Threat Advisory

Unveiling the Shadow Force Group's Tactics and Motivations

Threat: Malware
Criticality: High
[subscribe_to_unlock_form]

Summary:

 The Shadow Force group has emerged as a significant threat in recent times, targeting various industries and government organizations in Korea. Initially believed to be a state-sponsored threat group with a focus on information theft, recent findings suggest a shift in their motivations. The Shadow Force group demonstrates a sophisticated level of technical prowess in their operations. Notably, their malware campaigns involve the use of file modification techniques employing "latinfect.exe." While the usage of their previously known backdoor has declined, the group has increasingly employed other backdoors, including the recently identified "Viticdoor." Of significant concern is the discovery of cryptocurrency miners installed alongside the backdoors since December 2021.[/subscribe_to_unlock_form]

Summary:

 The Shadow Force group has emerged as a significant threat in recent times, targeting various industries and government organizations in Korea. Initially believed to be a state-sponsored threat group with a focus on information theft, recent findings suggest a shift in their motivations. The Shadow Force group demonstrates a sophisticated level of technical prowess in their operations. Notably, their malware campaigns involve the use of file modification techniques employing "latinfect.exe." While the usage of their previously known backdoor has declined, the group has increasingly employed other backdoors, including the recently identified "Viticdoor." Of significant concern is the discovery of cryptocurrency miners installed alongside the backdoors since December 2021.[emaillocker id="1283"]

Furthermore, the group has been observed signing their malware files with the certificate of a Korean game developer company since April 2018. This not only highlights their ability to evade detection but also raises concerns about the compromise of legitimate certificates for malicious purposes. Researchers have named the vtcp.exe file as Viticdoor, which has been in use since March 2019. Viticdoor functions as a backdoor, allowing unauthorized file uploads, executions, deletions, and reverse shell executions (cmd.exe). Its disguising as a Microsoft "Dynamic Virtual Channel" file adds to its deceptive nature.

In addition to their infiltration techniques, the Shadow Force group has been associated with the deployment of CoinMiners. Over 30 similar CoinMiners have been discovered within the systems compromised by the group. Notably, these CoinMiners are signed with invalid Microsoft certificates, indicating a deliberate attempt to deceive and avoid detection. However, due to limited availability of configuration files, a comprehensive analysis of their mining activities and associated infrastructure remains challenging.

The Shadow Force group, previously believed to be a state-sponsored threat, is now recognized as a cybercrime organization driven by financial motives. Their utilization of malware, such as Viticdoor, and the installation of CoinMiners in recent attacks point to a shift in objectives. Limited coverage and insufficient information on the group hinder effective response measures. Organizations in targeted sectors must enhance their security posture, including proactive monitoring, patch management, and robust incident response. Collaboration between affected entities and security researchers is vital in mitigating the evolving threat posed by the Shadow Force group.

 Threat Profile:

References:

 The following reports contain further technical details:

https://asec.ahnlab.com/wp-content/uploads/2023/04/ATIP_2023_Shadow-Force-Groups-Viticdoor-and-CoinMiner.pdf

[/emaillocker]
crossmenu