The third quarter of 2017 clearly demonstrated that Chinese-speaking actors have not “disappeared” and are still very much active, conducting cyber-espionage campaigns against a wide range of countries and industry verticals.

 

In total, 10 of the 24 research projects on advanced targeted attacks conducted by Kaspersky Lab in Q3 centered around activities attributed to multiple actors in the Chinese region. These and other trends are covered in Kaspersky Lab’s latest quarterly threat intelligence summary.

 

Research conducted during the period of July-September 2017 revealed a number of developments in the area of targeted attacks by, among others, C

 

Chinese criminals in particular were specifically active during this period. Their revitalization has affected not only various organizations, but also government and political bodies as well as huge regional agreements – bringing international relations into the business of advanced targeted attacks.

 

Highlights in Q3, 2017 include:

  • Rise of cyber-espionage attacks by Chinese-speaking actors. The most interesting of the attacks were Netsarang/ShadowPad and CCleaner – both of which involved embedding specific backdoors inside the installation packages of legitimate software. CCleaner alone managed to infect 2 million computers, making it one of the biggest attacks of 2017.
  • Growing Chinese-speaking actors’ interest in attacks on strategic facilities and economy sectors. At least two separate reports provide clear cases in point:
    1. IronHusky attack on Russian and Mongolian aviation companies and research institutes. This campaign was discovered in July, when the two countries were targeted with a Poison Ivy variant from a Chinese-speaking threat actor. The attack was connected to Mongolian air defense prospects, which were a key subject of negotiations held with Russia earlier in the year.
    2. H2ODecomposition attack on the energy sectors of India and Russia. Both countries’ energy sectors were targeted with a new piece of malware referred to as “H2ODecomposition”. In some cases, this malware was masquerading as a popular Indian antivirus solution (QuickHeal).

 

Furthermore, in Q3 2017 Kaspersky Lab experts issued several reports on Russian-speaking actors. Most of them were dedicated to financial and ATM attacks, however, one report examined Sofacy’s summertime activity, indicating that the group remained active.

 

Speaking of English-speaking actors, the third quarter also produced yet another member of the Lamberts: Red Lambert. The Lamberts is a family of sophisticated attack tools that has been used by either one or multiple threat actors against high-profile victims since at least 2008.

 

The Red Lambert is a network-driven backdoor, discovered during the previous analysis of Grey Lambert and utilized instead of hard-coded SSL certificates in command and control communications.

 

“The targeted threat landscape is evolving constantly, not only in terms of cybercriminals’ being increasingly well-prepared and technologically sophisticated, but also in terms of geography. The rise of Chinese-speaking actors once again demonstrates the importance of investing in threat intelligence and arming organizations with insight on the latest trends and developments,” said Brian Bartholomew, Principal Security Researcher, Global Research and Analysis Team, Kaspersky Lab.

 

The Q3 APT Trends report summarizes the findings of Kaspersky Lab’s subscriber-only threat intelligence reports. During the third quarter of 2017, Kaspersky Lab’s Global Research and Analysis Team created 24 private reports for subscribers, with Indicators of Compromise (IOC) data and YARA rules to assist in forensics and malware-hunting.

 

For more information, please contact: intelreports@kaspersky.com


RECOMMENDED ARTICLE FOR TECHWORLD


 
System Integration Expo Sets the Stage for High-Tech Innovations
Techworld Date Posted: 9 July 2018 1:18 PM | 211 Views
The 12th largest population in the world, and also arguably one of the most tech-savvy around, the Philippines offers a multitude of opportunities for tech companies and investors. For the past decade or so,.... See More
 
System Integration Expo Sets the Stage for High-Tech Innovations
Techworld Date Posted: 1:18 PM | 211 Views
The 12th largest population in the world, and also arguably one of the most tech-savvy around, the Philippines offers a multitude of opportunities for tech companies and investors. For the past decade or so,...See More

 
Epson Eases Print Management through EasyCare360
Techworld Date Posted: 4 December 2018 2:47 PM | 55 Views
Epson, a global leader in printing technologies and market leader for ink tank printers, recently launched its very own enterprise printing solution in a bid to ease print management for its customers nationwide. . See More
 
Epson Eases Print Management through EasyCare360
Techworld Date Posted: 2:47 PM | 55 Views
Epson, a global leader in printing technologies and market leader for ink tank printers, recently launched its very own enterprise printing solution in a bid to ease print management for its customers nationwide. See More

Frank Emmanuel Trazo
Steam Greenlight: An End of a Chaotic Era
All About Gaming • By: Frank Emmanuel Trazo | Date Posted: 6 September 2017 9:34 AM | 333 Views
On June 6, 2017, Valve decided to discontinue Steam Greenlight. After suspending the submission of new games, they had more than 3400 games that were pending in Steam Greenlight. Some titles weren't granted approval.... See More
Frank Emmanuel Trazo
Steam Greenlight: An End of a Chaotic Era
All About Gaming • By: Frank Emmanuel Trazo | Date Posted: 9:34 AM | 333 Views
On June 6, 2017, Valve decided to discontinue Steam Greenlight. After suspending the submission of new games, they had more than 3400 games that were pending in Steam Greenlight. Some titles weren't granted approval...See More

