Chinese hacking group attempts to 'trap' high level targets

Hackers strike!

Dell Secureworks has uncovered a Chinese advanced persistent threat (APT) group that has set scores of traps across the world to pilfer data from some big targets.

The group, known as Emissary Panda or Threat Group 3390 (TG-3390), has placed over 100 of the so-called 'traps' and has already gone after defence firms in the UK and US as well as the Russian Embassy in Washington D.C.

Using strategic web compromises (SWCs) to get inside organisations, victims are taken under its spell when they visit websites related to the business they are involved with. The hackers only go after victims that have "access to desirable data" and to do so code on the site exploits vulnerabilities on the victim's computer before installing a key logger and backdoor on Microsoft Exchange servers to take control.

Older vulnerabilities are being relied upon by the group such as those affecting Java (CVE-2011-3544) and JBoss (CVE-2010-0738). There is, however, no suggestion that zero-day exploits are being used and a couple of tools being deployed by TG-3390 are OwaAuth and ASPXTool.

OwaAuth is a web shell and credential thief used to attack Exchange Servers whilst ASPXTool is a modified ASPXSpy web shell used on accessible servers running Internet Information Services, according to V3. The group have also used a range of other tools including PlugX and HttpBrowser.

How to remove it

In addition to targeting victims when they visit websites, TG-3390 is using spearfishing emails when attempting to extract information from very specific targets. Otherwise the targets are a lot more general and are ranked in importance depending on the organisation.

Organisations can put an end to any data breaches carried out by the APT group by removing all access points including remote access tools, although attackers will attempt to return once again even if they have been removed.

Latest in Security
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Representational image depecting cybersecurity protection
Cisco smart licensing system sees critical security flaws exploited
Latest in News
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Sunday, March 23 (game #385)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Sunday, March 23 (game #651)
Google Pixel 9 Pro Fold main display opened
Apple is rumored to be prioritizing battery life on the foldable iPhone – which could also feature a liquid metal hinge for added durability
Google Pixel 9
The Google Pixel 10 just showed up in Android code – and may come with a useful speed boost
L-mount alliance
Sirui joins L-Mount Alliance to deliver its superb budget lenses for Leica, DJI, Sigma and Panasonic cameras