Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Endpoint

4/28/2020
04:30 PM
Connect Directly
Google+
Twitter
RSS
E-Mail
100%
0%

5-Year-Long Cyber Espionage Campaign Hid in Google Play

OceanLotus targeted Android devices in the so-called PhantomLance campaign.

[This article was updated to include information on BlackBerry's research on this OceanLotus attack campaign]

A targeted cyber-spying mission waged by a notorious hacking team out of Vietnam preyed mainly on Android users in Southeast Asia and evaded detection in Google Play, APKpure, and other app markets for five years. 

Researchers at Kaspersky today revealed details of their study of the attack campaign they call PhantomLance, which they believe is the handiwork of OceanLotus. While Kaspersky has a policy of not tying attack groups with specific nation-states, OceanLotus long has been believed to be a Vietnamese advanced persistent threat (APT) group. PhantomLance — which targets Android — has managed to stay alive by changing up its malware along the way to evade detection.

Researchers at BlackBerry last October in their mobile threat report published their own findings on this same attack campaign, which they dubbed Operation Oceanmobile, citing three fake Android apps that OceanLotus distributed both via phishing emails and on Google Play and other stores. 

Kaspersky researchers did not cite BlackBerry's research in their findings published yesterday, but noted that their report included fresh details on the attacks. "In our research on PhantomLance we aimed to heavily focus on the technical and attribution aspects of the campaign. We were able to discover and connect dozens of samples, trace and monitor the actor's infrastructure, and bring other technical evidence that can help others to protect themselves from the threat and also to better understand the tactics, techniques and procedures of the actor," says Alexey Firsh, security researcher with Kaspersky. "We haven't seen all of these things in other reports on presumably the same topic, and that is why we decided to publish our research."

Firsh says he and his team decided to dig deeper into a Trojan backdoor that was first revealed in a July 2019 report by researchers at Dr. Web. The relatively unusual backdoor, they found, dated back to at least December 2015, the registration date of one of the domains used in the campaign, according to Firsh. The latest sample of the spying malware was present in apps on Google Play in November 2019, he says, when Kaspersky notified Google. The apps, which were a mix of dozens of consumer utility-type apps such as ad blockers, Flash plug-ins, cache cleaners, and updaters, as well Vietnamese apps for locating nearby bars and churches, were then removed from the Google Play store.

Unlike most malicious mobile apps, PhantomLance is all about targeting, and not wide-net infections or promoting its installation. The attackers created several versions of the backdoor, with dozens of samples, and when an app first went up in Google Play or other app stores, it didn't contain malware: That was added later in the form of an update, after the user had installed it. That's likely what allowed the apps to pass any app store vetting.

There have been some 300 attack attempts on Androids in India, Vietnam, Bangladesh, and Indonesia, since 2016.

OceanLotus, aka APT32, for years has been spotted targeting Vietnamese citizens and dissidents and journalists, as well as industries in Germany, China, the Philippines, the US, and the UK, in traditional cyber espionage fashion. The group, believed to be backed by the Vietnam government, in 2014 hacked a European company that planned to build a manufacturing plant in Vietnam, as well as a hospitality developer in 2016 that was looking to do business in Vietnam. 

Opsec Game on Point
The malware performs the usual spy stuff, gathering geolocation information, call logs, contact lists, and SMS messages, as well as information on the victim's device, such as model, operating system, and installed apps. "But we see that it also has the ability to execute special shell commands from the [C2] server and download additional payloads on the victim's device," Firsh explains.

Another tactic the attackers employed: creating a fake developer profile on GitHub to appear as a legitimate app developer. "I think the main reason they have those accounts is to start background stories to developers to look more legitimate to moderators of the marketplaces," explains Lev Pikman, a Kaspersky researcher who worked with Firsh on the PhantomLance research

BlackBerry also noted the Github accounts in its research. "They created modified GitHub repositories that theoretically showed evidence of the developers’ code for each app, complete with public facing 'contact us' email addresses to answer any questions that might arise about their 'products.'" BlackBerry's report said. "They even went to lengths to concoct entire privacy policies for their apps, which few people tend to actually read, but nevertheless was ironic, given that OCEANLOTUS' entire premise was to spy on its targets."

Kaspersky's Firsh says the attack group employs different encryption keys, separate infrastructures, and other methods to cover its tracks. "They are pretty good at opsec," he says.

While defending against a nation-state is not so simple, the best bet is to have a mobile security tool or service for devices and to be wary of apps you download, experts say.

The researchers presented their findings at Kaspersky's online Security Analyst Summit today, which was kicked off by Eugene Kaspersky, founder and CEO of Kaspersky, who cited an increase in malicious online activity since much of the world went into quarantine stay-at-home due to the COVID-19 pandemic. "Now [attackers] have many more opportunities to do their business," Kaspersky said. "We have seen a 10% increase in the new malware we collect. ... In some specific nations, we see ... more attempts at attack."

Related Content:

Check out The Edge, Dark Reading's new section for features, threat data, and in-depth perspectives. Today's top story: "5 Ways to Prove Security's Worth in the Age of COVID-19.

Kelly Jackson Higgins is the Executive Editor of Dark Reading. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
pak24tv2
50%
50%
pak24tv2,
User Rank: Apprentice
5/10/2020 | 1:38:26 AM
Pak24tv
Its is really a good story for me.

I am site engineer and presently taking a shot at site Pak24tv. Pak24tv is a greater site and live television entrance in Pakistan. You can watch upto 80 live gushing channel free and can check any portable cost and determination in any nation. You can likewise understand sites and check any sim bundle. On the off chance that you need to visit site, at that point click
COVID-19: Latest Security News & Commentary
Dark Reading Staff 8/10/2020
Researcher Finds New Office Macro Attacks for MacOS
Curtis Franklin Jr., Senior Editor at Dark Reading,  8/7/2020
Hacking It as a CISO: Advice for Security Leadership
Kelly Sheridan, Staff Editor, Dark Reading,  8/10/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Special Report: Computing's New Normal, a Dark Reading Perspective
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
The Changing Face of Threat Intelligence
The Changing Face of Threat Intelligence
This special report takes a look at how enterprises are using threat intelligence, as well as emerging best practices for integrating threat intel into security operations and incident response. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-15596
PUBLISHED: 2020-08-12
The ALPS ALPINE touchpad driver before 8.2206.1717.634, as used on various Dell, HP, and Lenovo laptops, allows attackers to conduct Path Disclosure attacks via a "fake" DLL file.
CVE-2020-15868
PUBLISHED: 2020-08-12
Sonatype Nexus Repository Manager OSS/Pro before 3.26.0 has Incorrect Access Control.
CVE-2020-17362
PUBLISHED: 2020-08-12
search.php in the Nova Lite theme before 1.3.9 for WordPress allows Reflected XSS.
CVE-2020-17449
PUBLISHED: 2020-08-12
PHP-Fusion 9.03 allows XSS via the error_log file.
CVE-2020-17450
PUBLISHED: 2020-08-12
PHP-Fusion 9.03 allows XSS on the preview page.