Blackberry's Research and Intelligence Team has uncovered three phishing schemes targeting Indian nationals, and says a Chinese state-sponsored malware gang is the culprit.
Blackberry identified the responsible party as APT41 – a prolific Chinese state-sponsored cyberthreat group that has carried out what Fireye called "espionage activity in parallel with financially motivated operations" since at least 2012. The group targets many industries, including travel, telecommunications, healthcare, news, and education.
Blackberry says it joined the dots between phishing in India and APT41 by monitoring previously documented activity associated with commercial malware called "Cobalt Strike". The action Blackberry spotted used a bespoke, malleable command-and-control (C2) profile that displayed similarities to other attacks.
The researchers found sufficient grounds to associate past and new campaigns by identifying nearly identical HTTP GET profile blocks and mapping out similarities in Beacon configuration data. A few clusters with unique configuration metadata suggested association with APT41.
China-aligned APT41 gang phished Indian nationals
Blackberry says APT41 gang used lumpen remixes of Microsoft domain names to lure the unwary
www.theregister.com