The cybercriminal group APT36, or Transparent Tribe, has launched a series of cyber-attacks on Indian government, educational, and military organizations. The APT36 campaign includes fake malicious LNK filenames that list themselves as PDF file types to allow installation of remote access trojans (RATs) on targeted machines. The remote access trojans allow the cyber-criminals to maintain continual access to the infected machine remotely.
The attack begins with a spear-phishing email containing a zip file containing a malicious LNK file. When opened using mshta.exe to create a remote HTML application (HTA), this file will decrypt and load an iinneldc.dll RAT into the memory of the infected machine while also displaying a fake PDF.
Once installed, the RAT provides the attacker with complete control over the system and can be used to manage files, steal data, capture screenshots, and change the contents of the clipboard.
Advanced Persistent Threat (APT) 36 has been known for their ability to change their methods of gaining Persistence on Compromised Machines based on the Anti-Virus (AV) Software type's ability to detect and block APT 36 malware.
APT36 also send out "Fake" Advisories in order to redirect the target victim into the installation of APT 36 malware onto the Victim's Computer System. Additionally, APT 36's Command and Control (C2) Servers utilize an obfuscated version of the Endpoint Strings, in order to evade detection of the C2 Server from security solutions.
Patchwork & StreamSpy Trojan
The Patchwork Advanced Persistent Threat (APT) group is simultaneously deploying the StreamSpy remote access Trojan (RAT) that has been written in Python and delivered through ZIP files. The Patchwork group utilizes the features of MSBuild loaders to execute code stored in the ZIP file. In addition, they are using HTTP/Websocket for command and control (C2) communications with StreamSpy.
StreamSpy contains many features: file upload, system information gathering, and executing of persistent components. In addition to these featuresStreamSpy and ShadowAgent RAT exhibit similar functionality.
Both types of malware have become more sophisticated in targeting India with the use of multi-layered malware, multi-component RATs, and the ability to evade detection by employing multiple layers of defense so that they can achieve long-term access.
Source: The Hacker News