Cyber security firm uncovers decade-long malware attack on ASEAN governments and businesses

Today FireEye, the California-based security software firm, issued a lengthy report alleging that a single entity has been carrying out malware attacks towards businesses and governments in India, the USA, and Southeast Asia.
FireEye claims that the entity, which it calls APT 30, has been self-registering DNS domains with malware command and control since 2004. Its malware attacks appear to be targeted towards organizations with information generally relevant to state security and diplomatic agencies – in particular, the Communist Party of China. FireEye adds that APT 30 appears to have been working in a systematic, collaborative manner, using tools designed for longevity, which indicates the attacks constitute part of a long-term campaign.
“APT 30’s attack tools, tactics, and procedures (TTPs) have remained markedly consistent since inception – a rare finding as most APT actors adjust their TTPs regularly to evade detection,” reads a statement from FireEye.
FireEye pinpoints several types of malware, such as Spaceship, Shipspace, and Flashflood, as pieces designed to infect removable thumb-drives, spread through additional systems (possibly air-gapped ones, meaning systems isolated from the public internet), and then steal files.
FireEye couldn’t provide evidence linking APT 30 to a Chinese government agency. But the report points out a factors that indicate the state might have been involved in the attacks. Images of APT 30’s backdoor control system show menu items and dialogue boxes written in simplified Chinese script. In addition, while FireEye didn’t publicly disclose the specific nature of the retrieved files or the organization under attack, it claims that APT 30 appeared to have interests consistent with the Chinese government.
“Much of their social engineering efforts suggest the group is particularly interested in regional political, military, and economic issues, disputed territories, and media organizations and journalists who report on topics pertaining to China and the government’s legitimacy,” reads the report.
News of the alleged campaign comes days after Citizen Lab, the Toronto-based research organization, issued a report detailing the alleged origins of the recent distributed denial of service (DDoS) attack against GitHub and GreatFire.org. The research team claimed that the Chinese government used a tool dubbed the “Great Cannon,” to intercept traffic coming towards a site using Baidu’s server infrastructure, and redirect it towards the victim sites.
Editing by Paul Bischoff, top image by alpstedt
Stay updated on the go with our mobile app.
Get latest insights with smoother, more personalized experience through TIA mobile app.





