Home Security Darkish Pink APT Group Leverages TelePowerBot and KamiKakaBot in Subtle Assaults

Darkish Pink APT Group Leverages TelePowerBot and KamiKakaBot in Subtle Assaults

by crpt os


May 31, 2023Ravie LakshmananAdvanced Persistent Threat

The threat actor known as Dark Pink has been linked to five new attacks aimed at various entities in Belgium, Brunei, Indonesia, Thailand, and Vietnam between February 2022 and April 2023.

This includes educational entities, government agencies, military bodies, and non-profit organizations, indicating the adversarial crew’s continued focus on high-value targets.

Dark Pink, also called Saaiwc Group, is an advanced persistent threat (APT) actor believed to be of Asia-Pacific origin, with attacks targeting entities primarily located in East Asia and, to a lesser extent, in Europe.

The group employs a set of custom malware tools such as TelePowerBot and KamiKakaBot that provide various functions to exfiltrate sensitive data from compromised hosts.

“The group uses a range of sophisticated custom tools, deploys multiple kill chains relying on spear-phishing emails,” Group-IB security researcher Andrey Polovinkin said in a technical report shared with The Hacker News.

“Once the attackers gain access to a target’s network, they use advanced persistence mechanisms to stay undetected and maintain control over the compromised system.”

The findings also illustrate some key modifications to the Dark Pink attack sequence to impede analysis as well as accommodate improvements to KamiKakaBot, which executes commands from a threat actor-controlled Telegram channel via a Telegram bot.

Dark Pink

The latest version, notably, splits its functionality into two distinct parts: One for controlling devices and the other for harvesting valuable information.

The Singapore-headquartered company said it also identified a new GitHub account associated with the account that contains PowerShell scripts, ZIP archives, and custom malware which were committed between January 9, 2023, and April 11, 2023.

Besides using Telegram for command-and-control, Dark Pink has been observed exfiltrating stolen data over HTTP using a service called webhook[.]site. Another notable aspect is the use of an Microsoft Excel add-in to ensure the persistence of TelePowerBot within the infected host.

UPCOMING WEBINAR

Zero Trust + Deception: Learn How to Outsmart Attackers!

Discover how Deception can detect advanced threats, stop lateral movement, and enhance your Zero Trust strategy. Join our insightful webinar!

Save My Seat!

“With webhook[.]site, it is possible to set up temporary endpoints in order to capture and view incoming HTTP requests,” Polovinkin noted. “The threat actor created temporary endpoints and sent sensitive data stolen from victims.”

Dark Pink, its espionage motives notwithstanding, remains shrouded in mystery. That said, it’s suspected that the hacking crew’s victimology footprint could be broader than previously assumed.

The fact that the adversary has been linked to only 13 attacks (counting the five new victims) since mid-2021 indicates an attempt to maintain a low profile for stealthiness. It’s also a sign of the threat actor carefully selecting their targets and keeping the number of attacks at a minimum to reduce the likelihood of exposure.

“The fact that two attacks were executed in 2023 indicates that Dark Pink remains active and poses an ongoing risk to organizations,” Polovinkin said. “Evidence shows that the cybercriminals behind these attacks keep updating their existing tools in order to remain undetected.”

Found this article interesting? Follow us on Twitter and LinkedIn to read more exclusive content we post.





Source link

Related Articles

xxxanti beeztube.mobi hot sexy mp4 menyoujan hentaitgp.net jason voorhees hentai indian soft core chupatube.net youjzz ez2 may 8 2023 pinoycinema.org ahensya ng pamahalaan pakistani chut ki chudai pimpmovs.com www xvedio dost ke papa zztube.mobi 300mbfilms.in صور مص الزب arabporna.net نهر العطش لمن تشعر بالحرمان movierulz plz.in bustyporntube.info how to make rangoli video 穂高ゆうき simozo.net 四十路五十路 ロシアav javvideos.net 君島みお 無修正 افلام سكس في المطبخ annarivas.net فيلم سكس قديم rashmi hot videos porncorn.info audiosexstories b grade latest nesaporn.pro high school girls sex videos real life cam eroebony.info painfull porn exbii adult pics teacherporntrends.com nepali school sex