{"id":511,"date":"2020-02-06T21:08:51","date_gmt":"2020-02-06T13:08:51","guid":{"rendered":"https:\/\/www.91tfboys.com\/?p=511"},"modified":"2023-05-30T01:41:36","modified_gmt":"2023-05-29T17:41:36","slug":"%e9%a9%ac%e6%9d%a5%e8%a5%bf%e4%ba%9a-espionage-campaign-targeting-malaysia-government-officials","status":"publish","type":"post","link":"https:\/\/www.91tfboys.com\/?p=511","title":{"rendered":"[\u9a6c\u6765\u897f\u4e9a] Espionage campaign targeting Malaysia government officials"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><strong>1.0 Introduction<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">&nbsp;MyCERT observed an increase in number of artifacts and victims involving a campaign against Malaysian Government officials by a specific threat group. The group motives is believe to be&nbsp; data theft and exfiltration.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>2.0 Impact<\/strong><br>Possible data breach and confidential document exposed for espionage activity.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>3.0 Tactic, Techniques and Procedure (TTP)<\/strong><br>Since the target is utilizing short and targeted campaigns, the targeted campaign&#8217;s TTP is as below:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Reconnaissance:&nbsp;<\/strong>The group has leveraged previously compromised email addresses or impersonation of emails to send spear-phishing emails<\/li>\n\n\n\n<li><strong>Delivery:&nbsp;<\/strong>Send spear-phishing emails with malicious attachments although Google Drive has been observed. This includes pretending to be a journalist, an individual from a trade publication, or someone from a relevant military organization or non-governmental organization (NGO).<\/li>\n\n\n\n<li><strong>Weaponization:&nbsp;<\/strong>Microsoft document with enable macro that extract malicious exe to download loader.<\/li>\n\n\n\n<li><strong>Exploitation:<\/strong>\n<ul class=\"wp-block-list\">\n<li>CVE-2014-6352: Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow remote attackers to execute arbitrary code via a crafted OLE object, as exploited in the wild in October 2014 with a crafted PowerPoint document.<\/li>\n\n\n\n<li>CVE-2017-0199: Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Windows Vista SP2, Windows Server 2008 SP2, Windows 7 SP1, Windows 8.1 allow remote attackers to execute arbitrary code via a crafted document, aka &#8220;Microsoft Office\/WordPad Remote Code Execution Vulnerability w\/Windows API.<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>Installation:<\/strong>\n<ul class=\"wp-block-list\">\n<li>Utilizes unique \u201ciShape\u201d names benign exe, loader dll, and hidden content<\/li>\n\n\n\n<li>Facilitates extraction and execution of main payload in memory<\/li>\n\n\n\n<li>Load order hijacking using benign Windows Defender exe<\/li>\n\n\n\n<li>Contains and encrypted config block and LZMA compressed main payload.<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>Command and Control:&nbsp;<\/strong>Beacon + download and execute stage 2. Beacon that is also encrypted and looks like png.<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"395\" height=\"201\" src=\"https:\/\/www.91tfboys.com\/wp-content\/uploads\/2020\/02\/image.png\" alt=\"\" class=\"wp-image-512\"\/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Figure 7: Sample of Encrypted PNG<\/em><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Actions on Objectives:&nbsp;&nbsp;<\/strong>Data theft and exfiltration. The group&#8217;s operations tend to target government-sponsored projects and take large amounts of information specific to such projects, including proposals, meetings, financial data, shipping information, plans and drawings, and raw data.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>4.0 Affected Products<\/strong><\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>CVE-2014-6352: Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow remote attackers to execute arbitrary code via a crafted OLE object, as exploited in the wild in October 2014 with a crafted PowerPoint document.<\/li>\n\n\n\n<li>CVE-2017-0199: Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Windows Vista SP2, Windows Server 2008 SP2, Windows 7 SP1, Windows 8.1 allow remote attackers to execute arbitrary code via a crafted document, aka &#8220;Microsoft Office\/WordPad Remote Code Execution Vulnerability w\/Windows API.