Security News > 2022 > October > Researchers Uncover Stealthy Techniques Used by Cranefly Espionage Hackers
A recently discovered hacking group known for targeting employees dealing with corporate transactions has been linked to a new backdoor called Danfuan.
This hitherto undocumented malware is delivered via another dropper called Geppei, researchers from Symantec, by Broadcom Software, said in a report shared with The Hacker News.
The dropper "Is being used to install a new backdoor and other tools using the novel technique of reading commands from seemingly innocuous Internet Information Services logs," the researchers said.
"The commands read by Geppei contain malicious encoded.ashx files," the researchers noted.
"These files are saved to an arbitrary folder determined by the command parameter and they run as backdoors."
"The use of a novel technique and custom tools, as well as the steps taken to hide traces of this activity on victim machines, indicate that Cranefly is a fairly skilled threat actor," the researchers concluded.
News URL
Related news
- Researchers Uncover 4-Month Cyberattack on U.S. Firm Linked to Chinese Hackers (source)
- Hackers Weaponize Visual Studio Code Remote Tunnels for Cyber Espionage (source)
- Researchers Uncover Espionage Tactics of China-Based APT Groups in Southeast Asia (source)
- Russia-Linked Hackers Target Kazakhstan in Espionage Campaign with HATVIBE Malware (source)