• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
chinese hackers using sugargh0st rat to target south korea and

Chinese Hackers Using SugarGh0st RAT to Target South Korea and Uzbekistan

You are here: Home / General Cyber Security News / Chinese Hackers Using SugarGh0st RAT to Target South Korea and Uzbekistan
December 1, 2023

A suspected Chinese-speaking danger actor has been attributed to a destructive marketing campaign that targets the Uzbekistan Ministry of Foreign Affairs and South Korean buyers with a distant entry trojan known as SugarGh0st RAT.

The action, which commenced no later on than August 2023, leverages two different an infection sequences to provide the malware, which is a customized variant of Gh0st RAT (aka Farfli).

It comes with options to “aid the remote administration duties as directed by the C2 and modified conversation protocol based mostly on the similarity of the command construction and the strings utilized in the code,” Cisco Talos researchers Ashley Shen and Chetan Raghuprasad said.

✔ Approved Seller From Our Partners
Mullvad VPN Discount

Protect your privacy by Mullvad VPN. Mullvad VPN is one of the famous brands in the security and privacy world. With Mullvad VPN you will not even be asked for your email address. No log policy, no data from you will be saved. Get your license key now from the official distributor of Mullvad with discount: SerialCart® (Limited Offer).

➤ Get Mullvad VPN with 12% Discount


The attacks commence with a phishing email bearing decoy files, opening which activates a multi-phase procedure that sales opportunities to the deployment of SugarGh0st RAT.

Cybersecurity

The decoy documents are integrated inside a intensely obfuscated JavaScript dropper that is contained in a Windows Shortcut file embedded in the RAR archive email attachment.

“The JavaScript decodes and drops the embedded files into the %TEMP% folder, which include a batch script, a custom-made DLL loader, an encrypted SugarGh0st payload, and a decoy doc,” the researchers claimed.

The decoy doc is then exhibited to the victim, although, in the history, the batch script operates the DLL loader, which, in change, side-masses it with a copied variation of a respectable Windows executable termed rundll32.exe to decrypt and start the SugarGh0st payload.

A next variant of the attack also starts with a RAR archive that contains a malicious Windows Shortcut file that masquerades as a entice, with the big difference becoming that the JavaScript leverages DynamicWrapperX to operate shellcode that launches SugarGh0st.

SugarGh0st, a 32-little bit dynamic-website link library (DLL) created in C++, establishes get hold of with a tricky-coded command-and-regulate (C2) area, enabling it to transmit method metadata to the server, launch a reverse shell, and operate arbitrary commands.

It can also enumerate and terminate procedures, acquire screenshots, perform file functions, and even clear the machine’s function logs in an try to go over its tracks and evade detection.

The campaign’s back links to China stem from Gh0st RAT’s Chinese origins and the truth that the totally useful backdoor has been broadly adopted by Chinese menace actors over the decades, in part pushed by the release of its source code in 2008. A different smoking cigarettes gun evidence is the use of Chinese names in the “final modified by” area in the metadata of the decoy files.

Cybersecurity

“The Gh0st RAT malware is a mainstay in the Chinese threat actors’ arsenal and has been energetic due to the fact at least 2008,” the scientists said.

“Chinese actors also have a heritage of targeting Uzbekistan. The targeting of the Uzbekistan Ministry of Foreign Affairs also aligns with the scope of Chinese intelligence exercise abroad.”

The growth comes as Chinese state-sponsored groups have also increasingly specific Taiwan in the very last 6 months, with the attackers repurposing residential routers to mask their intrusions, in accordance to Google.

Identified this post interesting? Follow us on Twitter  and LinkedIn to browse extra unique material we publish.


Some elements of this short article are sourced from:
thehackernews.com

Previous Post: «discover how gcore thwarted powerful 1.1tbps and 1.6tbps ddos attacks Discover How Gcore Thwarted Powerful 1.1Tbps and 1.6Tbps DDoS Attacks
Next Post: Qakbot Takedown Aftermath: Mitigations and Protecting Against Future Threats qakbot takedown aftermath: mitigations and protecting against future threats»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.