{"id":6875,"date":"2022-06-28T20:14:35","date_gmt":"2022-06-28T11:14:35","guid":{"rendered":"https:\/\/cyberenso.jp\/?p=6875"},"modified":"2022-07-04T20:19:58","modified_gmt":"2022-07-04T11:19:58","slug":"research-reveals-that-chinese-apt-are-using-short-lived-ransomware-variants-as-a-disguise-for-cyberespionage-activities","status":"publish","type":"post","link":"https:\/\/cyberenso.jp\/en\/research-reveals-that-chinese-apt-are-using-short-lived-ransomware-variants-as-a-disguise-for-cyberespionage-activities\/","title":{"rendered":"Research reveals that Chinese APT are using short-lived ransomware variants as a disguise for cyberespionage activities"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"6875\" class=\"elementor elementor-6875\" data-elementor-post-type=\"post\">\n\t\t\t\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-c8d37a1 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"c8d37a1\" data-element_type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-17fa933\" data-id=\"17fa933\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t\t\t<div class=\"elementor-element elementor-element-2e4e83e elementor-widget elementor-widget-text-editor\" data-id=\"2e4e83e\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<p>On the 23rd of June 2022, cybersecurity researchers from Secureworks published new research which named several ransomware variants which have been identified as being used by a state-backed hacking group with China-linked origins known as \u2018Bronze Starlight\u2019 to disguise the true objective of their attacks that is for conducting cyberespionage activities. The research looked into HUI Loader, which is a malicious tool that criminals have used widely since 2015.<\/p><p>\u00a0<\/p><p>HUI Loader is a custom DLL loader that can be deployed by hijacked legitimate software programs susceptible to DLL search order hijacking. Once executed, the loader will then deploy and decrypt a file containing the main malware payload. HUI Loaders have been used by many threat groups before including APT10, Bronze Riverside and Blue Termite. But based on the research by Secureworks&#8217; Counter Threat Unit (CTU) research team, two activity clusters have been included.<\/p><p>\u00a0<\/p><p>The first cluster has been linked to Bronze Riverside which is known for having a focus on stealing valuable intellectual property from Japanese organisations. But the second cluster has been linked to another China-linked group, Bronze Starlight which seems to have a focus on IP theft and cyber espionage. Victims of these two groups have included Brazilian pharmaceutical companies, a US media outlet, Japanese manufacturers, and a major Indian organization&#8217;s aerospace and defence division.<\/p><p>\u00a0<\/p><p>The research also revealed that Bronze Starlight has deployed five different kinds of ransomware during their campaigns: LockFile, AtomSilo, Rook, Night Sky, and Pandora. It is believed that they developed their ransomware variants from two distinct code bases: one for LockFile and AtomSilo, and the other for Rook, Night Sky, and Pandora. Avast has released a decryptor for LockFile and AtomSilo. When it comes to the other ransomware variants, it appears that they are all based on Babuk source code.<\/p>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>On the 23rd of June 2022, cybersecurity researchers from Secureworks published new research which named several ransomware variants which have been identified as being used by a state-backed hacking group with China-linked origins known as \u2018Bronze Starlight\u2019 to disguise the true objective of their attacks that is for conducting cyberespionage activities. The research looked into HUI Loader, which is a<span class=\"excerpt-hellip\"> [\u2026]<\/span><\/p>\n","protected":false},"author":1,"featured_media":6880,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6,12,9,2,7,1],"tags":[],"class_list":["post-6875","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-latest_news","category-read_article","category-ransomware_criminals","category-ce_news","category-by_country","category-uncategorized"],"acf":[],"jetpack_featured_media_url":"https:\/\/i0.wp.com\/cyberenso.jp\/wp-content\/uploads\/2022\/07\/cyenso10.jpg?fit=1375%2C1032&ssl=1","_links":{"self":[{"href":"https:\/\/cyberenso.jp\/en\/wp-json\/wp\/v2\/posts\/6875"}],"collection":[{"href":"https:\/\/cyberenso.jp\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cyberenso.jp\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cyberenso.jp\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/cyberenso.jp\/en\/wp-json\/wp\/v2\/comments?post=6875"}],"version-history":[{"count":6,"href":"https:\/\/cyberenso.jp\/en\/wp-json\/wp\/v2\/posts\/6875\/revisions"}],"predecessor-version":[{"id":6884,"href":"https:\/\/cyberenso.jp\/en\/wp-json\/wp\/v2\/posts\/6875\/revisions\/6884"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cyberenso.jp\/en\/wp-json\/wp\/v2\/media\/6880"}],"wp:attachment":[{"href":"https:\/\/cyberenso.jp\/en\/wp-json\/wp\/v2\/media?parent=6875"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cyberenso.jp\/en\/wp-json\/wp\/v2\/categories?post=6875"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cyberenso.jp\/en\/wp-json\/wp\/v2\/tags?post=6875"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}