Observable: GopherWhisper Threat Group (China-Aligned)
Observable Type: Victimology, Tools, Tradecraft, IoCs
Details:
TLP:CLEAR
Came across a blog from ESET about a new China-Aligned threat group. The blog post is fluff, the real data is here:
To make a long story short, this report highlights a collection of Remote Access Trojans and tools utilized by this group for ops. Most of these tools do C2 via the use of legitimate tools such as Slack, Discord, and/or Outlook. There was one tool that does do Direct connections to a C2 but its Raw TCP data, and not HTTPS.
Interestingly, most of the RATs use the file[.]io service for exfiltrating data. More interestingly, file[.]io is… squints limewire? NSM coverage for this file sharing service is available for both Snort and Suricata via the Emerging Threats Open (free) ruleset via the following rules:
2058005: Commonly Abused File Sharing Site Domain Observed in DNS Lookup (file .io)
2058011: Observed Commonly Abused File Sharing Site Domain (file .io) in TLS SNI
The ruleset also features general DNS and TLS SNI rules for Discord activity, and might be useful to enable, if discord messenger activity isn’t expected in your network:
2035463: Observed Discord Domain (discord .com in TLS SNI)
2035464: Observed Discord Domain (discordapp .com in TLS SNI)
2035465: Observed Discord Domain in DNS Lookup (discord .com)
2035466: Observed Discord Domain in DNS Lookup (discordapp .com)
For a direct link to other consumable IOCs, here is the ESET github repo that has them: