APT 32
Overview
Hence, APT 32 targets the foreign companies doing business with Vietnam, Vietnamese government critics, local and ex-pat Vietnamese human rights activists, and rival South East Asian foreign governments, especially the Philippines and Cambodia. Its attacks often coincide with important contract and legal negotiations between foreign companies and the Vietnamese government.
How Does It Works?
METALJACK, Denis (or DenisRAT), Kerrdown, Windshield, Komprogo, and Soundbite are some malware strains exclusive to or closely associated with APT 32.
Tactics, Techniques, and Procedures
- They hack the adversaries' websites to collect their information and track their user base.
- They use custom macOS malware with double extension technique or malicious Office macros written in the Perl programming language.
- Make use of Facebook social networking to spread malware through social engineering attacks.
- Cobalt Strike, a legitimate penetration testing tool is used as Command and Control (C2) spyware.
Prevention
Hence, user awareness training to educate internal staff about proper procedures for assessing as well as handling documents, and a full-fledged Defense-in-Depth-based cybersecurity program is the best way to prevent a successful APT32 attack.
Comments
Post a Comment