Threat Advisory

Void Arachne Targets Chinese Users with Malicious VPN and Deepfake Software

Threat: Malicious Campaign
Threat Actor Name: Void Archane
Targeted Region: East Asia
Threat Actor Region: China
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY

Void Arachne, a newly identified threat actor group, has launched a campaign targeting Chinese-speaking users. The group's operation involves the distribution of malicious MSI files that contain legitimate software installers for various AI applications, popular software, and VPNs. These MSI files are distributed through SEO poisoning and shared across several Chinese-language-themed Telegram channels. During the installation process, a Winos backdoor is also installed, posing a significant risk of full system compromise.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY

Void Arachne, a newly identified threat actor group, has launched a campaign targeting Chinese-speaking users. The group's operation involves the distribution of malicious MSI files that contain legitimate software installers for various AI applications, popular software, and VPNs. These MSI files are distributed through SEO poisoning and shared across several Chinese-language-themed Telegram channels. During the installation process, a Winos backdoor is also installed, posing a significant risk of full system compromise.[emaillocker id="1283"]

The malicious MSI files in this campaign are bundled with legitimate software, including deepfake obscenity-generating AI software, voice-and-face-swapping AI software, and Chinese-marketed VPNs such as LetsVPN and QuickVPN. These installers perform multiple tasks without the user's knowledge, including creating scheduled tasks, configuring firewall rules, and establishing port forwarding to the attacker's C&C server. The Winos 4.0 implant, written in C++, is the final payload, equipped with capabilities for remote control, file management, DDoS attacks, webcam control, and more. It communicates with its C&C server using an encryption algorithm and stores plugins in the Windows Registry to perform various malicious activities.

Void Arachne's campaign exploits the public interest in AI technologies and VPNs to distribute malware through SEO poisoning and social media platforms like Telegram. The group's use of AI-generated deepfake obscenity and voice-altering technologies raises concerns about potential misuse, including virtual kidnapping schemes. It is crucial for individuals and organizations to download software only from trusted sources and to be vigilant about the risks associated with MSI files. Implementing comprehensive security solutions can help detect, respond to, and mitigate such threats effectively, improving overall cybersecurity posture and resilience.

THREAT PROFILE:

Tactic Technique Id Technique
Initial Access T1199 Trusted Relationship
Execution T1059 Command and Scripting Interpreter
Defense Evasion T1027 Obfuscated Files or Information
 Discovery T1012 Query Registry
T1082 System Information Discovery
Collection T1005 Data from Local System
T1113 Screen Capture
Exfiltration T1041 Exfiltration Over C2 Channel
 T1048 Exfiltration Over Alternative Protocol
 Impact T1485 Data Destruction

REFERENCES:

The following reports contain further technical details:

https://thehackernews.com/2024/06/void-arachne-uses-deepfakes-and-ai-to.html

[/emaillocker]
crossmenu