Project Hyphae
Search

VLC=Virus Loading Controller

Share This Post

Chinese threat actor Cicada (a.k.a menuPass, Stone Panda, Potassium, APT10, RedApollo) has been linked to a recent campaign using VLC Media Player to deploy malware on networks around the world. Targeting various organizations, Cicada typically starts by exploiting unpatched vulnerabilities in Microsoft Exchange to gain access to the network. Once inside, they utilize a technique called side-loading, where they replace a DLL file in the same path as the export function on a clean version of VLC with a malicious DLL, which then loads malware into the legitimate process.

Symantec’s Threat Hunter Team, who identified the threat, has not named the attack. In an interview with Bleeping Computer, the Threat Hunter team reported that along with exploiting Exchange Server and side-loading VLC, Cicada also deploys WinVNC to gain remote control over compromised systems, as well as the Sodamaster backdoor. The Sodamaster backdoor is a file-less exploit that runs in the system memory and utilizes stealth techniques to avoid detection. Sodamaster is also capable of enumerating system information, downloading additional packages and executing them, as well as obfuscating and encrypting its traffic going out to its command & control server.

Update your Exchange Server: https://docs.microsoft.com/en-us/exchange/new-features/updates?view=exchserver-2019

Then read about Cicada’s attacks: https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/cicada-apt10-china-ngo-government-attacks



Reach out to our incident response team for help

More To Explore

Information Security News 4-22-2024

Cisco Duo Warns Third-Party Data Breach Exposed SMS MFA Logs Article Link: https://www.bleepingcomputer.com/news/security/cisco-duo-warns-third-party-data-breach-exposed-sms-mfa-logs/ Notorious Russian Hacking Unit Linked to Breach of Texas Water Facility Article

Information Security News 4-15-2024

Roku Disclosed a Security Incident Impacting 576,000 Accounts Article Link: https://securityaffairs.com/161765/data-breach/roku-second-data-breach.html FBI Warns of Massive Wave of Road Toll SMS Phishing Attacks Article Link: https://www.bleepingcomputer.com/news/security/fbi-warns-of-massive-wave-of-road-toll-sms-phishing-attacks/

Do You Want to Shore Up Your Defenses?

We're opening our first round of threat hunting engagements to 100 organizations. Sign up or join the wait list here.