Digital Forensic, Research and Analytics Center

Sunday, January 29, 2023
spot_imgspot_imgspot_imgspot_img
HomeOnline FraudChinese espionage group targets newfound weaknesses in Exchange, targets giant companies in...

Chinese espionage group targets newfound weaknesses in Exchange, targets giant companies in South-East Asia

Published on

Subscribe us

At the Security Analyst Summit that took place on September 30,2021, during which the security company Kaspersky Lab released a report on a new cyber espionage group called GhostEmperor who have been using new techniques to launch cyberattacks on servers. 

The main target of GhostEmperor is government and telecommunications services in Malaysia, Thailand, Indonesia even spanning all the way to Afghanistan and Egypt. 

It is being said that the group is focused on gaining long term access to its victims and uses a highly sophisticated toolkit that is even compatible with Windows 10 further increasing the risks. 

GhostEmperor entered servers through applications such as Oracle and Microsoft Exchange whose servers were exploited by the group to enter the target servers. 

In the report, they have detailed how GhostEmperor uses different scripts and tools to help infiltrate the network’s backdoors. 

The architecture used by the attackers to stage shellcode buffers in the winlogon.exe process in order to handle various remote control features
Courtesy: Kaspersky

After infiltrating the network, the backdoor is used to install the open-source Cheat Engine which is primarily used by gamers to install cheat codes to their games. This was then used to install a very powerful rootkit called Demodex to their server. 

The toolkit is developed in such a manner that it continues to stay on the system even after the operating system is reinstalled and updated to Windows 10. 

The main reason why this group sticks out is because the group seems to be using anti-forensics and anti-analysis tools that caused a hindrance to security researchers who were trying to analyse their malware.

They also packaged fake data and sent it to the command rather than sending the real things. This kind of sophistication that GhostEmperor displays is something to keep your eye on. 

- Advertisement -[automatic_youtube_gallery type="channel" channel="UCY5tRnems_sRCwmqj_eyxpg" thumb_title="0" thumb_excerpt="0" player_description="0"]
DFRAC Editor
DFRAC Editorhttps://dfrac.org
Digital Forensics, Research and Analytics Centre (DFRAC) is a non-partisan and independent media organisation which focuses on fact-checking and identifying hate speech. With the popularisation of the internet came the challenge of information overload and often times, our feeds are overpopulated with conflicting, incendiary and false information which is increasingly becoming difficult to ignore and not believe in

Popular of this week

Latest articles

No protest is held against BBC in London for releasing PM Modi’s Documentary- Read Fact Check

A recent release of a BBC Documentary that is on the Gujrat riots in...

TMC leader Shaukat Ali, who won 75% of Hindu voter seats, stopped Durga Visarjan. 

A graphical poster is going viral on social media. In this poster, a claim...

An old video of Burning a Quaran from Denmark is going viral as an incident in Sweden. Read- Fact Check

A video is going viral on social media. It can be seen in the...

Muslim women will go to watch the film “Pathan” by selling free ration from the Modi government. Read- Fact Check

A picture is getting viral on social media. In this picture, it can be...

all time popular

More like this

No protest is held against BBC in London for releasing PM Modi’s Documentary- Read Fact Check

A recent release of a BBC Documentary that is on the Gujrat riots in...

TMC leader Shaukat Ali, who won 75% of Hindu voter seats, stopped Durga Visarjan. 

A graphical poster is going viral on social media. In this poster, a claim...

An old video of Burning a Quaran from Denmark is going viral as an incident in Sweden. Read- Fact Check

A video is going viral on social media. It can be seen in the...

Muslim women will go to watch the film “Pathan” by selling free ration from the Modi government. Read- Fact Check

A picture is getting viral on social media. In this picture, it can be...

The truth about the media campaign against India from the Gulf

In the media war against India, only Pakistan and the handlers sitting outside Pakistan...

Is RBI now planning to use photos of notes instead of Photos- Read Fact Check

A video shared on Instagram which is claiming that RBI is planning on issuing...