Threat Advisory

EastWind Campaign Targeting Russian Government with CloudSorcerer Malware

Threat: Malicious Campaign
Targeted Region: Russia
Threat Actor Region: China
Targeted Sector: Government & Defense, Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY

An ongoing cyber espionage campaign named "EastWind," attackers have targeted Russian government organizations and IT companies through a series of spear-phishing attacks. The campaign has leveraged tactics, including the use of malicious shortcut files in phishing emails, to infiltrate systems and deploy multiple malware strains, some of which are linked to known advanced persistent threat (APT) groups like APT31 and APT27. This campaign highlights the attackers' evolving tactics, with notable updates to identified malware, including the CloudSorcerer backdoor and the introduction of a new implant, PlugY.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY

An ongoing cyber espionage campaign named "EastWind," attackers have targeted Russian government organizations and IT companies through a series of spear-phishing attacks. The campaign has leveraged tactics, including the use of malicious shortcut files in phishing emails, to infiltrate systems and deploy multiple malware strains, some of which are linked to known advanced persistent threat (APT) groups like APT31 and APT27. This campaign highlights the attackers' evolving tactics, with notable updates to identified malware, including the CloudSorcerer backdoor and the introduction of a new implant, PlugY.[emaillocker id="1283"]

 

The attackers initiated the infection by sending spear-phishing emails containing RAR archives with names such as "initiative group from Chernigov district of Primorsky Krai.rar." Inside these archives were a mix of legitimate and malicious files, including a malicious shortcut that executed a command to install malware from a Dropbox-hosted payload. The CloudSorcerer backdoor, updated to communicate with command servers via LiveJournal and Quora profiles, was among the tools deployed. Additionally, a Trojan known as GrewApacha, linked to APT31, was used to further infiltrate targeted systems. The campaign also introduced the PlugY implant, which features extensive backdoor capabilities and similarities to the DRBControl backdoor associated with APT27.

 

The "EastWind" campaign exemplifies the growing complexity of cyber espionage operations, especially those targeting high-value government and IT sectors. By leveraging a combination of updated and newly developed malware, the attackers demonstrated their ability to adapt and enhance their tactics, making detection and mitigation increasingly challenging. The use of cloud services like Dropbox and social media platforms for command and control further complicates traditional defense mechanisms, underscoring the need for enhanced security measures and vigilance against such advanced threats.

THREAT PROFILE:

Tactic Technique Id Technique
Initial Access T1566 Phishing
Execution T1203 Exploitation for Client Execution
 T1053 Scheduled Task/Job
Collection T1213 Data from Information Repositories
 Command and Control T1071 Application Layer Protocol
T1132 Data Encoding
T1090 Proxy
T1105 Ingress Tool Transfer
Exfiltration T1041 Exfiltration Over C2 Channel

REFERENCES:

The following reports contain further technical details:
https://www.bleepingcomputer.com/news/security/chinese-hacking-groups-target-russian-government-it-firms/

[/emaillocker]
crossmenu