we

All quiet on the Western Front as APT actors shift to mobile and increase activity in Asia

Advanced persistent threat (APT) activity in the first quarter of 2020 demonstrated that
infection and distribution of malware via mobile platforms is on the rise, with some
campaigns focusing solely on mobile. At the same time, activity in Asia is growing,
particularly among new actors, while traditional advanced actors are becoming much more
selective in how they carry out their operations. These and other APT trends from across
the world are covered in Kaspersky’s latest quarterly threat intelligence summary.
A three-month APT trends summary for the last quarter has come from Kaspersky’s private
threat intelligence research, as well as other sources that cover the major developments
that the company’s researchers believe everyone should be aware of.
 
APT findings in Q1 2020 confirmed that activity in Asia keeps growing with a variety of
attacks spurring across South East Asia, Korea and Japan. Kaspersky has seen new APT groups with creative and sometimes low-budget campaigns emerging and establishing
their presence alongside well-known actors, such as CactusPete and Lazarus.
 
On top of that, the interest in mobile platforms as a means ofattack and dissemination of
malware distribution is expected to grow. Kaspersky recently shared reports on a number of campaigns that were strongly focused on mobile attacks, including aLightSpywater-
holing campaignthat targeted users in Hong Kong and exploited iOS and Android devices,as well asan Android espionage campaign named PhantomLancetargeting victims in South
East Asia. Notably, both of these campaigns successfully utilized various online platforms, from forums and social media to the Google Play app store, demonstrating a smart
approach to distributing malware.
 
APT actors targeting Asia are not the only ones that developed mobile implants. For
instance, TransparentTribecarried out a campaign with a new module named “USBWorm”,targeting victims in Afghanistan and India,developed a new implant designed
to infect Android devices. The malware used is a modified version of the “AhMyth” Android RAT -an open source piece of malware available on GitHub.
 
Additionally, the COVID-19 pandemichas been used by different APT groups since mid-
March to lure in victims, but does not signify a meaningful change in terms of TTPs other than a popular topic being leveraged to capitalize on vulnerable users. The topic was used
by APT actors such as Kimsuky, Hades and DarkHotel.
 
“APT activities have not stoppedduring pandemic.Actually, some threat actors have
capitalized on it in different ways, such as trying to improve their reputation by announcing
that they would not target health institutions for the time being. Nevertheless, our findings
suggest that both financial gain and geo-politics continue to be the key drivers of APT
activity, particularly foractors who emerged in the last two years and are currently
consolidating their status as persistent malefactors. Mobile is gaining more traction in new
campaigns, as new players emerge with creative solutions, and activity from more seasoned actorshas become nearly invisible. This is possibly a consequence of the changing
circumstances we all face. As usual, I must add that we do not necessarily have full visibility, and there will be activity that is not yet on our radar nor fully understood – so
protection against both known and unknown threats remains vital for everyone,” said
Vicente Diaz, Principal Security Researcher, Global Research and Analysis Team, Kaspersky.
 
The Q1 APT trends report summarizes the findings of Kaspersky’s subscriber-only threat
intelligence reports, which also include Indicators of Compromise (IOC) data and YARA rules to assist in forensics and malwarehunting. For more information, please contact:
 
In order to avoid falling victim to a targeted attack by a known or unknown threat actor,
Kaspersky researchers recommend implementing the following measures:
• Provide your SOC team with access to the latest Threat Intelligence to keep it up to date
with new and emerging tools, techniques and tactics used by threat actors and cybercriminals.
• For endpoint level detection, investigation and timely remediation of incidents,
implement EDR solutions such as Kaspersky Endpoint Detection and Response.
• Ensure your endpoint security solution providesprotection for mobile devices. It should
enable protection from web threats and malware targeting mobile platforms, as well as application and device control.
• In addition to adopting essential endpoint protection, implement a corporate-grade
security solution that detects advanced threats on the network level at an early stage, such as Kaspersky Anti Targeted Attack Platform.
• As many targeted attacks start with phishing or other social engineering techniques,
introduce security awareness training and teach practical skills – for example through the Kaspersky Automated Security Awareness Platform.
Read the full Q1 2020 APT trends report on Securelist

شاهد أيضاً

Telecom Egypt

Telecom Egypt and Ericsson successfully test 5G in Egypt’s New Administrative Capital

Telecom Egypt and Ericsson (NASDAQ: ERIC) have successfully trialed 5G across several key locations in …

اترك تعليقاً

لن يتم نشر عنوان بريدك الإلكتروني. الحقول الإلزامية مشار إليها بـ *