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>5.0 Indicator of Compromised<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-table\"><table><tbody><tr><td><strong>IP Address<\/strong><\/td><td><strong>Domains<\/strong><\/td><td><strong>Hashes<\/strong><\/td><\/tr><tr><td>108[.]61[.]223[.]27<br>139[.]162[.]23[.]6<br>139[.]162[.]44[.]81<br>139[.]59[.]66[.]229<br>149[.]28[.]151[.]144<br>152[.]89[.]161[.]5<br>157[.]230[.]34[.]7<br>159[.]65[.]197[.]248<br>167[.]99[.]72[.]82<br>195[.]12[.]50[.]168<br>207[.]148[.]79[.]152<br>45[.]32[.]123[.]142<br>45[.]77[.]241[.]33<\/td><td>byfleur[.]myftp[.]org<br>dynamics[.]ddnsking[.]com<br>accountsx[.]bounceme[.]net<br>vvavesltd[.]servebeer[.]com<br>capitana[.]onthewifi[.]com<br>kulkarni.bounceme[.]net<br>thestar[.]serveblog[.]net<br>invoke[.]ml<\/td><td>A827d521181462a45a7077ae3c20c9b5<br>F744481A4C4A7C811FFC7DEE3B58B1FF<br>Fe1247780b31bbb9f54a65d3ba17058f<br>ae342bf6b1bd0401a42aae374f961fc6<br>b427c7253451268ca97de38be04bf59a<br>cf94796a07b6082b9e348eef934de97a<br>d81db8c4485f79b4b85226cab4f5b8f9<br>f744481a4c4a7c811ffc7dee3b58b1ff<br>fe1247780b31bbb9f54a65d3ba17058f<br>01b5276fdfda2043980cbce19117aaa0<br>3c43eb86d40ae78037c29bc94b3819b7<br>3ca84fe6cec9bf2e2abac5a8f1e0a8d2<br>3cb38f7574e8ea97db53d3857830fcc4<br>4c47ca6ecf04cfe312eb276022a0c381<br>4c89d5d8016581060d9781433cfb0bb5<br>5fe8dcdfe9e3c4e56e004b2eebf50ab3<br>6e9f0c3f64cd134ad9dfa173e4474399<br>8a133a382499e08811dceadcbe07357e<br>89a81ea2b9ee9dd65d0a82b094099b43<br>6889c7905df000b874bfc2d782512877<br>7233ad2ba31d98ff5dd47db1b5a9fe7c<br>4114857f9bc888122b53ad0b56d03496<br>3ca84fe6cec9bf2e2abac5a8f1e0a8d2<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>6.0 Recommendations<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Follow the best practices adviced in own organization<\/li>\n\n\n\n<li>To patch the vulnerabilities listed above as necessary<\/li>\n\n\n\n<li>To block and set rule in firewall, IDS or IPS of the IOC found<\/li>\n\n\n\n<li>To give awareness on the current TTP to users in the own organization<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Generally, MyCERT advises the users of this devices to be updated with the latest security announcements by the vendor and follow best practice security policies to determine which updates should be applied.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For further enquiries, please contact MyCERT through the following channels:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">E-mail: cyber999[at]cybersecurity.my<br>Phone: 1-300-88-2999 (monitored during business hours)<br>Fax: +603 &#8211; 8008 7000&nbsp;(Office Hours)<br>Mobile: +60 19 2665850 (24&#215;7 call incident reporting)<br>SMS: CYBER999 REPORT EMAIL COMPLAINT to 15888<br>Business Hours: Mon &#8211; Fri 09:00 -18:00 MYT<br>Web:&nbsp;<a href=\"https:\/\/www.mycert.org.my\/\">https:\/\/www.mycert.org.my<\/a><br>Twitter:&nbsp;<a href=\"https:\/\/twitter.com\/mycert\">https:\/\/twitter.com\/mycert<\/a><br>Facebook:&nbsp;<a href=\"https:\/\/www.facebook.com\/mycert.org.my\">https:\/\/www.facebook.com\/mycert.org.my<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>5.0&nbsp; &nbsp; References<\/strong><\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>https:\/\/prezi.com\/view\/jGyAzyy5dTOkDrtwsJi5\/<\/li>\n\n\n\n<li>https:\/\/www.fireeye.com\/blog\/threat-research\/2019\/03\/apt40-examining-a-china-nexus-espionage-actor.html<\/li>\n\n\n\n<li>https:\/\/medium.com\/insomniacs\/on-27-march-2019-we-notice-a-twitter-post-by-clearsky-cyber-security-on-having-a-sample-named-951ec7896d3<\/li>\n\n\n\n<li>https:\/\/wemp.app\/posts\/80ab2b2d-4e0e-4960-94b7-4d452a06fd38?utm_source=latest-posts<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">\uff08\u8f6c\u81ea <a href=\"https:\/\/www.mycert.org.my\/portal\/advisory?id=MA-770.022020\">https:\/\/www.mycert.org.my\/portal\/advisory?id=MA-770.022020<\/a> \uff09<\/p>\n","protected":false},"excerpt":{"rendered":"<p>1.0 Introduction &nbsp;MyCERT observed an increase in n [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":513,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[36,37,38],"class_list":["post-511","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-coding","tag-apt","tag-apt40","tag-38"],"_links":{"self":[{"href":"https:\/\/www.91tfboys.com\/index.php?rest_route=\/wp\/v2\/posts\/511","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.91tfboys.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.91tfboys.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.91tfboys.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.91tfboys.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=511"}],"version-history":[{"count":3,"href":"https:\/\/www.91tfboys.com\/index.php?rest_route=\/wp\/v2\/posts\/511\/revisions"}],"predecessor-version":[{"id":671,"href":"https:\/\/www.91tfboys.com\/index.php?rest_route=\/wp\/v2\/posts\/511\/revisions\/671"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.91tfboys.com\/index.php?rest_route=\/wp\/v2\/media\/513"}],"wp:attachment":[{"href":"https:\/\/www.91tfboys.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=511"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.91tfboys.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=511"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.91tfboys.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=511"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}