Tracking the Progression of Earth Hundun’s Cyberespionage Campaign in 2024


In their previous report, Trend Micro researchers introduced the sophisticated cyberespionage campaign orchestrated by Earth Hundun, a threat actor known for targeting the Asia-Pacific region using the Waterbear malware and its latest iteration, Deuterbear. We first observed Deuterbear being used by Earth Hundun in October 2022, and it has since been part of the group’s subsequent campaigns.

Trend Micro analysis provided insights into the intricate workings of the downloader, detailing its infection flow, traffic behavior, anti-analysis techniques, and evolutionary trajectory. In this entry, we examine the behavior of the final Remote Access Trojan (RAT) that the researchers recently managed to download from a C&C server, based on an Earth Hundun campaign from 2024.

Read more…
Source: Trend Micro


Sign up for our Newsletter


Related:

  • US bans Huawei, ZTE equipment sales amid Chinese spying fears

    November 27, 2022

    The Biden administration has banned approvals of new telecommunications equipment from China’s Huawei Technologies and ZTE because they pose “an unacceptable risk” to US national security. The US Federal Communications Commission said on Friday it had adopted the final rules, which also bar the sale or import of equipment made by China’s surveillance equipment maker Dahua ...

  • RCMP use of spyware warrants update to Canada’s privacy laws, MPs say

    November 24, 2022

    Canada should update its privacy laws in the wake of revelations that the country’s national police force uses spyware to hack mobile devices, a parliamentary committee says. The House of Commons ethics committee is recommending the federal government require privacy assessments for the use of “high-risk technological tools” that collect personal data, according to a report ...

  • Earth Preta Spear-Phishing Governments Worldwide

    November 17, 2022

    Trend Micro researchers have been monitoring a wave of spear-phishing attacks targeting the government, academic, foundations, and research sectors around the world. Based on the lure documents researchers observed in the wild, this is a large-scale cyberespionage campaign that began around March. After months of tracking, the seemingly wide outbreak of targeted attacks includes but ...

  • Billbug: State-sponsored Actor Targets Cert Authority, Government Agencies in Multiple Asian Countries

    November 15, 2022

    State-sponsored actors compromised a digital certificate authority in an Asian country during a campaign in which multiple government agencies were also targeted. Symantec, by Broadcom Software, was able to link this activity to a group we track as Billbug due to the use in this campaign of tools previously attributed to this group. Billbug (aka Lotus ...

  • SolarWinds says it’s facing SEC ‘enforcement action’ over 2020 hack

    November 7, 2022

    The long hangover from a 2020 state-sponsored compromise still isn’t over for SolarWinds, as the software giant targeted by Russian government hackers has to pony up $26 million to shareholders and face possible enforcement action from the federal government. In a recent 8-K filing with the U.S. Securities and Exchange Commission, SolarWinds said it reached an ...

  • Greece: Report claims illegal surveillance software was used to spy on politicians, journalists and businessmen

    November 5, 2022

    Greece has been rocked by a ‘wiretapping’ scandal as a bombshell report claimed Prime Minister Kyriakos Mitsotakis ‘used state intelligence to spy on dozens of people including potential political rivals, journalists and businessmen’. Documento reported that the list of targets included former premier Antonis Samaras, current members of the cabinet and shipping magnate Vangelis Marinakis, owner ...