QiAnXin Threat Intelligence Center and Falcon Operations Team observed in their daily operations that in June 2024, several foreign counterparts reported in-the-wild attacks related to the new attack technique GrimResource.
QiAnXin Threat Intelligence Center and Falcon Operations Team promptly conducted research on this technique and have been continuously monitoring it. In mid-July 2024, they discovered the first attack incident in government and enterprise terminals, and the researchers classified the nature of the attack as black industry. The GrimResource technique exploits the XSS vulnerability in mmc system files to execute JS code and uses DotNetToJScript to load arbitrary .NET programs into memory. This not only bypasses ActiveX control warnings but also enables fileless payload execution.
Read more…
Source: QiAnXin Threat Intelligence Center/Falcon Operations Team
Related:
- Weak data protection helped China attack US Federal Reserve, report says
July 27, 2022
China’s cyber espionage activities are extensive and sophisticated but when the Middle Kingdom tried to steal sensitive economic data from the US Fed, poor security meant its operatives didn’t have to dip too far into their bags of tricks. Or at least that’s according to the findings of an investigation by the Senate’s Committee on Homeland ...
- Chinese ride-sharing operator Didi slapped with $1.1B fine for breaching China data security laws
July 21, 2022
Didi Global has been fined 8 billion yuan ($1.18 billion) for breaching China’s cybersecurity and data security laws. The Chinese ride-sharing operator is accused of 16 illegal practices involving the collection of passenger data. Cyberspace Administration of China (CAC) said Thursday Didi had violated the country’s cybersecurity and data security laws. The industry regulator pointed to ...
- Belgium says Chinese hackers attacked its Ministry of Defense
July 19, 2022
The Minister for Foreign Affairs of Belgium says multiple Chinese state-backed threat groups targeted the country’s defense and interior ministries. “Belgium exposes malicious cyber activities that significantly affected our sovereignty, democracy, security and society at large by targeting the FPS Interior and the Belgian Defence,” the foreign minister said. “Belgium assesses these malicious cyber activities to have ...
- Hackers pose as journalists to breach news media org’s networks
July 16, 2022
Researchers following the activities of advanced persistent (APT) threat groups originating from China, North Korea, Iran, and Turkey say that journalists and media organizations have remained a constant target for state-aligned actors. The adversaries are either masquerading or attacking these targets because they have unique access to non-public information that could help expand a cyberespionage operation. Recent ...
- How data on a billion people may have leaked from a Chinese police dashboard
July 10, 2022
Details have emerged on how more than a billion personal records were stolen in China and put up for sale on the dark web, and it all boils down to a unprotected online dashboard that left the data open to anyone who could find it. More than 23TB of details apparently stolen from the Shanghai police ...
- Hacker claims to have stolen data on 1 billion Chinese citizens
July 4, 2022
An anonymous threat actor is selling several databases they claim to contain more than 22 terabytes of stolen information on roughly 1 billion Chinese citizens for 10 bitcoins (approximately $195,000). The announcement was posted on a hacker forum by someone using the handle ‘ChinaDan,’ saying that the information was leaked from the Shanghai National Police (SHGA) ...

