Budworm Hackers Resurface with New Espionage Attacks Aimed at U.S. Organization

Share:

An advanced persistent threat (APT) actor known as Budworm targeted a U.S.-based entity for the first time in more than six years, according to latest research.

The attack was aimed at an unnamed U.S. state legislature, the Symantec Threat Hunter team, part of Broadcom Software, said in a report shared with The Hacker News.

Other “strategically significant” intrusions mounted over the past six months were directed against a government of a Middle Eastern country, a multinational electronics manufacturer, and a hospital in South East Asia.

Budworm, also called APT27, Bronze Union, Emissary Panda, Lucky Mouse, and Red Phoenix, is a threat actor that’s believed to operate on behalf of China through attacks that leverage a mix of custom and openly available tools to exfiltrate information of interest.

“Bronze Union maintains a high degree of operational flexibility in order to adapt to the environments it operates in,” Secureworks notes in a profile of the nation-state group, pointing out its ability to “maintain access to sensitive systems over a long period of time.”

A prominent backdoor attributed to the adversarial collective is HyperBro, which has been put to use since at least 2013 and is in continuous development. Its other tools include PlugXSysUpdate, and the China Chopper web shell.

The latest set of attacks are no different, with the threat actor leveraging Log4Shell flaws to compromise servers and install web shells, ultimately paving the way for the deployment of HyperBro, PlugX, Cobalt Strike, and credential dumping software.

The development marks the second time Budworm has been linked to an attack on a U.S. entity. Earlier this month, the U.S. government revealed that multiple nation-state hacking groups breached a defense sector organization using ProxyLogon flaws in Microsoft Exchange Server to drop China Chopper and HyperBro.

“In more recent years, the group’s activity appears to have been largely focused on Asia, the Middle East, and Europe,” the researchers said. “A resumption of attacks against U.S.-based targets could signal a change in focus for the group.”

https://thehackernews.com/2022/10/budworm-hackers-resurface-with-new.html

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
9:57 am, Jul 7, 2025
weather icon 14°C
L: 14° | H: 16°
broken clouds
Humidity: 84 %
Pressure: 1011 mb
Wind: 9 mph N
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 75%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:52 am
Sunset: 9:18 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
14° | 16°°C 1 mm 100% 11 mph 85 % 1014 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
13° | 24°°C 0.2 mm 20% 11 mph 76 % 1020 mb 0 mm/h
Wed Jul 09 10:00 pm
weather icon
15° | 24°°C 0.35 mm 35% 5 mph 68 % 1023 mb 0 mm/h
Thu Jul 10 10:00 pm
weather icon
18° | 31°°C 0 mm 0% 7 mph 75 % 1024 mb 0 mm/h
Fri Jul 11 10:00 pm
weather icon
19° | 29°°C 0 mm 0% 10 mph 61 % 1023 mb 0 mm/h
Today 10:00 am
weather icon
15° | 16°°C 1 mm 100% 11 mph 85 % 1011 mb 0 mm/h
Today 1:00 pm
weather icon
17° | 21°°C 0.7 mm 70% 11 mph 74 % 1011 mb 0 mm/h
Today 4:00 pm
weather icon
19° | 21°°C 0 mm 0% 10 mph 55 % 1012 mb 0 mm/h
Today 7:00 pm
weather icon
21° | 21°°C 0 mm 0% 6 mph 41 % 1013 mb 0 mm/h
Today 10:00 pm
weather icon
17° | 17°°C 0 mm 0% 10 mph 51 % 1014 mb 0 mm/h
Tomorrow 1:00 am
weather icon
16° | 16°°C 0.2 mm 20% 10 mph 72 % 1015 mb 0 mm/h
Tomorrow 4:00 am
weather icon
13° | 13°°C 0 mm 0% 11 mph 76 % 1015 mb 0 mm/h
Tomorrow 7:00 am
weather icon
13° | 13°°C 0 mm 0% 9 mph 73 % 1017 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€92,533.29
0.90%
Ethereum(ETH)
€2,190.87
2.62%
Tether(USDT)
€0.85
-0.01%
XRP(XRP)
€1.93
1.10%
Solana(SOL)
€129.55
3.40%
USDC(USDC)
€0.85
0.00%
Dogecoin(DOGE)
€0.146413
5.23%
Shiba Inu(SHIB)
€0.000010
2.14%
Pepe(PEPE)
€0.000008
4.23%
Scroll to Top