Threat Advisory

Melofee: Researchers Uncover New Linux Malware Linked to Chinese APT Groups

Threat: Malware
Threat Actor Name: APT41
Threat Actor Type: State-Sponsored
Targeted Region: Global
Alias: G0044/G0096, Wicked Panda, APT41 / Double Dragon, Barium/Brass Typhoon, Blackfly/Grayfly, TAG-28, Bronze Atlas, Earth Baku, Red Kelpie, TG-2633 , REF2924 , Hoodoo , amoeba , SparklingGoblin
Threat Actor Region: China
Targeted Sector: Government & Defense, Technology & IT
Criticality: High
[subscribe_to_unlock_form]

 

Summary: [/subscribe_to_unlock_form]

 

Summary: [emaillocker id="1283"]

A new type of malware targeted at Linux systems has been connected to an unidentified Chinese state-sponsored hacking group. Researchers discovered three samples of the previously known dangerous software known as Mélofée which was first discovered in early 2022. An open-source project-based kernel-mode rootkit is one of the artifacts that is targeted to be dropped. Since at least 2020 a state-sponsored actor known as Earth Berberoka has primarily targeted gaming websites in China with multi-platform malware like HelloBot and Pupy RAT. Trend Micro reports that the Reptile rootkit has been used to hide some copies of the Python-based Pupy RAT

It has been seen that the installer and an individual binary package are downloaded from a remote server by shell instructions that are used to distribute both the implant and the rootkit. The rootkit only has a few features, primarily installing a hook designed for self-replication. The rootkit and an active server implant module are both extracted by the installer after it receives the binary package as an argument. The capabilities of Mélofée which enable it to communicate with a remote server and obtain instructions that enable it to operate on files, create sockets, run a shell, and issue arbitrary commands, are identical to those of other backdoors. Another implant, AlienReverse, leverages open-source software like EarthWorm and socks proxy and has code in common with Mélofée.

The Mélofée implant family is yet another tool in the armoury of state-sponsored Chinese attackers, which constantly innovate and create new technologies. Mélofée's capabilities are simple, they could allow opponents to carry out covert operations. The fact that these implants were not commonly seen indicates that the attackers are probably only using them on high-value targets.

 

Threat Profile:

Tactic Technique Id Technique
Reconnaissance T1592 Gather Victim Host Information
Resource Development T1583 Acquire Infrastructure
T1587 Develop Capabilities
T1588 Obtain Capabilities
T1608 Stage Capabilities
Execution T1059 Command and Scripting Interpreter
Persistence T1037 Boot or Logon Initialization Scripts
 Defense Evasion T1564 Hide Artifacts
T1562 Impair Defenses
T1070 Indicator Removal
T1599 Network Boundary Bridging
T1027 Obfuscated Files or Information
T1014 Rootkit
T1497 Virtualization/Sandbox Evasion
Discovery T1083 File and Directory Discovery
T1057 Process Discovery
T1082 System Information Discovery
 Command and Control T1071 Application Layer Protocol
T1132 Data Encoding
T1573 Encrypted Channel
T1095 Non-Application Layer Protocol
T1571 Non-Standard Port
T1572 Protocol Tunneling
T1090 Proxy

 

References:

The following reports contain further technical details:

https://thehackernews.com/2023/03/melofee-researchers-uncover-new-linux.html

[/emaillocker]
crossmenu