Security News > 2021 > January > Ransomware Attacks Linked to Chinese Cyberspies

Ransomware Attacks Linked to Chinese Cyberspies
2021-01-05 04:59

China-linked cyber-espionage group APT27 is believed to have orchestrated recent ransomware attacks, including one where a legitimate Windows tool was used to encrypt the victim's files.

More recently the cyberspies appear to have switched to financially-motivated attacks.

The attack, boutique cybersecurity services company Profero explains in a detailed report, had similarities in code and TTPs with the DRBControl campaign that Trend Micro linked in early 2020 to Chinese APT groups APT27 and Winnti.

During their investigation of the ransomware attack, Security Joes and Profero researchers identified a backdoor they linked to DRBControl, as well as an ASPXSpy webshell, a PlugX sample, and Mimikatz.

Also unusual for a ransomware attack was the use of BitLocker, a local tool, instead of a ransomware family.

This does not appear to be a singular ransomware incident attributed to the Chinese hacking group: in late November 2020, Positive Technologies detailed an APT27 attack in which the Polar ransomware was used.


News URL

http://feedproxy.google.com/~r/Securityweek/~3/5SQHkMJYeZQ/ransomware-attacks-linked-chinese-cyberspies