Chinese State-Linked Hackers Blend Automated Tools With Hands-On Attacks
Detection stack
- AIDR
- Alert
- ETL
- Query
Summary
Chinese government-linked actors, supported by Integrity Technology Group, utilize a combination of automated scanning tools, large-scale botnets, and manual exploitation. They target sensitive data across critical infrastructure sectors using vulnerabilities in web applications and Microsoft Exchange servers. The actors employ various techniques for persistence, credential theft, and data exfiltration to achieve their objectives.
Investigation
The investigation was conducted by multiple international agencies, including the FBI, CISA, NSA, and others, based on technical evidence recovered from multiple investigations related to Integrity Technology Group. Analysts observed the use of custom tools like MicroScan, EBurst, and Curlc4.txt, alongside standard living-off-the-land techniques. Findings revealed specific malware such as live700_v1.exe and the use of SoftEther VPN for persistence.
Mitigation
Organizations should prioritize disabling unused services and ports and sanitizing web application inputs to prevent injection attacks. Implementing multifactor authentication (MFA) for all services and adopting strong identity and access management (ICAM) policies is critical. Additionally, timely patching of software and firmware is recommended to reduce the risk of exploitation.
Response
Upon detection, organizations should isolate compromised hosts and initiate threat hunting to determine the full scope of the intrusion. Review relevant logs and artifacts to identify specific TTPs and a timeline of activities. Implement eviction countermeasures systematically using established playbooks to contain and eradicate the threat actor from the network.
Attack Flow
Detections
Download or Upload via Powershell (via cmdline)
Possible Unauthorized Network Scan via Nmap Or Masscan (via cmdline)
Suspicious Mailbox Export Request (via powershell)
Suspicious Executable File Named Like a Legitimate System Process was Created (via file_event)
Possible DCSync Attack (via audit)
DCSync Rights was Granted (via audit)
Azure Authentication Request Was Perfomed With Suspicious User Agent (via azure)
Password Spraying and Guessing on Microsoft Exchange Servers [Azure Activity Logs]
Automated Vulnerability Scanning Tools Used by Chinese Government-linked Actors [AWS Cloudtrail]
Detection of DCSync Activity Using DC.exe [Windows Sysmon]
Detection of Abnormal Executables for Malicious Activity [Windows Process Creation]
Simulation Execution
-
Attack Narrative & Commands: The adversary has gained initial access to the workstation. To maintain persistence and evade detection by SOC analysts looking for unknown binaries, the adversary performs a “Masquerading” technique. They take a simple benign executable (in this case,
calc.exe) and rename it toDiagTrack.exe. They then execute this renamed file from a non-standard directory (C:UsersPublic). This action is intended to trigger the detection rule which monitors for the execution ofDiagTrack.exewhen it is used as a masquerading tool. -
Regression Test Script:
# Simulation Script: Masquerading as DiagTrack.exe $TargetDir = "C:UsersPublicDownloads" $MaliciousName = "DiagTrack.exe" $SourceBinary = "C:WindowsSystem32calc.exe" # 1. Create directory if it doesn't exist if (!(Test-Path $TargetDir)) { New-Item -ItemType Directory -Path $TargetDir -Force | Out-Null } # 2. Copy and rename the binary to masquerade Copy-Item -Path $SourceBinary -Destination "$TargetDir$MaliciousName" -Force # 3. Execute the masqueraded binary to trigger the detection Write-Host "[+] Executing masqueraded binary: $TargetDir$MaliciousName" Start-Process -FilePath "$TargetDir$MaliciousName" Write-Host "[+] Simulation complete. Check SIEM for detection." -
Cleanup Commands:
# Cleanup Script $TargetDir = "C:UsersPublicDownloads" $MaliciousName = "DiagTrack.exe" if (Test-Path "$TargetDir$MaliciousName") { Remove-Item -Path "$TargetDir$MaliciousName" -Force Write-Host "[+] Cleanup successful: $MaliciousName removed." } else { Write-Host "[-] Cleanup failed: File not found." }