The Chinese state-backed group TAG-74 is known for conducting intelligence collection on organizations in the following countries:-
The TAG-74 utilizes .chm files to trigger a DLL search order hijack execution chain and deploy malware for loading a customized ReVBShell VBScript backdoor.
Cybersecurity analysts at Recorded Future’s Insikt Group recently analyzed a Chinese state-sponsored cyber-espionage campaign, attributed to TAG-74, targeting South Korean academic, political, and government bodies, primarily linked to Chinese military intelligence.
This complete assessment primarily relies on the past targeting behavior and PLA Northern Theater Command-aligned actors’ usual areas of operation.
Attend the Live DDoS Website & API Attack Simulation webinar to gain knowledge on various types of attacks and how to prevent them.
TAG-74’s infection chain, observed since 2020, relies on spearphishing via .chm files containing three main components.
Here below, we have mentioned those three key components of .chm files:-
The HTML file initiates a DLL search order hijack chain by executing hh.exe and vias.exe via bitmap shortcut objects; simulating mouse clicks on the objects in sequence.
The loaded malicious DLL generates and runs a customized ReVBShell VBscript backdoor in %TEMP%.
TAG-74 employs South Korean VPS infrastructure from various providers and dynamic DNS domains for C2, often impersonating South Korean organizations.
Here below, we have mentioned all the IP addresses observed in use by TAG-74:-
TAG-74 uses a modified ReVBShell backdoor that sleeps for a set duration after a C2 server NOOP response. TAG-74 typically alters the sleep time from 5 seconds to 5 minutes, with added C2 command capability for adjusting the interval.
Insikt Group spotted Bisonal samples communicating with TAG-74’s C2 infrastructure, suggesting it’s a follow-on malware family with enhanced features beyond ReVBShell.
Bisonal is an exclusive Chinese state-sponsored backdoor that has been active since 2010 in the following countries:-
Here below, we have mentioned all the domains that TAG-74 spoofs:-
Here below, we have mentioned all the mitigations offered by the cybersecurity researchers-
Keep informed about the latest Cyber Security News by following us on Google News, Linkedin, Twitter, and Facebook.
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…