探索中国DDoS威胁态势(英文版)_32页_4mb
报告摘要
Summary of the Chinese DDoS Threat Landscape Report
Core Content
This report explores the Chinese DDoS threat landscape, focusing on the activities of two prominent threat groups: ChinaZ and Nitol, and discusses the potential code and artifact sharing between them. It also includes a case study on a specific variant of Gh0st RAT found in the wild, which has been associated with multiple Chinese threat actor campaigns, including those involving APT groups.
Main Threat Groups
ChinaZ
- Description: A cross-platform DDoS botnet group first reported in 2014.
- Activities: Known for deploying DDoS botnets targeting both Linux and Windows systems.
- Malware Families: Includes Linux.Elknot, Linux.BillGates, AESDDoS, IptableX, XorDDoS, MrBlack, DDoSClient, and ChaChaBot.
- Motivation: Monetization through DDoS attacks as a service, demanding ransom.
- Development: Some malware was developed by students, such as DDoSClient.
- Hosting: Utilizes Chinese HTTP File Servers (HFS) for distribution.
- Code Reuse: All malware families share a common code base, with some functions reused from previous versions.
Nitol
- Description: A Windows-focused DDoS botnet first discovered in 2011.
- Infection Method: Spread via removable media and network shares.
- DLL Hijacking: Uses the
lpk.dllDLL, which is part of the Microsoft Language Pack, to hijack processes. - C&C Communication: Communicates through domains such as 3322.org.
- Infected Systems: Most infections were found on new factory systems with counterfeit Windows.
Key Findings and Correlations
Code and Artifact Similarities
- Shared Code Base: Both ChinaZ and Nitol share code, as evidenced by code reuse analysis.
- Common Functions: The SYN flood function is shared between ServStart (Nitol) and MrBlack (ChinaZ), indicating a potential link.
- File Infector: A Parite file infector was found in both Nitol and ChinaZ campaigns.
- Cryptographic Key: The 'Mother360' RC4 key is used in multiple Gh0st RAT variants, including those associated with ChinaZ and Iron Tiger APT, suggesting a shared tool or framework within the Chinese threat community.
Case Study: Gh0st RAT Variant
- Deployment: Gh0st RAT variants were found in ChinaZ HFS servers with names like 'BX.exe' and 'shadow.exe'.
- Cryptographic Key: The same RC4 key used in the Iron Tiger APT's Operation PZCHAO campaign was also found in these variants.
- C&C Decryption: This key was used to decrypt both C&C addresses and traffic between the client and the C&C server.
- Shared Artifacts: Some Gh0st RAT variants were found alongside Nitol artifacts, such as a malicious Usp10.dll.
- Stack String: A characteristic stack string at
WinMainwas used to identify different Gh0st RAT instances deployed by the same actor.
Conclusion and Future Investigation
- Community Linkage: There is evidence of code and artifact sharing between ChinaZ and Nitol, suggesting a potential connection or collaboration within the Chinese threat community.
- Monetization and Distribution: Chinese HFS panels are a common distribution method for DDoS tools and malware, indicating a well-established infrastructure.
- Shared Cryptographic Keys: The use of a common RC4 key across multiple Gh0st RAT variants suggests the presence of a shared tool or framework within the Chinese threat ecosystem.
- Future Research: Further investigation is needed to determine the exact relationships and operational structures between these groups, especially regarding the potential overlap between APT groups and DDoS campaigns.
展开完整摘要
试读结束,高清完整版pdf/doc/ppt,请点下载