跳到主体内容

Winnti Group responsible for enhanced attack platform infecting organizations in South Korea, UK and Russia

2015年10月6日

Kaspersky Lab experts tracking the activity of the Winnti group have discovered an active threat based on a 2006 bootkit installer

Kaspersky Lab experts tracking the activity of theWinnti grouphave discovered an active threat based on a 2006 bootkit installer.  The threat, which Kaspersky Lab has called “HDRoot” after the original tool’s name “HDD Rootkit”, is a universal platform for a sustainable and persistent appearance in a targeted system, which can be used as a foothold for any arbitrary tool.

The Winnti criminal organization is known for industrial cyberespionage campaigns targeting software companies, especially those in the gaming industry. Recently it has also been observed targeting pharmaceutical businesses.

“HDRoot” was discovered when an intriguing sample of malware sparked the interest of Kaspersky Lab’s Global Research and Analysis Team (GReAT) for the following reasons:

  • It was protected with a commercial VMProtect Win64 executable signed with a known compromised certificate belonging to the Chinese entity, Guangzhou YuanLuo Technology; a certificate that the Winnti group was  known to have abused to sign other tools;
  • The properties and output text of the executable were spoofed to make it look like a Microsoft’s Net Command net.exe, obviously to reduce the risk of system administrators exposing the program as hostile.

Taken together, this made the sample look suitably suspicious.  Further analysis showed that the HDRoot bootkit is a universal platform for a sustainable and persistent appearance in a system. It can be used to launch any other tool. The GReAT researchers were able to identify two types of backdoors launched with the help of this platform, and there may be more. One of these backdoors was able to bypass well-established anti-virus products in South Korea - AhnLab’s V3 Lite, AhnLab’s V3 365 Clinic and ESTsoft’s ALYac. Winnti therefore used it to launch malware products on target machines in South Korea.

According to Kaspersky Security Network data, South Korea is the main area of interest for the Winnti group in South East Asia; with other targets in this region including organizations in Japan, China, Bangladesh and Indonesia. Kaspersky Lab has also detected HDRoot infections in a company in the UK and in one in Russia, both of which have previously been targeted by the Winnti group.

“The most important goal for any APT-actor is to stay under the radar, to remain in the shadow. That’s why we rarely see any complicated code encryption, because that would attract attention. The Winnti group took a risk, because it probably knows from experience which signs should be covered-up and which ones can be overlooked because organizations don’t always apply all the best security policies all of the time. System administrators have to keep on top of many things, and if the team is small, the chance that cybercriminal activity will remain undetected is even higher.” – said Dmitry Tarakanov, Senior Security Researcher in Kaspersky Lab’s GReAT team.

The development of the HDD Rootkit is likely to be the work of someone who went on to join the Winnti group when it was set up. Kaspersky Lab believes that Winnti was forming into a group in 2009, so didn’t yet exist in 2006. But there is a possibility that Winnti made use of third-party software.  Perhaps this utility and source code are available on the Chinese or other cybercriminal black market. The threat is still active. Since Kaspersky Lab started to add detections, the group behind the attacks has started to adapt them – in less than a month, a new modification was identified.

Kaspersky Lab’s products successfully block the malware and protect users against the threat.

Learn more about Chinese-language APT campaigns here.

To learn more about the Winnti Group’s attack platform, please read the blog post available at Securelist.com.

Winnti Group responsible for enhanced attack platform infecting organizations in South Korea, UK and Russia

Kaspersky Lab experts tracking the activity of the Winnti group have discovered an active threat based on a 2006 bootkit installer
Kaspersky logo

关于卡巴斯基

卡巴斯基是一家成立于1997年的全球网络安全和数字隐私公司。卡巴斯基以“网络免疫”理念引领行业创新,致力于保护消费者、企业、关键基础设施和政府机构免受网络威胁,迄今为止已保护超过 10 亿台设备。

卡巴斯基秉持“Cybersecurity True to Business”的理念,专注于交付明确成果、保障营收、减轻团队负担并避免业务中断。卡巴斯基深厚的威胁情报和安全专业知识不断转化为创新解决方案和服务,服务于从小型企业到大型集团等各种规模的组织,将成熟的 AI 驱动型保护技术与简洁高效的管理和专家支持相结合。

卡巴斯基的解决方案经独立测试认可,深受全球数百万个人用户及近 20 万家企业的信赖,帮助客户更早识别威胁、更快速响应,以更强的信心与自由空间开展业务,保护对客户至关重要的资产。了解更多详情,请访问 www.kaspersky.com.cn

相关文章 企业新闻