Symantec researchers describe Carderbee, a newly named APT group that used the Cobra DocGuard software in a supply chain attack to deploy the Korplug backdoor (PlugX) onto victim machines, primarily in Hong Kong. The operation relies on legitimate software and Microsoft-signed components to evade detection and conduct targeted intrusions. #Carderbee #Korplug #PlugX #CobraDocGuard #EsafeNet #Budworm #HongKong
Keypoints
- A previously unknown APT group, named Carderbee, used the Cobra DocGuard software to carry out a supply chain attack with the goal of deploying the Korplug backdoor (aka PlugX).
- Malware was signed with a legitimate Microsoft certificate, illustrating certificate abuse to improve stealth.
- The Cobra DocGuard client is from EsafeNet (owned by NSFOCUS); past activity links to Budworm (APT27) and a 2022 Korplug variant with an ESET-related header.
- Attack flow shows Cobra DocGuard installed on about 2,000 computers, with malicious activity seen on around 100 victims, indicating selective payload deployment.
- A downloader used a Microsoft-signed certificate and downloaded update.zip from a remote URL; update.zip decompresses to content.dll, a dropper that loads drivers and injects Korplug into svchost.exe.
- The Korplug payload can execute commands, enumerate files, check processes, download files, open firewall ports, and function as a keylogger.
MITRE Techniques
- [T1195] Supply Chain Compromise – Used Cobra DocGuard software to carry out a supply chain attack with the goal of deploying the Korplug backdoor onto victim computers. “A previously unknown advanced persistent threat (APT) group used the legitimate Cobra DocGuard software to carry out a supply chain attack with the goal of deploying the Korplug backdoor (aka PlugX) onto victim computers.”
- [T1218] Signed Binary Proxy Execution – Used a downloader signed with a legitimate Microsoft certificate to install Korplug. “a downloader deployed by the attackers had a digitally signed certificate from Microsoft, called Microsoft Windows Hardware Compatibility Publisher.”
- [T1105] Ingress Tool Transfer – Downloader downloaded update.zip from a remote location to install the dropper. “The downloader attempted to download a file named update.zip from the following location: http://cdn.stream-amazon[.]com/update.zip.” The update.zip file is a zlib compressed archive file. It decompresses and executes a file named content.dll.
- [T1543.003] Create or Modify System Process: Windows Service – The dropper creates services and registry entries. “The dropper creates services and registry entries.”
- [T1055] Process Injection – The payload is injected into svchost.exe. “The dropped drivers read encrypted data from the registry, decrypt it, and inject it into svchost.exe.”
- [T1012] Query Registry – The dropper reads encrypted data from the registry to decrypt payload. “The dropped drivers read encrypted data from the registry, decrypt it, and inject it into svchost.exe.”
- [T1562.004] Impair Defenses: Modify Firewall – The Korplug payload opens firewall ports. “Open firewall ports.”
- [T1036] Masquerading – The use of a magic header ‘ESET’ to bypass ESET products. “magic header “ESET”, indicating that it may have been modified to try to bypass ESET products.”
- [T1027] Obfuscated/Compressed Files and Information – The update.zip is a zlib compressed archive; it decompresses and executes content.dll. “The update.zip file is a zlib compressed archive file. It decompresses and executes a file named content.dll.”
- [T1059.003] Command and Scripting Interpreter – The Korplug backdoor can execute commands via cmd. “Execute commands via cmd”
- [T1083] File and Directory Discovery – The backdoor can enumerate files. “Enumerate files”
- [T1056.001] Keylogging – The backdoor can act as a keylogger. “Act as a keylogger”
Indicators of Compromise
- [SHA256] file hashes – 96170614bbd02223dc79cec12afb6b11004c8edb8f3de91f78a6fc54d0844622, 19a6a404605be964ab87905d59402e2890460709a1d9038c66b3fbeedc1a2343 and 2 more hashes
- [IP] remote IP addresses – 45.76.179.209, 104.238.151.104
- [URL] URLs – http://111.231.100.228:8888/CDGServer3/UpgradeService2, http://103.151.28.11:8090/CDGServer3/UpgradeService2
- [Domain] Domains – cdn.stream-amazon.com, cdn.ofo.ac and 5 more domains