Threat Advisory

Iron Tiger’s SysUpdate Reappears, Adds Linux Targeting

Threat: Malware
Threat Actor Name: APT27
Threat Actor Type: State-Sponsored
Targeted Region: Southeast Asia, Taiwan and Philippines
Alias: G0027, Emissary Panda, APT27/Temp.Hippo/UNC215, LuckyMouse, Iron Taurus, Budworm, Hive0006, Bronze Union, Iron Tiger , Earth Smilodon, Red Phoenix, ATK15, TG-3390 , Group35 , ZipToken , Iron Taurus
Threat Actor Region: China
Targeted Sector: Government & Defense
Criticality: High
[subscribe_to_unlock_form]

Summary:

Iron Tiger is an APT group that has been largely focused on cyber espionage for more than a decade. This threat actor is interested in the gambling business and the region of Southeast Asia. Researchers discovered that one of their custom malware families, SysUpdate, had been upgraded to offer additional functionality and support for malware infection on Linux systems. Iron Tiger had likely made the loading logic complex to get around security measures. The rshell malware family runs on Linux and Mac OS, indicating that the threat actor is interested in other operating systems outside Windows.[/subscribe_to_unlock_form]

Summary:

Iron Tiger is an APT group that has been largely focused on cyber espionage for more than a decade. This threat actor is interested in the gambling business and the region of Southeast Asia. Researchers discovered that one of their custom malware families, SysUpdate, had been upgraded to offer additional functionality and support for malware infection on Linux systems. Iron Tiger had likely made the loading logic complex to get around security measures. The rshell malware family runs on Linux and Mac OS, indicating that the threat actor is interested in other operating systems outside Windows.[emaillocker id="1283"]

DNS abuse is being used by the attacker to send and receive data. The new DNS tunnelling capability was utilised by many Linux samples. The attacker loads a file called rc.dll and executes rc.exe, a valid "Microsoft Resource Compiler" signed file. A file called rc.bin is loaded into memory by the malicious rc.dll. The first stage is loaded into memory and decompressed by the rc.bin file, which is an encoded shellcode. The malware then moves the files to a hardcoded folder and runs the transferred executable rc.exe with a single parameter by either creating a registry key or a service. By examining the Linux system's SysUpdate infrastructure, certain ELF binary files related to some C&C servers were discovered.

 

Infection chain

 

Different legal executables being utilised, sideloading different DLL names, and those DLLs loading multiple binary file names. Researchers saw a threat actor take use of a sideloading flaw in a Wazuh signed programme. The threat actor utilised the stolen certificate to sign some of its malicious executables and VMProtect to disguise one of them. This threat actor frequently signs dangerous malware with stolen certificates.

Iron Tiger upgrades its tools frequently to include new features and perhaps to make them easier to use on various platforms. This campaign further supports Iron Tiger's frequent use of chat programmes as infection vectors.

 

Threat Profile:

Tactics Technique Id Technique
Resource Development T1583 Acquire Infrastructure
T1584 Compromise Infrastructure
Execution T1204 User Execution
T1569 System Services
T1059 Command and Scripting Interpreter
Persistence T1574 Hijack Execution Flow
Defense Evasion T1055 Process Injection
T1027 Obfuscated file or information
Credential Access T1649 Steal or Forge Authentication Certificates
T1552 Unsecured Credentials
Discovery T1082 System Information Discovery
T1083 File and Directory Discovery
Collection T1113 Screen Capture
Command and Control T1573 Encrypted Channel
T1071 Application Layer Protocol

 

References:

The following reports contain further technical details:

https://www.trendmicro.com/en_us/research/23/c/iron-tiger-sysupdate-adds-linux-targeting.html

[/emaillocker]
crossmenu