A sophisticated exploit kit named MOONSHINE has been actively targeting Android messaging apps to implant backdoors on users’ devices.
This toolkit, under continuous monitoring since 2019, has recently been found to have an upgraded version with enhanced capabilities and protections against security analysis.
Earth Minotaur, the threat actor behind these attacks, primarily targets Tibetan and Uyghur communities. Their modus operandi involves:-
Security experts at Trend Micro observed that the attack links are disguised as legitimate content, including government announcements, COVID-19 news, religious information, and travel updates.
Free Webinar on Best Practices for API vulnerability & Penetration Testing: Free Registration
The upgraded MOONSHINE kit employs several sophisticated techniques:-
The kit can target multiple Android applications, including WeChat, Facebook, Line, and QQ.
The primary payload of the MOONSHINE kit is the DarkNimbus backdoor, which has both Android and Windows versions:-
Android Version Features:-
Windows Version Features:-
Both versions use similar command structures and communicate with command and control (C&C) servers for data exfiltration and receiving instructions.
While Earth Minotaur is believed to be a distinct threat actor, the MOONSHINE exploit kit has been linked to multiple Chinese operations:-
The widespread use of MOONSHINE and related tools among Chinese threat actors suggests a complex ecosystem of shared resources and techniques in cyber espionage operations.
To protect against such attacks, users should exercise caution when clicking on links in suspicious messages and keep their applications updated to the latest versions to mitigate known vulnerabilities.
Analyse Real-World Malware & Phishing Attacks With ANY.RUN - Get up to 3 Free Licenses
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…