{"id":30218,"date":"2017-11-23T11:39:38","date_gmt":"2017-11-23T03:39:38","guid":{"rendered":"http:\/\/www.upgrademag.com\/web\/?p=30218"},"modified":"2017-11-23T11:47:48","modified_gmt":"2017-11-23T03:47:48","slug":"arly-half-of-advanced-targeted-attacks-in-q3-came-from-chinese-speaking-cybercriminals","status":"publish","type":"post","link":"http:\/\/www.upgrademag.com\/web\/2017\/11\/23\/arly-half-of-advanced-targeted-attacks-in-q3-came-from-chinese-speaking-cybercriminals\/","title":{"rendered":"Nearly half of advanced targeted attacks in Q3 came from Chinese-speaking cybercriminals"},"content":{"rendered":"<p><strong>The third quarter of 2017 clearly demonstrated that Chinese-speaking actors have not \u201cdisappeared\u201d and are still very much active, conducting cyber-espionage campaigns against a wide range of countries and industry verticals.\u00a0<\/strong><\/p>\n<p><a href=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2017\/11\/Kaspersky-Lab_Q3-APT-Report.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-30222 size-large\" src=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2017\/11\/Kaspersky-Lab_Q3-APT-Report-1024x672.jpg\" alt=\"\" width=\"640\" height=\"420\" srcset=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2017\/11\/Kaspersky-Lab_Q3-APT-Report-1024x672.jpg 1024w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2017\/11\/Kaspersky-Lab_Q3-APT-Report-300x197.jpg 300w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2017\/11\/Kaspersky-Lab_Q3-APT-Report-768x504.jpg 768w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2017\/11\/Kaspersky-Lab_Q3-APT-Report-84x55.jpg 84w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2017\/11\/Kaspersky-Lab_Q3-APT-Report.jpg 1460w\" sizes=\"auto, (max-width: 640px) 100vw, 640px\" \/><\/a><\/p>\n<p>In total, 10 of the 24 research projects on advanced targeted attacks conducted by Kaspersky Lab in Q3 centered around activities attributed to multiple actors in the Chinese region. These and other trends are covered in Kaspersky Lab\u2019s latest quarterly threat intelligence summary.<\/p>\n<p>Research conducted during the period of July-September 2017 revealed a number of developments in the area of targeted attacks by, among others, Chinese-, Russian-, English-, and Korean-speaking threat actors.<\/p>\n<p>Chinese criminals in particular were specifically active during this period. Their revitalization has affected not only various organizations, but also government and political bodies as well as huge regional agreements \u2013 bringing international relations into the business of advanced targeted attacks.<\/p>\n<p>Kaspersky Lab\u2019s report also notes a rise of cyber-espionage attacks by Chinese-speaking actors. The most interesting of the attacks were <a href=\"https:\/\/securelist.com\/shadowpad-in-corporate-networks\/81432\/\">Netsarang\/ShadowPad<\/a> and <a href=\"https:\/\/threatpost.com\/inside-the-ccleaner-backdoor-attack\/128283\/\">CCleaner<\/a> \u2013 both of which involved embedding specific backdoors inside the installation packages of legitimate software. CCleaner alone managed to infect 2 million computers, making it one of the biggest attacks of 2017.<\/p>\n<p>The report also reveals growing Chinese-speaking actors\u2019 interest in attacks on strategic facilities and economy sectors. At least two separate reports provide clear cases in point:<\/p>\n<ol>\n<li><b>IronHusky attack on Russian and Mongolian aviation companies<\/b> <b>and research institutes<\/b>. This campaign was discovered in July, when the two countries were targeted with a Poison Ivy variant from a Chinese-speaking threat actor. The attack was connected to Mongolian air defense prospects, which were a key subject of negotiations held with Russia earlier in the year.<\/li>\n<\/ol>\n<ol start=\"2\">\n<li><b>H2ODecomposition attack on the energy sectors of India and Russia<\/b>. Both countries\u2019 energy sectors were targeted with a new piece of malware referred to as \u201cH2ODecomposition\u201d. In some cases, this malware was masquerading as a popular Indian antivirus solution (QuickHeal).<\/li>\n<\/ol>\n<p>Furthermore, in Q3 2017 Kaspersky Lab experts issued several reports on Russian-speaking actors. Most of them were dedicated to financial and ATM attacks, however, one report examined <a href=\"https:\/\/apt.securelist.com\/#!\/threat\/1012\">Sofacy<\/a>\u2019s summertime activity, indicating that the group remained active.<\/p>\n<p>Speaking of English-speaking actors, the third quarter also produced yet another member of the Lamberts: Red Lambert. <a href=\"https:\/\/securelist.com\/unraveling-the-lamberts-toolkit\/77990\/\">The Lamberts<\/a> is a family of sophisticated attack tools that has been used by either one or multiple threat actors against high-profile victims since at least 2008.<\/p>\n<p>The Red Lambert is a network-driven backdoor, discovered during the previous analysis of Grey Lambert and utilized instead of hard-coded SSL certificates in command and control communications.<\/p>\n<p>\u201cThe targeted threat landscape is evolving constantly, not only in terms of cybercriminals\u2019 being increasingly well-prepared and technologically sophisticated, but also in terms of geography. The rise of Chinese-speaking actors once again demonstrates the importance of investing in threat intelligence and arming organizations with insight on the latest trends and developments,\u201d said Brian Bartholomew, Principal Security Researcher, Global Research and Analysis Team, Kaspersky Lab.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The third quarter of 2017 clearly demonstrated that Chinese-speaking actors have not \u201cdisappeared\u201d and are still very much active, conducting cyber-espionage campaigns against a wide range of countries and industry verticals.\u00a0 In total, 10 of the 24 research projects on advanced targeted attacks conducted by Kaspersky Lab in Q3 centered around activities attributed to multiple [&hellip;]<\/p>\n","protected":false},"author":6,"featured_media":30222,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[19],"tags":[495,286,117],"class_list":["post-30218","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-headlines","tag-cybersecurity-and-cybercrime","tag-it-security","tag-kaspersky-lab"],"_links":{"self":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/30218","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/comments?post=30218"}],"version-history":[{"count":0,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/30218\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media\/30222"}],"wp:attachment":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media?parent=30218"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/categories?post=30218"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/tags?post=30218"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}