Site icon Back End News

APT groups increase cyberattacks in Asia

Image by Gerd Altman | Pixabay

Advanced persistent threat (APT) activity in the first quarter of 2020 demonstrated that infection and distribution of malware via mobile platforms is on the rise, with some campaigns focusing solely on mobile.

At the same time, activity in Asia is growing, particularly among new actors, while traditional advanced actors are becoming much more selective in how they carry out their operations. These and other APT trends from across the world are covered in Kaspersky’s latest quarterly threat intelligence summary.

A three-month APT trends summary for the last quarter has come from Kaspersky’s private threat intelligence research, as well as other sources that cover the major developments that the company’s researchers believe everyone should be aware of.


PhantomLance hacking campaign hides malware in Google Play

Report: Cyberspying groups target gov’ts, military in SEA


APT findings in Q1 2020 confirmed that activity in Asia keeps growing with a variety of attacks spurring across Southeast Asia, Korea, and Japan. Kaspersky has seen new APT groups with creative and sometimes low-budget campaigns emerging and establishing their presence alongside well-known actors, such as CactusPete and Lazarus.

Mobile platforms

The interest in mobile platforms as a means of attack and dissemination of malware distribution is expected to grow. Kaspersky recently shared reports on a number of campaigns that were strongly focused on mobile attacks, including a LightSpy water-holing campaign that targeted users in Hong Kong and exploited iOS and Android devices, as well as an Android espionage campaign named PhantomLance targeting victims in South East Asia. Notably, both of these campaigns successfully utilized various online platforms, from forums and social media to the Google Play app store, demonstrating a smart approach to distributing malware.

APT actors targeting Asia are not the only ones that developed mobile implants. For instance, TransparentTribe carried out a campaign with a new module named “USBWorm”, targeting victims in Afghanistan and India, developed a new implant designed to infect Android devices. The malware used is a modified version of the “AhMyth” Android RAT, an open-source piece of malware available on GitHub.

COVID-19 pandemic

Additionally, the COVID-19 pandemic has been used by different APT groups since mid-March to lure in victims but does not signify a meaningful change in terms of TTPs other than a popular topic being leveraged to capitalize on vulnerable users. The topic was used by APT actors such as Kimsuky, Hades, and DarkHotel.

The Q1 APT Trends report summarizes the findings of Kaspersky’s subscriber-only threat intelligence reports, which also include Indicators of Compromise (IOC) data and YARA rules to assist in forensics and malware hunting. For more information, please contact: intelreports@kaspersky.com

In order to avoid falling victim to a targeted attack by a known or unknown threat actor, Kaspersky researchers recommend implementing the following measures:

Exit mobile version