Summary:
Iron Tiger is an APT group that has been largely focused on cyber espionage for more than a decade. This threat actor is interested in the gambling business and the region of Southeast Asia. Researchers discovered that one of their custom malware families, SysUpdate, had been upgraded to offer additional functionality and support for malware infection on Linux systems. Iron Tiger had likely made the loading logic complex to get around security measures. The rshell malware family runs on Linux and Mac OS, indicating that the threat actor is interested in other operating systems outside Windows.[/subscribe_to_unlock_form]
Summary:
Iron Tiger is an APT group that has been largely focused on cyber espionage for more than a decade. This threat actor is interested in the gambling business and the region of Southeast Asia. Researchers discovered that one of their custom malware families, SysUpdate, had been upgraded to offer additional functionality and support for malware infection on Linux systems. Iron Tiger had likely made the loading logic complex to get around security measures. The rshell malware family runs on Linux and Mac OS, indicating that the threat actor is interested in other operating systems outside Windows.[emaillocker id="1283"]
DNS abuse is being used by the attacker to send and receive data. The new DNS tunnelling capability was utilised by many Linux samples. The attacker loads a file called rc.dll and executes rc.exe, a valid "Microsoft Resource Compiler" signed file. A file called rc.bin is loaded into memory by the malicious rc.dll. The first stage is loaded into memory and decompressed by the rc.bin file, which is an encoded shellcode. The malware then moves the files to a hardcoded folder and runs the transferred executable rc.exe with a single parameter by either creating a registry key or a service. By examining the Linux system's SysUpdate infrastructure, certain ELF binary files related to some C&C servers were discovered.

Infection chain
Different legal executables being utilised, sideloading different DLL names, and those DLLs loading multiple binary file names. Researchers saw a threat actor take use of a sideloading flaw in a Wazuh signed programme. The threat actor utilised the stolen certificate to sign some of its malicious executables and VMProtect to disguise one of them. This threat actor frequently signs dangerous malware with stolen certificates.
Iron Tiger upgrades its tools frequently to include new features and perhaps to make them easier to use on various platforms. This campaign further supports Iron Tiger's frequent use of chat programmes as infection vectors.
Threat Profile:
| Tactics | Technique Id | Technique |
| Resource Development | T1583 | Acquire Infrastructure |
| T1584 | Compromise Infrastructure | |
| Execution | T1204 | User Execution |
| T1569 | System Services | |
| T1059 | Command and Scripting Interpreter | |
| Persistence | T1574 | Hijack Execution Flow |
| Defense Evasion | T1055 | Process Injection |
| T1027 | Obfuscated file or information | |
| Credential Access | T1649 | Steal or Forge Authentication Certificates |
| T1552 | Unsecured Credentials | |
| Discovery | T1082 | System Information Discovery |
| T1083 | File and Directory Discovery | |
| Collection | T1113 | Screen Capture |
| Command and Control | T1573 | Encrypted Channel |
| T1071 | Application Layer Protocol |
References:
The following reports contain further technical details:
https://www.trendmicro.com/en_us/research/23/c/iron-tiger-sysupdate-adds-linux-targeting.html
[/emaillocker]