• contact@globalcase.org
  • +995322476006
ქართული

Choose country

  • CASE GEO
  • CASE USA
  • About UsAbout Us
    • About CASEAbout CASE
    • Our teamour-team
    • CASE AnalyticsCASE Analytics
    • CASE NetworkingCASE Networking
    • Careercareer
    • Certificationcertification
    • Cyber Security in CASECyber Security in CASE
    • Success StoriesSuccess Stories
    • Contact UsGet in touch
  • Blog
  • ServicesServices
    • Personal Data ProtectionPersonal Data Protection Service and DPO Outsourcing
    • Cyber Security ServicesCyber Security Services
    • Corporate TrainingsCorporate Trainings
  • HomeLets start here
  • Mediamedia
    • Media about usMedia about us
    • News
  • CoursesCourses
  • Resources
    • Cyber PodcastCyber Podcast
    • Research and Analysis
    • E-Books
    • Security Brief
    • Frequently asked QuestionsFrequently asked Questions
logo
CASE

Email Address

contact@globalcase.org

Phone

+995322476006
  • About UsAbout Us
    • About CASEAbout CASE
    • Our teamour-team
    • CASE AnalyticsCASE Analytics
    • CASE NetworkingCASE Networking
    • Careercareer
    • Certificationcertification
    • Cyber Security in CASECyber Security in CASE
    • Success StoriesSuccess Stories
    • Contact UsGet in touch
  • Blog
  • ServicesServices
    • Personal Data ProtectionPersonal Data Protection Service and DPO Outsourcing
    • Cyber Security ServicesCyber Security Services
    • Corporate TrainingsCorporate Trainings
  • HomeLets start here
  • Mediamedia
    • Media about usMedia about us
    • News
  • CoursesCourses
  • Resources
    • Cyber PodcastCyber Podcast
    • Research and Analysis
    • E-Books
    • Security Brief
    • Frequently asked QuestionsFrequently asked Questions

Security Brief

    HomeSecurity Brief
    Chinese Hackers Deploy UNAPIMON Malware
Chinese Hackers Deploy UNAPIMON Malware
Chinese Hackers Deploy UNAPIMON Malware
In:
Breaking News
Created:
03 Apr 2024
Share :

"Earth Freybug is a cyberthreat group that focuses on espionage and financially motivated activities," Trend Micro security analyst Christopher So stated in a report released today. The group has been active since at least 2012.

"It has been observed to target organisations from various sectors across different countries."

According to the cybersecurity company, Earth Freybug is a component of APT41, a China-affiliated cyber espionage organisation that is also being monitored under the names Axiom, Brass Typhoon (formerly known as Barium), Bronze Atlas, HOODOO, Wicked Panda, and Winnti.
To achieve its objectives, the hostile group is reported to rely on a mix of bespoke malware and living-off-the-land binaries (LOLBins). Techniques like application programming interface (API) unhooking and dynamic-link library (DLL) hijacking are also used.

According to Trend Micro, the activity has tactical similarities with a cluster that cybersecurity firm Cybereason previously revealed under the moniker Operation CuckooBees. Operation CuckooBees is a campaign of intellectual property theft that targets manufacturing and technology companies in North America, Western Europe, and East Asia.

Using a valid VMware Tools executable ("vmtoolsd.exe") to set up a scheduled task with "schtasks.exe" and launch a programme called "cc.bat" on the remote computer is the first step in the attack chain.
UNAPIMON is a straightforward C++-based virus that uses an open-source Microsoft library called Detours to unhook crucial API functions. This allows it to avoid detection in sandbox situations where hooking is used for API monitoring.

The purpose of the batch script is to gather system data and start a second scheduled task on the compromised host. This second task then starts another batch file called "cc.bat" and eventually launches the UNAPIMON virus.

This opens the door for TSMSISrv.DLL to run, which is in charge of dropping UNAPIMON and injecting the same DLL into cmd.exe, among other DLL files. In order to evade defence, the DLL file is also simultaneously injected into SessionEnv.

Source: The Hacker News

In:
Breaking News

Search Date

Categories

  • Breaking News
  • Updates
  • Thoughts
  • footer_logo

    Advancing Security as a Profession!

    Join Newsletter

    Services

    • Cyber and Information Security
    • Bank Security officer course
    • Work safety services
    • Fire safety training
    • First aid training

    Links

    • FAQ
    • Services
    • Courses
    • Privacy Policy
    • Terms

    Contact

    • +995 322 476 006
    • contact@globalcase.org
    • Georgia, Tbilisi, Pekini Ave. 30
    • Homepage
    • Main competence
    • Services
    • Courses
    • Blog
    • Contact us