New Attack Technique GrimResource Sweeps Through China with Fake Website


QiAnXin Threat Intelligence Center and Falcon Operations Team observed in their daily operations that in June 2024, several foreign counterparts reported in-the-wild attacks related to the new attack technique GrimResource.

QiAnXin Threat Intelligence Center and Falcon Operations Team promptly conducted research on this technique and have been continuously monitoring it. In mid-July 2024, they discovered the first attack incident in government and enterprise terminals, and the researchers classified the nature of the attack as black industry. The GrimResource technique exploits the XSS vulnerability in mmc system files to execute JS code and uses DotNetToJScript to load arbitrary .NET programs into memory. This not only bypasses ActiveX control warnings but also enables fileless payload execution.

Read more…
Source: QiAnXin Threat Intelligence Center/Falcon Operations Team


Sign up for our Newsletter


Related:

  • Chinese Playful Taurus Activity in Iran

    January 18, 2023

    Playful Taurus, also known as APT15, BackdoorDiplomacy, Vixen Panda, KeChang and NICKEL, is a Chinese advanced persistent threat group that routinely conducts cyber espionage campaigns. The group has been active since at least 2010 and has historically targeted government and diplomatic entities across North and South America, Africa and the Middle East. In June 2021, ESET ...

  • A UN committee is struggling to define what cybercrime is in upcoming treaty

    January 10, 2023

    A United Nations committee – whose members include delegates from the U.S., China and Russia — is meeting throughout this week and next to continue negotiations for a new international cybercrime treaty. Why it matters: The finished UN cybercrime treaty will jumpstart a wave of new laws around the world based on the agreed-upon principles in ...

  • Cloudflare finds a way through China’s network defences

    November 30, 2022

    Cloudflare has found a way to extend some of its services across the Great Firewall and into mainland China. “Performance and reliability for traffic flows across the mainland China border have been a consistent challenge for IT teams within multinational organizations,” wrote product managers Kyle Krum and Annika Garbers. “Packets crossing the China border often experience ...

  • Always Another Secret: Lifting the Haze on China-nexus Espionage in Southeast Asia

    November 28, 2022

    Mandiant Managed Defense recently identified cyber espionage activity that heavily leverages USB devices as an initial infection vector and concentrates on the Philippines. Mandiant tracks this activity as UNC4191 and we assess it has a China nexus. UNC4191 operations have affected a range of public and private sector entities primarily in Southeast Asia and extending to ...

  • US bans Huawei, ZTE equipment sales amid Chinese spying fears

    November 27, 2022

    The Biden administration has banned approvals of new telecommunications equipment from China’s Huawei Technologies and ZTE because they pose “an unacceptable risk” to US national security. The US Federal Communications Commission said on Friday it had adopted the final rules, which also bar the sale or import of equipment made by China’s surveillance equipment maker Dahua ...

  • UK: Government departments ordered to stop installing cameras made by Chinese firms in ‘sensitive sites’

    November 24, 2022

    Government departments have been told to stop installing cameras made by Chinese firms in “sensitive sites”. They have also been urged to disconnect Chinese-made devices from core computer networks and to consider removing them altogether, amid security concerns. The Government Security Group has said that since companies in China have to comply with the country’s national intelligence ...