Ke3chang APT Linked to Previously Undocumented Backdoor
#1
Quote:The Ke3chang cyberespionage group, a.k.a. APT15, Mirage, Playful Dragon or Vixen Panda, has been tied to a backdoor called Okrum that has been used to target diplomatic missions throughout Europe and Latin America. The attribution widens the scope of known Ke3chang activity, an APT believed to be operating from China.

Ke3change first appeared in 2010, making a name for itself by developing simple but custom malware like the BS2005/Ketrican backdoors and the RoyalDNS malware and deploying it in what was dubbed “Operation Ke3chang.” Almost 10 years later, the group continues to be active according to ESET, using revamped versions of BS2005/Ketrican.
 
In 2015, Ke3chang made a splash by continuing its previous Operation Ke3chang attacks that centered around Slovakia, using the BS2005/Ketrican backdoor family.

The following year, ESET discovered Okrum, focused on the same type of targets: Diplomatic missions in Slovakia, Belgium, Chile, Guatemala and Brazil, with the attackers showing a particular interest in Slovakia. The attackers were also seen using a related TidePool malware family discovered by Palo Alto Networks that targeted Indian embassies across the globe.

The Okrum activity continued through 2017 and the ESET team has been able to tie it back to Ke3chang, with Okrum observed acting as a first-stage malware that then fetched Ketrican samples to install on a compromised machine.

“Our research has shown that the Ketrican, Okrum and RoyalDNS backdoors detected by ESET after 2015 are linked to previously documented Ke3chang group activity, and to each other, in a number of ways,” said ESET researcher Zuzana Hromcová, in an analysis[PDF] posted on Thursday. “[Since then], Ketrican backdoors from 2015, 2017, 2018 and 2019 have all evolved from malware used in Operation Ke3chang.”

SOURCE: https://threatpost.com/ke3chang-apt-undo...or/146537/
[-] The following 2 users say Thank You to silversurfer for this post:
  • harlan4096, ismail
Reply


Messages In This Thread
Ke3chang APT Linked to Previously Undocumented Backdoor - by silversurfer - 18 July 19, 18:39

Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
QOwnNotes
26.4.0  LanguageT...Kool — 08:39
Surfshark VPN : Award-winning VPN servi...
Surfshark Apps Ver...jasonX — 04:41
Surfshark VPN : Award-winning VPN servi...
Surfshark launches...jasonX — 03:43
ESET 19.1.12.0
Changes in 19.1.12...harlan4096 — 14:49
Vivaldi 7.9 Build 3970.47
Vivaldi 7.9 Build ...harlan4096 — 07:31

[-]
Birthdays
Today's Birthdays
avatar (41)alapesihy
Upcoming Birthdays
avatar (45)wapedDow
avatar (49)oapedDow
avatar (42)Sanchowogy
avatar (46)MeighGoask
avatar (47)creatralGuelm
avatar (38)procnipsut
avatar (44)accenwibly
avatar (41)ahyvily
avatar (38)urumahiz
avatar (44)techlignub
avatar (43)Stevenmam
avatar (50)onlinbah
avatar (50)fuspeukChark
avatar (44)werriewWaiNg
avatar (38)Freemanleo
avatar (48)cticigges
avatar (50)ecoFit
avatar (44)soccejeS
avatar (43)cdoubapKit
avatar (38)lystraPonia
avatar (31)smith8395john
avatar (51)steakelask
avatar (45)Termoplenka
avatar (43)bycoPaist
avatar (49)pieloKat
avatar (43)ilyagNeexy
avatar (51)donitascene
avatar (51)burntLaw
avatar (41)MrDoorsskibheeds
avatar (51)Toligo
avatar (46)Rodneykak
avatar (49)tradeSmode
avatar (39)vemedProkbior
avatar (38)RobertUtelt
avatar (46)JamesZic
avatar (43)Sanfordbup
avatar (38)Der.Reisende
avatar (36)Kiran78

[-]
Online Staff
There are no staff members currently online.

>