National Cyber Warfare Foundation (NCWF)

TwoSail Junk


0 user ratings
2024-07-26 20:17:46
blscott

 - archive -- 


Alternate Group Names
Operation Poisoned News

TwoSail Junk directs visitors to its exploit site by posting
links within the threads of forum discussions, or creating new topic threads of
their own. To date, dozens of visits were recorded from within Hong Kong, with
a couple from Macau. The technical details around the functionality of the iOS
implant, called LightSpy, and related infrastructure, reveal a low-to-mid
capable actor. However, the iOS implant is a modular and exhaustively
functional iOS surveillance framework.



(Kaspersky) A watering hole was discovered on January 10,
2020 utilizing a full remote iOS exploit chain to deploy a feature-rich implant
named LightSpy. The site appears to have been designed to target users in Hong
Kong based on the content of the landing page. Since the initial activity, we
released two private reports exhaustively detailing spread, exploits,
infrastructure and LightSpy implants.



We are temporarily calling this APT group “TwoSail Junk”.
Currently, we have hints from known backdoor callbacks to infrastructure about
clustering this campaign with previous activity. And we are working with
colleagues to tie LightSpy with prior activity from a long running
Chinese-speaking APT group, previously reported on as \'Lotus Blossom, Spring
Dragon, Thrip\', known for their Lotus Elise and Evora backdoor malware.



Considering that this LightSpy activity has been disclosed
publicly by our colleagues from TrendMicro, we would like to further contribute
missing information to the story without duplicating content. And, in our quest
to secure technologies for a better future, we reported the malware and
activity to Apple and other relevant companies.



First seen- 2020



Targets- Hong Kong,



Tools-



dmsSpy (category:
Malware)


type: Reconnaissance, Backdoor, Info stealer, Exfiltration

(Trend Micro) Another APK link was disguised as a calendar application for
checking the schedule of upcoming political events in Hong Kong. Though the
link was also down, we managed to find the original file downloaded from it.
The calendar application shown above requires manysensitive permissions such as
READ_CONTACTS, RECEIVE_SMS, READ_SMS, CALL_PHONE, ACCESS_LOCATION, and
WRITE/READ EXTERNAL_STORAGE. When launched, it first collects device
information such as device ID, brand, model, OS version, physicallocation, and
SDcard file list. It then sends the collected information back to the C&C
server. It also steals contact and SMS information stored in the device.
Furthermore, it registers a receiver that monitors new incoming SMS messages
and syncs messages with the C&C server in real-time. The appcan perform an
update by querying the C&C server to fetch the URL of the latest APK file,
then download and install it.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=94171b88-29ea-4840-8f84-61096123d0b0

https://documents.trendmicro.com/assets/Tech-Brief-Operation-Poisoned-News-Hong-Kong-Users-Targeted-with-Mobile-Malware-via-Local-News-Links.pdf

https://securelist.com/ios-exploit-chain-deploys-lightspy-malware/96407/

https://blog.trendmicro.com/trendlabs-security-intelligence/operation-poisoned-news-hong-kong-users-targeted-with-mobile-malware-via-local-news-links/

https://malpedia.caad.fkie.fraunhofer.de/details/apk.dmsspy





lightSpy (category:
Malware)


type: Reconnaissance, Backdoor, Info stealer, Exfiltration

(Trend Micro) The iOS malware, which we named \'lightSpy\' (detected by Trend
Micro as IOS_LightSpy.A), is a modular backdoor that allowed the attacker to
remotely execute a shell command and manipulate files on the infected device.
It is also implemented with several functionalities through different modules
for exfiltrating data from the infected device including: • Hardware
information • Contacts • Keychain • SMS messages • Phone call history • GPS
location • Connected Wi-Fi history • Browser history of Safari and Chrome

The malware also reports the surrounding environment of the device by: •
Scanning local network IP address • Scanning available Wi-Fi network The
campaign also employs modules specifically designed to exfiltrate data from
popular messenger applications such as QQ, WeChat, and Telegram.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=4c9d4f77-ee82-4452-b187-84072275951e

https://documents.trendmicro.com/assets/Tech-Brief-Operation-Poisoned-News-Hong-Kong-Users-Targeted-with-Mobile-Malware-via-Local-News-Links.pdf

https://securelist.com/ios-exploit-chain-deploys-lightspy-malware/96407/

https://blog.trendmicro.com/trendlabs-security-intelligence/operation-poisoned-news-hong-kong-users-targeted-with-mobile-malware-via-local-news-links/

https://blogs.blackberry.com/en/2024/04/lightspy-returns-renewed-espionage-campaign-targets-southern-asia-possibly-india

https://www.threatfabric.com/blogs/lightspy-implant-for-macos

https://www.threatfabric.com/blogs/lightspy-implant-for-ios

https://www.lookout.com/threat-intelligence/article/wyrmspy-dragonegg-surveillanceware-apt41

https://blogs.blackberry.com/en/2024/11/lightspy-apt41-deploys-advanced-deepdata-framework-in-targeted-southern-asia-espionage-campaign

https://hunt.io/blog/lightspy-malware-targets-facebook-instagram

https://malpedia.caad.fkie.fraunhofer.de/details/ios.lightspy



Comments
new comment
Nobody has commented yet. Will you be the first?


a.k.a
Poisoned News
 




This link is from a restricted area of the forums.
Forum



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.