Hackers breach ISP to poison software updates with malware

Share:

A Chinese hacking group tracked as StormBamboo has compromised an undisclosed internet service provider (ISP) to poison automatic software updates with malware.

Also tracked as Evasive Panda, Daggerfly, and StormCloud, this cyber-espionage group has been active since at least 2012, targeting organizations across mainland China, Hong Kong, Macao, Nigeria, and various Southeast and East Asian countries.

On Friday, Volexity threat researchers revealed that the Chinese cyber-espionage gang had exploited insecure HTTP software update mechanisms that didn’t validate digital signatures to deploy malware payloads on victims’ Windows and macOS devices.

“When these applications went to retrieve their updates, instead of installing the intended update, they would install malware, including but not limited to MACMA and POCOSTICK (aka MGBot),” cybersecurity company Volexity explained in a report published on Friday.

To do that, the attackers intercepted and modified victims’ DNS requests and poisoned them with malicious IP addresses. This delivered the malware to the targets’ systems from StormBamboo’s command-and-control servers without requiring user interaction.

For instance, they took advantage of 5KPlayer requests to update the youtube-dl dependency to push a backdoored installer hosted on their C2 servers.

​After compromising the target’s systems, the threat actors installed a malicious Google Chrome extension (ReloadText), which allowed them to harvest and steal browser cookies and mail data.

“Volexity observed StormBamboo targeting multiple software vendors, who use insecure update workflows, using varying levels of complexity in their steps for pushing malware,” the researchers added.

“Volexity notified and worked with the ISP, who investigated various key devices providing traffic-routing services on their network. As the ISP rebooted and took various components of the network offline, the DNS poisoning immediately stopped.”

In April 2023, ESET threat researchers also observed the hacking group deploying the Pocostick (MGBot) Windows backdoor by abusing the automatic update mechanism for the Tencent QQ messaging application in attacks targeting international NGOs (non-governmental organizations).

Almost a year later, in July 2024, Symantec’s threat hunting team spotted the Chinese hackers targeting an American NGO in China and multiple organizations in Taiwan with new Macma macOS backdoor and Nightdoor Windows malware versions.

In both cases, although the attackers’ skill was evident, the researchers believed it was either a supply chain attack or an adversary-in-the-middle (AITM) attack but weren’t able to pin down the exact attack method.

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
1:10 am, Jan 22, 2025
weather icon 3°C
L: 2° | H: 4°
mist
Humidity: 91 %
Pressure: 1008 mb
Wind: 2 mph
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 100%
Rain Chance: 0%
Visibility: 5 km
Sunrise: 7:52 am
Sunset: 4:31 pm
DailyHourly
Daily ForecastHourly Forecast
Today 9:00 pm
weather icon
2° | 4°°C 1 mm 100% 5 mph 95 % 1008 mb 0 mm/h
Tomorrow 9:00 pm
weather icon
2° | 8°°C 1 mm 100% 17 mph 94 % 1005 mb 0 mm/h
Fri Jan 24 9:00 pm
weather icon
6° | 10°°C 1 mm 100% 24 mph 91 % 1004 mb 0 mm/h
Sat Jan 25 9:00 pm
weather icon
4° | 6°°C 0.89 mm 89% 8 mph 86 % 1012 mb 0 mm/h
Sun Jan 26 9:00 pm
weather icon
5° | 8°°C 0.2 mm 20% 14 mph 86 % 1011 mb 0 mm/h
Today 3:00 am
weather icon
3° | 3°°C 0 mm 0% 3 mph 92 % 1008 mb 0 mm/h
Today 6:00 am
weather icon
3° | 3°°C 0.8 mm 80% 3 mph 95 % 1006 mb 0 mm/h
Today 9:00 am
weather icon
4° | 4°°C 1 mm 100% 3 mph 95 % 1004 mb 0 mm/h
Today 12:00 pm
weather icon
4° | 4°°C 0.8 mm 80% 4 mph 91 % 1003 mb 0 mm/h
Today 3:00 pm
weather icon
4° | 4°°C 0 mm 0% 5 mph 89 % 1002 mb 0 mm/h
Today 6:00 pm
weather icon
3° | 3°°C 0 mm 0% 3 mph 87 % 1003 mb 0 mm/h
Today 9:00 pm
weather icon
2° | 2°°C 0 mm 0% 4 mph 95 % 1004 mb 0 mm/h
Tomorrow 12:00 am
weather icon
2° | 2°°C 0 mm 0% 3 mph 94 % 1004 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€101,666.87
4.38%
Ethereum(ETH)
€3,218.75
3.63%
XRP(XRP)
€3.07
1.10%
Tether(USDT)
€0.96
0.13%
Solana(SOL)
€242.63
6.43%
Dogecoin(DOGE)
€0.356671
7.44%
USDC(USDC)
€0.96
0.00%
Shiba Inu(SHIB)
€0.000020
4.03%
Pepe(PEPE)
€0.000015
3.75%
Peanut the Squirrel(PNUT)
€0.364163
1.01%
Scroll to Top