Chinese hackers suspected of attacking government agencies in Mongolia www.securitylab.ru
A Chinese cybercriminal APT group is suspected of hacking into the network of a Mongolian software company and hacking into a chat application used by hundreds of Mongolian government agencies.
According to experts from ESET, the attack took place in June this year. Hackers attacked an application called Able Desktop, developed by local company Able Software. The application is an instant messaging add-on for the company's main product, the HR platform. The platform is used by over 430 government agencies in Mongolia, including the Office of the President, the Ministry of Justice, the Ministry of Health, various local law enforcement agencies and authorities.
Due to its widespread use among government officials, ESET said the app has been a target of cyber attacks since at least 2018. In the first attacks, the criminals tried to inject the HyperBro backdoor and the PlugX remote access Trojan into the Able Desktop application and distributed Trojan versions of the application's installer via email.
In June 2020, attackers appeared to have been able to hack into Able's backend and compromised the system that delivers software updates to all of Able's software applications. Hackers have used this system at least twice to distribute the malware-infected Able Desktop chat application through a legitimate update mechanism. To carry out these attacks, the attackers again used the HyperBro backdoor, but replaced PlugX with Tmanager as a component for remote access.
Published Date:2020-12-15