Chinese Cyber Espionage Hackers Using USB Devices to Target Entities in Philippines

Share:

A threat actor with a suspected China nexus has been linked to a set of espionage attacks in the Philippines that primarily relies on USB devices as an initial infection vector.

Mandiant, which is part of Google Cloud, is tracking the cluster under its uncategorized moniker UNC4191. An analysis of the artifacts used in the intrusions indicates that the campaign dates as far back as September 2021.

“UNC4191 operations have affected a range of public and private sector entities primarily in Southeast Asia and extending to the U.S., Europe, and APJ,” researchers Ryan Tomcik, John Wolfram, Tommy Dacanay, and Geoff Ackerman said.

 

“However, even when targeted organizations were based in other locations, the specific systems targeted by UNC4191 were also found to be physically located in the Philippines.”

The reliance on infected USB drives to propagate the malware is unusual if not new. The Raspberry Robin worm, which has evolved into an initial access service for follow-on attacks, is known to use USB drives as an entry point.

Bild28

The threat intelligence and incident response firm said that the attacks led to the deployment of three new malware families dubbed MISTCLOAK, DARKDEW, BLUEHAZE, and Ncat, the latter of which is a command-line networking utility that’s used to create a reverse shell on the victim system.

MISTCLOAK, for its part, gets activated when a user plugs in a compromised removable device to a system, acting as a launchpad for an encrypted payload called DARKDEW that’s capable of infecting removable drives, effectively proliferating the infections.

Bild29

“The malware self-replicates by infecting new removable drives that are plugged into a compromised system, allowing the malicious payloads to propagate to additional systems and potentially collect data from air-gapped systems,” the researchers explained.

The DARKDEW dropper further serves to launch another executable (“DateCheck.exe”), a renamed version of a legitimate, signed application known as “Razer Chromium Render Process” that invokes the BLUEHAZE malware.

BLUEHAZE, a launcher written in C/C++, takes the attack chain forward by starting a copy of Ncat to create a reverse shell to a hardcoded command-and-control (C2) address.

“We believe this activity showcases Chinese operations to gain and maintain access to public and private entities for the purposes of intelligence collection related to China’s political and commercial interests,” the researchers said.

https://thehackernews.com/2022/11/chinese-cyber-espionage-hackers-using.html

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
11:41 pm, Jun 2, 2025
weather icon 14°C
L: 12° | H: 14°
few clouds
Humidity: 60 %
Pressure: 1013 mb
Wind: 9 mph SSW
Wind Gust: 13 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 19%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:48 am
Sunset: 9:09 pm
DailyHourly
Daily ForecastHourly Forecast
Tomorrow 10:00 pm
weather icon
12° | 14°°C 1 mm 100% 16 mph 92 % 1013 mb 0 mm/h
Wed Jun 04 10:00 pm
weather icon
10° | 17°°C 0.47 mm 47% 12 mph 84 % 1009 mb 0 mm/h
Thu Jun 05 10:00 pm
weather icon
12° | 19°°C 0.76 mm 76% 12 mph 88 % 1008 mb 0 mm/h
Fri Jun 06 10:00 pm
weather icon
12° | 17°°C 1 mm 100% 11 mph 96 % 1008 mb 0 mm/h
Sat Jun 07 10:00 pm
weather icon
11° | 18°°C 1 mm 100% 18 mph 95 % 1007 mb 0 mm/h
Tomorrow 1:00 am
weather icon
13° | 14°°C 0 mm 0% 9 mph 60 % 1013 mb 0 mm/h
Tomorrow 4:00 am
weather icon
13° | 14°°C 0 mm 0% 11 mph 65 % 1012 mb 0 mm/h
Tomorrow 7:00 am
weather icon
14° | 15°°C 0 mm 0% 14 mph 66 % 1010 mb 0 mm/h
Tomorrow 10:00 am
weather icon
16° | 16°°C 0 mm 0% 16 mph 76 % 1007 mb 0 mm/h
Tomorrow 1:00 pm
weather icon
14° | 14°°C 1 mm 100% 14 mph 92 % 1007 mb 0 mm/h
Tomorrow 4:00 pm
weather icon
14° | 14°°C 1 mm 100% 9 mph 89 % 1007 mb 0 mm/h
Tomorrow 7:00 pm
weather icon
16° | 16°°C 1 mm 100% 8 mph 58 % 1007 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
14° | 14°°C 0 mm 0% 7 mph 59 % 1009 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€92,563.13
0.07%
Ethereum(ETH)
€2,258.39
1.44%
Tether(USDT)
€0.88
0.00%
XRP(XRP)
€1.93
1.09%
Solana(SOL)
€136.68
-0.57%
USDC(USDC)
€0.88
0.00%
Dogecoin(DOGE)
€0.171022
0.84%
Shiba Inu(SHIB)
€0.000011
1.46%
Pepe(PEPE)
€0.000011
3.80%
Peanut the Squirrel(PNUT)
€0.240725
3.33%
Scroll to Top