Malware
JuicyPotato
As described on the Github repository page, "A sugared version of RottenPotatoNG, with a bit of juice, i.e. another Local Privilege Escalation tool, from a Windows Service Accounts to NT AUTHORITY\SYSTEM".
Indicators of Compromise 20
Domain vn[.]xyz Filename C:\Windows\System32\drivers\etc\hosts:cache Filename MyAppDomainManager.dll Filename PerfWatson2.exe Filename acpi_pad.ko Filename chrome_setup.zip Filename demo.pdb Filename service.pdb GitHub Repo widestring-1.2.1 SHA-256 00e09754526d0fe836ba27e3144ae161b0ecd3774abec5560504a16a67f0087c SHA-256 4e1f8888d020decd09799ec946f1bf677cac6612b24582ddbf4d8ede425d8384 SHA-256 9b481b69cd91b09fa7bae7428f646dd89473a4c03393e43da81fe756cde1c472 SHA-256 cbfe8de6ffadbb1d396f61e63eb18e8b11c29527c1528641e3223d4c516cf7c3 SHA-256 dce5df29bddff5a4ddaea5c4fec14da91f7b69063a6e1c45ed61e5da4fc6c87b SHA-256 f34bd1d485de437fe18360d1e850c3fd64415e49d691e610711d8d232071a0b1 IP 139[.]180[.]134[.]221 IP 202[.]182[.]102[.]5 IP 45[.]32[.]113[.]172 IP 45[.]76[.]210[.]43 Registry User index.crates.io-1949cf8c6b5b557f
MITRE ATT&CK TTPs 21
T1003 T1021 T1055 T1055.003 T1059.001 T1068 T1071.001 T1074 T1078 T1082 T1090 T1105 T1110 T1134 T1203 T1210 T1211 T1212 T1218 T1222 T1485
OS Credential Dumping
Credential Access
Remote Services
Lateral Movement
Process Injection
Defense Evasion
Thread Execution Hijacking
Defense Evasion
PowerShell
Execution
Exploitation for Privilege Escalation
Privilege Escalation
Web Protocols
Command And Control
Data Staged
Collection
Valid Accounts
Defense Evasion
System Information Discovery
Discovery
Proxy
Command And Control
Ingress Tool Transfer
Command And Control
Brute Force
Credential Access
Access Token Manipulation
Defense Evasion
Exploitation for Client Execution
Execution
Exploitation of Remote Services
Lateral Movement
Exploitation for Defense Evasion
Defense Evasion
Exploitation for Credential Access
Credential Access
System Binary Proxy Execution
Defense Evasion
File and Directory Permissions Modification
Defense Evasion
Data Destruction
Impact
Source Articles
UAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities
UAT-10147, a Chinese-speaking threat actor, is deploying a new cross-platform backdoor named SPECTRE that targets both Windows and Linux systems. The implant includes advanced capabilities such as process injection, credential theft, anti-analysis routines, and EDR evasion via Bring Your Own Vulnerable Driver (BYOVD) techniques. On Linux, SPECTRE deploys a kernel rootkit called Specter, disguised as 'acpi_pad.ko', which uses ftrace-based hooking to hide processes, modules, and enable UID 0 escalation. The actor also leverages SEO fraud tools like BadIIS and a custom ASHX web handler targeting Vietnamese users, along with multiple backdoors including Meterpreter, Noodle RAT, QuasarRAT, and Gh0stCringe for persistence.
talos ·1w ago
CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure
CL-STA-1062, a Chinese-speaking threat actor group active since at least March 2022, has been targeting government entities and critical infrastructure in Southeast Asia. The group, also tracked as UAT-7237, uses a hybrid toolkit combining open-source tools like SoftEther VPN, Mimikatz, and VNT with a custom backdoor named TinyRCT. This backdoor enables command execution, file exfiltration, screen capture, and self-destruction, and is deployed via AppDomainManager injection through a maliciously crafted archive. The campaign demonstrates a sustained regional focus, with attacks spanning from Taiwan to Southeast Asia, particularly targeting energy and government sectors.
unit42 ·2mo ago