Chinese Cyber Espionage Hackers Using USB Devices to Target Entities in Philippines

Share:

A threat actor with a suspected China nexus has been linked to a set of espionage attacks in the Philippines that primarily relies on USB devices as an initial infection vector.

Mandiant, which is part of Google Cloud, is tracking the cluster under its uncategorized moniker UNC4191. An analysis of the artifacts used in the intrusions indicates that the campaign dates as far back as September 2021.

“UNC4191 operations have affected a range of public and private sector entities primarily in Southeast Asia and extending to the U.S., Europe, and APJ,” researchers Ryan Tomcik, John Wolfram, Tommy Dacanay, and Geoff Ackerman said.

 

“However, even when targeted organizations were based in other locations, the specific systems targeted by UNC4191 were also found to be physically located in the Philippines.”

The reliance on infected USB drives to propagate the malware is unusual if not new. The Raspberry Robin worm, which has evolved into an initial access service for follow-on attacks, is known to use USB drives as an entry point.

Bild28

The threat intelligence and incident response firm said that the attacks led to the deployment of three new malware families dubbed MISTCLOAK, DARKDEW, BLUEHAZE, and Ncat, the latter of which is a command-line networking utility that’s used to create a reverse shell on the victim system.

MISTCLOAK, for its part, gets activated when a user plugs in a compromised removable device to a system, acting as a launchpad for an encrypted payload called DARKDEW that’s capable of infecting removable drives, effectively proliferating the infections.

Bild29

“The malware self-replicates by infecting new removable drives that are plugged into a compromised system, allowing the malicious payloads to propagate to additional systems and potentially collect data from air-gapped systems,” the researchers explained.

The DARKDEW dropper further serves to launch another executable (“DateCheck.exe”), a renamed version of a legitimate, signed application known as “Razer Chromium Render Process” that invokes the BLUEHAZE malware.

BLUEHAZE, a launcher written in C/C++, takes the attack chain forward by starting a copy of Ncat to create a reverse shell to a hardcoded command-and-control (C2) address.

“We believe this activity showcases Chinese operations to gain and maintain access to public and private entities for the purposes of intelligence collection related to China’s political and commercial interests,” the researchers said.

https://thehackernews.com/2022/11/chinese-cyber-espionage-hackers-using.html

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
9:44 am, Jun 1, 2025
weather icon 16°C
L: 15° | H: 17°
few clouds
Humidity: 64 %
Pressure: 1014 mb
Wind: 14 mph W
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 20%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:49 am
Sunset: 9:07 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
15° | 17°°C 0 mm 0% 14 mph 70 % 1014 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
11° | 21°°C 0 mm 0% 10 mph 82 % 1019 mb 0 mm/h
Tue Jun 03 10:00 pm
weather icon
11° | 17°°C 1 mm 100% 16 mph 92 % 1013 mb 0 mm/h
Wed Jun 04 10:00 pm
weather icon
9° | 19°°C 0 mm 0% 13 mph 83 % 1010 mb 0 mm/h
Thu Jun 05 10:00 pm
weather icon
11° | 15°°C 1 mm 100% 13 mph 97 % 1009 mb 0 mm/h
Today 10:00 am
weather icon
16° | 16°°C 0 mm 0% 10 mph 63 % 1014 mb 0 mm/h
Today 1:00 pm
weather icon
16° | 17°°C 0 mm 0% 12 mph 57 % 1014 mb 0 mm/h
Today 4:00 pm
weather icon
16° | 16°°C 0 mm 0% 14 mph 45 % 1013 mb 0 mm/h
Today 7:00 pm
weather icon
15° | 15°°C 0 mm 0% 12 mph 51 % 1013 mb 0 mm/h
Today 10:00 pm
weather icon
16° | 16°°C 0 mm 0% 9 mph 70 % 1014 mb 0 mm/h
Tomorrow 1:00 am
weather icon
13° | 13°°C 0 mm 0% 7 mph 82 % 1016 mb 0 mm/h
Tomorrow 4:00 am
weather icon
11° | 11°°C 0 mm 0% 6 mph 78 % 1017 mb 0 mm/h
Tomorrow 7:00 am
weather icon
12° | 12°°C 0 mm 0% 9 mph 72 % 1018 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€91,948.58
0.62%
Ethereum(ETH)
€2,208.62
-0.65%
Tether(USDT)
€0.88
0.01%
XRP(XRP)
€1.89
0.80%
Solana(SOL)
€135.60
-0.66%
USDC(USDC)
€0.88
0.00%
Dogecoin(DOGE)
€0.167087
0.26%
Shiba Inu(SHIB)
€0.000011
1.69%
Pepe(PEPE)
€0.000011
1.98%
Peanut the Squirrel(PNUT)
€0.228236
3.13%
Scroll to Top