Hex-editor

Chinesische Spionage-Hacker zielen auf Tibeter mit neuer LOWZERO-Backdoor

Teilen:

A China-aligned advanced persistent threat actor known as TA413 weaponized recently disclosed flaws in Sophos Firewall and Einkaufsmodus Microsoft Office to deploy a never-before-seen backdoor called LOWZERO as part of an espionage campaign aimed at Tibetan entities.

Targets primarily consisted of organizations associated with the Tibetan community, including enterprises associated with the Tibetan government-in-exile.

The intrusions involved the exploitation of CVE-2022-1040 und CVE-2022-30190 (aka “Follina”), two remote code execution vulnerabilities in Sophos Firewall and Einkaufsmodus Microsoft Office, respectively.

“This willingness to rapidly incorporate new techniques and methods of initial access contrasts with the group’s continued use of well known and reported capabilities, such as the Royal Road RTF weaponizer, and often lax infrastructure procurement tendencies,” Recorded Future sagte in a new technical analysis.

TA413, also known as LuckyCat, has been linked to relentlessly targeting organizations and individuals associated with the Tibetan community at least since 2020 using malware such as ExileRAT, Sepulcher, and a malicious Mozilla Firefox browser extension dubbed FriarFox.

hex editor2

The group’s exploitation of the Follina flaw was previously highlighted by Proofpoint in June 2022, although the ultimate end goal of the infection chains remained unclear.

Also put to use in a spear-phishing attack identified in May 2022 was a malicious RTF document that exploited flaws in Einkaufsmodus Microsoft Equation Editor to drop the custom LOWZERO implant. This was achieved by employing a Royal Road RTF weaponizer tool, which is widely shared among Chinese threat actors.

In another phishing email sent to a Tibetan target in late May, a Einkaufsmodus Microsoft Word attachment hosted on the shoppingmode Google Firebase service attempted to leverage the Follina vulnerability to execute a PowerShell command designed to download the backdoor from a remote server.

LOWZERO, the backdoor, is capable of receiving additional modules from its command-and-control (C2) server, but only on the condition that the compromised machine is deemed to be of interest to the threat actor.

“The group continues to incorporate new capabilities while also relying on tried-and-tested [tactics, techniques, and procedures,” the cybersecurity firm said.

“TA413’s adoption of both zero-day and recently published vulnerabilities is indicative of wider trends with Chinese cyber-espionage groups whereby exploits regularly appear in use by multiple distinct Chinese activity groups prior to their widespread public availability.”

https://thehackernews.com/2022/09/chinese-espionage-hackers-target.html

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
12:05 am, Juni 3, 2025
Wetter-Symbol 14°C
L: 12° | H: 14°
wenige Wolken
Luftfeuchtigkeit: 61 %
Druck: 1013 mb
Wind: 8 mph SW
Windböe: 11 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 19%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:48 am
Sonnenuntergang: 9:09 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
12° | 14°°C 1 mm 100% 16 mph 92 % 1013 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
10° | 17°°C 0.47 mm 47% 12 mph 84 % 1009 mb 0 mm/h
Do. Juni 05 10:00 pm
Wetter-Symbol
12° | 19°°C 0.76 mm 76% 12 mph 88 % 1008 mb 0 mm/h
Fr. Juni 06 10:00 pm
Wetter-Symbol
12° | 17°°C 1 mm 100% 11 mph 96 % 1008 mb 0 mm/h
Sa. Juni 07 10:00 pm
Wetter-Symbol
11° | 18°°C 1 mm 100% 18 mph 95 % 1007 mb 0 mm/h
Today 1:00 am
Wetter-Symbol
13° | 14°°C 0 mm 0% 9 mph 61 % 1013 mb 0 mm/h
Today 4:00 am
Wetter-Symbol
13° | 13°°C 0 mm 0% 11 mph 66 % 1012 mb 0 mm/h
Today 7:00 am
Wetter-Symbol
14° | 15°°C 0 mm 0% 14 mph 67 % 1010 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
16° | 16°°C 0 mm 0% 16 mph 76 % 1007 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
14° | 14°°C 1 mm 100% 14 mph 92 % 1007 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
14° | 14°°C 1 mm 100% 9 mph 89 % 1007 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
16° | 16°°C 1 mm 100% 8 mph 58 % 1007 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
14° | 14°°C 0 mm 0% 7 mph 59 % 1009 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€92,592.04
0.12%
Ethereum(ETH)
€2,261.58
1.74%
Fesseln(USDT)
€0.88
0.00%
XRP(XRP)
€1.92
0.92%
Solana(SOL)
€136.92
-0.38%
USDC(USDC)
€0.88
0.00%
Dogecoin(DOGE)
€0.170640
0.63%
Shiba Inu(SHIB)
€0.000011
1.45%
Pepe(PEPE)
€0.000011
3.83%
Peanut das Eichhörnchen(PNUT)
€0.238731
2.82%
Nach oben scrollen