OceanLotus APT-C-00 Campaign Unleashes a Stealthy New Arsenal

OceanLotus APT-C-00 campaign exploiting Windows registry and deploying stealthy malware

An ordinary email attachment can serve as the perilous gateway to a sophisticated attack chain when a meticulously crafted toolkit lurks behind a seemingly benign document. Recently, analysts at 360 Advanced Threat Research uncovered a novel operation orchestrated by APT-C-00. This notorious threat actor, also widely recognized as OceanLotus and APT32, has returned with enhanced vigor. In this latest endeavor, the collective deployed malicious disk images, circumvented traditional security mechanisms, and seamlessly established remote access to compromised systems.

Deceptive Deliveries and Ingenious Disguises

The assailants disseminated targeted spear-phishing emails containing malicious archives. These digital payloads harbored decoy documents alongside a weaponized IMG disk image. Concealed within this image was an LNK file deliberately masquerading as a standard Microsoft Word document. Upon execution, the file unleashed a script that simultaneously opened a legitimate decoy document to avert suspicion and seamlessly copied the attack components into the host’s AppData directory. Consequently, these malicious files masqueraded flawlessly as conventional software.

Subsequently, the group employed DLL Sideloading, a pernicious technique wherein a legitimate application is exploited to load a malicious library. Specifically, the executable Analyzer.exe loaded mglobal.dll. This clandestine library then decrypted subsequent attack stages and executed them directly within the system’s volatile memory, leaving virtually no footprint on the hard drive.

Advanced Persistence and Evasion Tactics

A pivotal element of this newly discovered schema involves the establishment of system persistence. Contingent upon the active defensive posture of the host machine, the malware dynamically selected disparate methods to maintain its foothold. In the absence of active security measures, it simply embedded itself into the Windows startup sequence via the Run registry key.

Conversely, when confronted with active protective software, APT-C-00 resorted to a far more clandestine technique. The malware generated an NTUSER.MAN file containing tailored Windows user profile configurations. To forge this configuration file, the adversaries utilized an open-source utility known as HiveSwarming.exe, which elegantly transformed an exported registry hive into a binary registry file. This sophisticated approach facilitated the execution of malicious code upon user login without ever requiring elevated administrative privileges.

Formidable Anti-Analysis Capabilities

Furthermore, as detailed in a recent threat intelligence analysis published by 360 Advanced Threat Research, the malicious library incorporated a formidable array of anti-analysis mechanisms. The underlying code meticulously checked for the presence of debuggers, hardware breakpoints, and artifacts indicative of a forensic research environment. Upon detecting any suspicious conditions, the program would instantly terminate its execution, thereby profoundly complicating the analysis of the specimen by security professionals.

Command, Control, and Exfiltration

Following successful persistence, the malware deployed a sophisticated remote access trojan (RAT). This insidious code harvested comprehensive intelligence regarding the host machine, the active user, the operating system architecture, and currently running processes. Subsequently, it exfiltrated this valuable data to the attackers’ command and control (C2) servers.

In return, the command server could issue real-time directives to execute specific programs, initiate a hidden command-line interface, upload or download sensitive files, alter connection parameters, and fetch supplementary malicious modules.

Cybersecurity experts observe that this novel campaign illustrates a profound evolution in APT-C-00’s arsenal, particularly regarding its stealth capabilities and the evasion of modern defensive mechanisms. To mitigate such formidable risks, organizations are strongly advised to refrain from opening unknown archives and email attachments. Moreover, users must meticulously verify the provenance of all documents and deploy advanced security solutions capable of detecting anomalous activities within the registry, startup sequences, and system memory.

Support Our Threat Intelligence

If you find our technology report and cybersecurity news helpful, consider supporting our work.

Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Leave a Reply