 
Far Eastern University Team Wins First Intercollegiate PUBG Competition
Techworld Date Posted: 24 July 2018 5:15 PM | 727 Views
The FEU_ANBU team of Far Eastern University has emerged as the champions of the inaugural MSI-NVIDIA University League PlayerUnknown’s Battleground (PUBG) Tournament, the first intercollegiate competition in the Philippines.. See More
 
Far Eastern University Team Wins First Intercollegiate PUBG Competition
Techworld Date Posted: 5:15 PM | 727 Views
The FEU_ANBU team of Far Eastern University has emerged as the champions of the inaugural MSI-NVIDIA University League PlayerUnknown’s Battleground (PUBG) Tournament, the first intercollegiate competition in the Philippines.See More

 
EagleTree Capital Buys Majority Share in CORSAIR in a Transaction Valued at $525 Million
Techworld Date Posted: 27 July 2017 3:30 PM | 367 Views
CORSAIR, a world leader in high-performance PC components, gaming peripherals, and enthusiast memory, announced today that EagleTree Capital ("EagleTree"), formerly Wasserstein Partners, has reached a definitive agreement in partnership with current management to acquire.... See More
 
EagleTree Capital Buys Majority Share in CORSAIR in a Transaction Valued at $525 Million
Techworld Date Posted: 3:30 PM | 367 Views
CORSAIR, a world leader in high-performance PC components, gaming peripherals, and enthusiast memory, announced today that EagleTree Capital ("EagleTree"), formerly Wasserstein Partners, has reached a definitive agreement in partnership with current management to acquire...See More

 
Apacer AC532 USB 3.1 Gen 1 Portable Hard Drive: Anti-Vibration Internal Suspension Structure, 1-Meter Shockproof and Anti-Slip Design
Techworld Date Posted: 23 August 2017 11:30 AM | 275 Views
Apacer launches the brand-new AC532, a classic portable hard drive combining a slim shape with great protection design, making it a high price-performance choice in portable hard drives. AC532 is equipped with an anti.... See More
 
Apacer AC532 USB 3.1 Gen 1 Portable Hard Drive: Anti-Vibration Internal Suspension Structure, 1-Meter Shockproof and Anti-Slip Design
Techworld Date Posted: 11:30 AM | 275 Views
Apacer launches the brand-new AC532, a classic portable hard drive combining a slim shape with great protection design, making it a high price-performance choice in portable hard drives. AC532 is equipped with an anti...See More

PCBG Gaming Crew
2017 Mid-Season Invitational Mania
Techworld • By: PCBG Gaming Crew | Date Posted: 12 April 2017 10:51 AM | 1075 Views
As the first half of major league tournaments all over the globe has been exhausted and judged, the 2017 Mid-Season Invitational will begin on the 29th of April with massive hungry league fans waiting.... See More
PCBG Gaming Crew
2017 Mid-Season Invitational Mania
Techworld • By: PCBG Gaming Crew | Date Posted: 10:51 AM | 1075 Views
As the first half of major league tournaments all over the globe has been exhausted and judged, the 2017 Mid-Season Invitational will begin on the 29th of April with massive hungry league fans waiting...See More


 
Kaspersky Lab and iSecure Networks Give Away P280k in Photo Story Contest
Techworld Date Posted: 14 October 2017 2:16 PM | 179 Views
Manila, Philippines – Be among the twelve lucky winners of a total of P280,000 worth of cash prizes tax-free just by securing your devices against cyberattacks with Kaspersky Lab and iSecure Network’s photo story.... See More
 
Kaspersky Lab and iSecure Networks Give Away P280k in Photo Story Contest
Techworld Date Posted: 2:16 PM | 179 Views
Manila, Philippines – Be among the twelve lucky winners of a total of P280,000 worth of cash prizes tax-free just by securing your devices against cyberattacks with Kaspersky Lab and iSecure Network’s photo story...See More

 
Alita: Battle Angel Hypes Up with AOC and 21st Century Fox’s Exclusive Sneak Peek in IMAX Theatre
Techworld Date Posted: 18 December 2018 10:48 AM | 81 Views
AOC, a global-leader in display technology, and Twentieth Century Fox Film Corporation once again joined forces as promotional partners for an exclusive sneak peek of Alita: Battle Angel at the IMAX Theater in SM.... See More
 
Alita: Battle Angel Hypes Up with AOC and 21st Century Fox’s Exclusive Sneak Peek in IMAX Theatre
Techworld Date Posted: 10:48 AM | 81 Views
AOC, a global-leader in display technology, and Twentieth Century Fox Film Corporation once again joined forces as promotional partners for an exclusive sneak peek of Alita: Battle Angel at the IMAX Theater in SM...See More


Power by

Download Free AZ | Free Wordpress Themes