• 3,000 firms
  • Independent
  • Trusted
Save up to 70% on staff

News » China-linked cyber-spies breach Russian government, IT networks

China-linked cyber-spies breach Russian government, IT networks

china-linked-cyber-spies-breach-russia
Photo from Shutterstock

MOSCOW, RUSSIA — A sophisticated cyber-espionage campaign, allegedly linked to Chinese state-sponsored groups, has infiltrated Russian government agencies and IT providers. 

The Russia-based cybersecurity firm Kaspersky has identified “dozens” of compromised computers infected with backdoors and trojans since late July. 

This ongoing operation, dubbed “EastWind,” involves malware associated with two notorious China-linked groups, APT27 and APT31.

Phishing tactics and cloud-based command centers

The attackers initially gained access through phishing emails containing RAR archive attachments. These attachments included a Windows shortcut, a decoy document, and both legitimate and malicious files. 

The malicious components utilized DLL sideloading to deploy a backdoor that communicated with Dropbox. Once communication was established, the backdoor executed commands, conducted reconnaissance and downloaded additional malware.

The cyber-spies cleverly used popular cloud services and websites such as GitHub, Dropbox, Quora, LiveJournal, and Yandex.Disk as command-and-control (C2) servers to manage their operations. This approach allowed them to direct their malware to download further payloads onto compromised systems.

Advanced malware tools 

Among the malware deployed was the GrewApacha trojan, which was linked to APT31 in past campaigns. The latest version of GrewApacha uses two C2 servers and obfuscates the server address in a Base64-encoded GitHub profile bio. 

In addition, the attackers deployed the CloudSorcerer backdoor, which Kaspersky previously reported in July. This backdoor has been updated to use LiveJournal and Quora as initial C2 servers.

PlugY implant as a new threat

Kaspersky’s analysis revealed that CloudSorcerer was used to download a new implant named PlugY. This implant connects to C2 servers via TCP and UDP protocols or named pipes and can execute a wide range of commands, including file manipulation, shell command execution, keystroke logging, screen monitoring, and clipboard snooping.

“Analysis of the implant is still ongoing, but we can conclude with a high degree of confidence that the code of the DRBControl (aka Clambling) backdoor was used to develop it,” Kaspersky’s researchers noted.

Implications of the EastWind campaign

The EastWind campaign highlights the collaboration among nation-state-backed cyber groups, with malware similarities observed between APT27 and APT29. 

Kaspersky’s findings highlight the complex and increasing number of cyberattacks, emphasizing the need for strong cybersecurity measures to protect sensitive information from such sophisticated attacks.

This incident serves as a stark reminder of cyber espionage’s persistent and evolving nature, urging governments and organizations worldwide to bolster their defenses against such threats.

Read more here.

Start your
journey today

  • Independent
  • Free
  • Transparent

About OA

Outsource Accelerator is the trusted source of independent information, advisory and expert implementation of Business Process Outsourcing (BPO)

The #1 outsourcing authority

Outsource Accelerator offers the world’s leading aggregator marketplace for outsourcing. It specifically provides the conduit between Philippines outsourcing suppliers and the businesses – clients – across the globe.

The Outsource Accelerator website has over 5,000 articles, 450+ podcast episodes, and a comprehensive directory with 4000+ BPO companies… all designed to make it easier for clients to learn about – and engage with – outsourcing.

About Derek Gallimore

Derek Gallimore has been in business for 20 years, outsourcing for over eight years, and has been living in Manila (the heart of global outsourcing) since 2014. Derek is the founder and CEO of Outsource Accelerator, and is regarded as a leading expert on all things outsourcing.

“Excellent service for outsourcing advice and expertise for my business.”

Learn more
Banner Image
Get 3 Free Quotes Verified Outsourcing Suppliers
3,000 firms.Just 2 minutes to complete.
SAVE UP TO
70% ON STAFF COSTS
Learn more

Connect with over 3,000 outsourcing services providers.

Banner Image

Transform your business with skilled offshore talent.

  • 3,000 firms
  • Simple
  • Transparent
Banner Image