Threat Advisory

OPSWAT Driver Flaw Enables BYOVD Technique for Arbitrary Code Execution

Threat: Vulnerability
Targeted Region: Asia, China, Southeast Asia
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Acronis' Threat Research Unit identified a recent campaign targeting individuals and organizations in Cambodia. The analyzed samples employ diverse lure themes suggesting an effort to appeal to a broad range of potential victims, including government notices, public health materials, real estate-related content, and other topics. The campaign employs a multi-stage infection chain including DLL sideloading, decryption of shellcodes hidden in PNG files, process injection, and installation of vulnerable drivers.

The final stage reflectively loads SparkRAT into a legitimate Windows process, providing the operators with remote access and control while concealing execution within a trusted process. The campaign shows operational similarities to SilverFox-associated activity but no shared infrastructure, code reuse, or other actor-specific link was identified. The analyzed campaign uses a multi-stage execution chain with each component handling a specific part of the attack.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Acronis' Threat Research Unit identified a recent campaign targeting individuals and organizations in Cambodia. The analyzed samples employ diverse lure themes suggesting an effort to appeal to a broad range of potential victims, including government notices, public health materials, real estate-related content, and other topics. The campaign employs a multi-stage infection chain including DLL sideloading, decryption of shellcodes hidden in PNG files, process injection, and installation of vulnerable drivers.

The final stage reflectively loads SparkRAT into a legitimate Windows process, providing the operators with remote access and control while concealing execution within a trusted process. The campaign shows operational similarities to SilverFox-associated activity but no shared infrastructure, code reuse, or other actor-specific link was identified. The analyzed campaign uses a multi-stage execution chain with each component handling a specific part of the attack.[emaillocker id="1283"]

An Inno Setup package creates a hidden staging directory, launches a signed Tencent executable, and relies on DLL sideloading to start the malicious loader. The loader then extracts encrypted stages from several PNG-formatted files and moves execution into a malicious executable, a malicious executable, and a malicious executable. Persistence and defense impairment are built into multiple stages.

THREAT PROFILE:

Tactic Technique Id Technique Sub-technique
Initial access T1566.002 Phishing Spearphishing Link
Execution T1059.003 Command and Scripting Interpreter Windows Command Shell
Persistence T1547.001 Boot or Logon Autostart Execution Registry Run Keys / Startup Folder
Defence Evasion T1027.002 Obfuscated Files or Information Software Packing
Defence Evasion T1055 Process Injection -
Collection T1005 Data from Local System -
Command and control T1071.001 Application Layer Protocol Web Protocols
Exfiltration T1041 Exfiltration Over C2 Channel -

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu