it-firms/