Alternate Group Names
Operation Poisoned News,
TwoSail Junk directs visitors to its exploit site by posting
links within the threads of forum discussions, or creating new topic threads of
their own. To date, dozens of visits were recorded from within Hong Kong, with
a couple from Macau. The technical details around the functionality of the iOS
implant, called LightSpy, and related infrastructure, reveal a low-to-mid
capable actor. However, the iOS implant is a modular and exhaustively
functional iOS surveillance framework.
(Kaspersky) A watering hole was discovered on January 10,
2020 utilizing a full remote iOS exploit chain to deploy a feature-rich implant
named LightSpy. The site appears to have been designed to target users in Hong
Kong based on the content of the landing page. Since the initial activity, we
released two private reports exhaustively detailing spread, exploits,
infrastructure and LightSpy implants.
We are temporarily calling this APT group “TwoSail Junk”.
Currently, we have hints from known backdoor callbacks to infrastructure about
clustering this campaign with previous activity. And we are working with
colleagues to tie LightSpy with prior activity from a long running
Chinese-speaking APT group, previously reported on as \'Lotus Blossom, Spring
Dragon, Thrip\', known for their Lotus Elise and Evora backdoor malware.
Considering that this LightSpy activity has been disclosed
publicly by our colleagues from TrendMicro, we would like to further contribute
missing information to the story without duplicating content. And, in our quest
to secure technologies for a better future, we reported the malware and
activity to Apple and other relevant companies.
First seen- 2020
Targets- Hong Kong,
Tools-
dmsSpy (category:
Malware)
type: Reconnaissance, Backdoor, Info stealer, Exfiltration
(Trend Micro) Another APK link was disguised as a calendar application for
checking the schedule of upcoming political events in Hong Kong. Though the
link was also down, we managed to find the original file downloaded from it.
The calendar application shown above requires manysensitive permissions such as
READ_CONTACTS, RECEIVE_SMS, READ_SMS, CALL_PHONE, ACCESS_LOCATION, and
WRITE/READ EXTERNAL_STORAGE. When launched, it first collects device
information such as device ID, brand, model, OS version, physicallocation, and
SDcard file list. It then sends the collected information back to the C&C
server. It also steals contact and SMS information stored in the device.
Furthermore, it registers a receiver that monitors new incoming SMS messages
and syncs messages with the C&C server in real-time. The appcan perform an
update by querying the C&C server to fetch the URL of the latest APK file,
then download and install it.
https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=94171b88-29ea-4840-8f84-61096123d0b0
https://documents.trendmicro.com/assets/Tech-Brief-Operation-Poisoned-News-Hong-Kong-Users-Targeted-with-Mobile-Malware-via-Local-News-Links.pdf
https://securelist.com/ios-exploit-chain-deploys-lightspy-malware/96407/
https://blog.trendmicro.com/trendlabs-security-intelligence/operation-poisoned-news-hong-kong-users-targeted-with-mobile-malware-via-local-news-links/
https://malpedia.caad.fkie.fraunhofer.de/details/apk.dmsspy
lightSpy (category:
Malware)
type: Reconnaissance, Backdoor, Info stealer, Exfiltration
(Trend Micro) The iOS malware, which we named \'lightSpy\' (detected by Trend
Micro as IOS_LightSpy.A), is a modular backdoor that allowed the attacker to
remotely execute a shell command and manipulate files on the infected device.
It is also implemented with several functionalities through different modules
for exfiltrating data from the infected device including: • Hardware
information • Contacts • Keychain • SMS messages • Phone call history • GPS
location • Connected Wi-Fi history • Browser history of Safari and Chrome
The malware also reports the surrounding environment of the device by: •
Scanning local network IP address • Scanning available Wi-Fi network The
campaign also employs modules specifically designed to exfiltrate data from
popular messenger applications such as QQ, WeChat, and Telegram.
https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=4c9d4f77-ee82-4452-b187-84072275951e
https://documents.trendmicro.com/assets/Tech-Brief-Operation-Poisoned-News-Hong-Kong-Users-Targeted-with-Mobile-Malware-via-Local-News-Links.pdf
https://securelist.com/ios-exploit-chain-deploys-lightspy-malware/96407/
https://blog.trendmicro.com/trendlabs-security-intelligence/operation-poisoned-news-hong-kong-users-targeted-with-mobile-malware-via-local-news-links/
https://blogs.blackberry.com/en/2024/04/lightspy-returns-renewed-espionage-campaign-targets-southern-asia-possibly-india
https://www.threatfabric.com/blogs/lightspy-implant-for-macos
https://www.threatfabric.com/blogs/lightspy-implant-for-ios
https://www.lookout.com/threat-intelligence/article/wyrmspy-dragonegg-surveillanceware-apt41
https://blogs.blackberry.com/en/2024/11/lightspy-apt41-deploys-advanced-deepdata-framework-in-targeted-southern-asia-espionage-campaign
https://hunt.io/blog/lightspy-malware-targets-facebook-instagram
https://malpedia.caad.fkie.fraunhofer.de/details/ios.lightspy
