Chinese APT Targets South Korea in Multi-Year Campaign

There has been an extensive Chinese state-sponsored cyber espionage effort spanning multiple years, targeting South Korean academic, political, and governmental entities.

The Insikt Group from Recorded Future, operating under the code name TAG-74, has identified this campaign. They have connected the adversary to Chinese military intelligence and have expressed concerns regarding its impact on South Korean, Japanese, and Russian academic, aerospace, defense, governmental, military, and political organizations.

The cybersecurity company has characterized the targeting of South Korean academic institutions as part of China's broader strategy to engage in intellectual property theft and increase its influence, particularly in light of its strategic relationship with the United States.

Help Files Used as Bait

The Chinese APT employs social engineering techniques, utilizing Microsoft Compiled HTML Help (CHM) files as bait. These files introduce a customized version of the open-source Visual Basic Script backdoor named ReVBShell. This backdoor subsequently facilitates the deployment of the Bisonal remote access trojan.

ReVBShell is designed to remain dormant for a specified period, with the ability to adjust this interval through remote commands. It also employs Base64 encoding to obscure its command-and-control (C2) communications.

The use of ReVBShell has been associated with two other China-related clusters known as Tick and Tonto Team. In April 2023, ASEC (AhnLab Security Emergency Response Center) detected an identical infection sequence linked to Tonto Team.

Bisonal, the remote access trojan delivered by ReVBShell, is a versatile tool capable of various tasks, including information gathering, command execution, process management, file transfers, and file deletions.

TAG-74 is closely tied to Tick, underscoring the prevalent practice of sharing tools among Chinese threat groups.

Recorded Future has emphasized that the TAG-74 campaign reflects the group's enduring commitment to collecting intelligence from South Korean targets over an extended period.

September 26, 2023
Loading...

Cyclonis Backup Details & Terms

The Free Basic Cyclonis Backup plan gives you 2 GB of cloud storage space with full functionality! No credit card required. Need more storage space? Purchase a larger Cyclonis Backup plan today! To learn more about our policies and pricing, see Terms of Service, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.