A sophisticated Chinese APT group, which is tracked as LuoYu, has been detected recently by the security experts at Kaspersky Lab. A malicious Windows tool named WinDealer was observed being used by this Chinese APT group.
The malicious Windows tool, WinDealer is primarily spread through the stealthy malicious mechanism known as a man-on-the-side attack by placing the malicious payloads in place of legitimate app updates.
Threat actors use this form of propagation to monitor the network traffic of their target to determine whether applications linked to popular Asian social apps are requesting app updates.
Once they find the legitmate app update, they immediately replace the update with malicious WinDealer installers.
When WinDealer is deployed, it assists attackers in their attacks and provides multiple sophisticated capabilities. And here we have mentioned all the capabilities offered by WinDealer:-
Since 2008, LuoYu has been operating in China, and it has mainly focused on Chinese targets like:-
The WinDealer server selects a random IP address from between 48,000 IP addresses provided by ChinaNet (AS4134) from the Xizang and Guizhou provinces and connects to it.
Here’s what Kaspersky senior security researcher Suguru Ishimaru stated:-
“Man-on-the-side-attacks are extremely destructive as the only condition needed to attack a device is for it to be connected to the internet. No matter how the attack has been carried out, the only way for potential victims to defend themselves is to remain extremely vigilant and have robust security procedures.”
Moreover, GReAT (Global Research and Analysis Team) from Kaspersky has also detected some infections in other countries, including:-
The operators of LuoYu APT group have previously been observed to target not only Windows devices using WinDealer, but also macOS, Linux, and Android devices as well, with malware called Demsty and SpyDealer.
You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity and hacking news updates.
Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…
The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…
CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…
Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…
You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…
Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…