Threat Advisory

Hackers Exploiting Remote Desktop Software Flaws to Deploy PlugX Malware

Threat: Malware
Threat Actor Type:  APT
Targeted Region: Global
Threat Actor Region:  China
Targeted Sector: Finance & Banking
Criticality: High
[subscribe_to_unlock_form]

Summary:

Researchers found that hackers are actively exploiting known vulnerabilities in remote desktop software to deploy the PlugX malware. The PlugX malware is a remote access trojan (RAT) that allows hackers to gain remote access to infected systems. Once installed, it can steal sensitive information, take screenshots, and execute remote commands on the infected system. PlugX uses DLL side-loading technique for installing a malicious DLL alongside a legitimate program in the same path, then exploiting the legitimate software's execution to load the malicious DLL, which then launches the malicious function.[/subscribe_to_unlock_form]

Summary:

Researchers found that hackers are actively exploiting known vulnerabilities in remote desktop software to deploy the PlugX malware. The PlugX malware is a remote access trojan (RAT) that allows hackers to gain remote access to infected systems. Once installed, it can steal sensitive information, take screenshots, and execute remote commands on the infected system. PlugX uses DLL side-loading technique for installing a malicious DLL alongside a legitimate program in the same path, then exploiting the legitimate software's execution to load the malicious DLL, which then launches the malicious function.[emaillocker id="1283"]

Attacks against systems that either have unpatched vulnerabilities or have settings that are not appropriate are being observed by researchers. Subsequently, the researcher confirmed that remote-control programs exploiting the RCE vulnerability are being used to install PlugX malware. The researcher verified that a file called esetservice.exe is created by the PowerShell command run as a result of this vulnerability exploitation. A researcher found that in addition to downloading esetservice.exe, the threat actor also downloaded a file with the name http dll.dll. The "esetservice.exe" program contains a function that loads the "http dll.dll" file in the same directory. And This standard DLL side-loading approach is used by PlugX malware.

PlugX is one of the main backdoor malware used by APT threat groups based in China. New features are being added to it even to this day as it continues to see steady use in attacks. Therefore, users must update their installed software to the latest version to pre-emptively prevent vulnerability exploitations.

 

Threat Profile:

Tactics Technique Id Technique
Execution T1047 Windows Management Instrumentation
T1059 Command and Scripting Interpreter
T1129 Shared Modules
T1569 System Services
Persistence T1574 Hijack Execution Flow
Privilege Escalation T1055 Process Injection
Defense Evasion T1027 Obfuscated Files or Information
T1036 Masquerading
T1055 Process Injection
Credential Access T1056 Input Capture
Discovery T1018 Remote System Discovery
Collection T1056 Input Capture
Command and Control T1071 Application Layer Protocol

 

References:

The following reports contain further technical details:

https://thehackernews.com/2023/03/hackers-exploiting-remote-desktop.html

[/emaillocker]
crossmenu