Cybersecurity Experts Alert to APT40’s Swift Adaptation Tactics Linked to China

Cybersecurity agencies from Australia, Canada, Germany, Japan, New Zealand, South Korea, the U.K., and the U.S. have issued a collaborative alert concerning a Chinese-linked cyber espionage group known as APT40. This advisory highlights the group’s capability to exploit newly uncovered security vulnerabilities within a matter of hours or days after they become publicly known.

“APT40 has a history of targeting entities across multiple nations, including Australia and the U.S.,” the advisory notes. “The group is adept at quickly adapting vulnerability proofs-of-concept (PoCs) for their own targeting, reconnaissance, and exploitation efforts.”

Also identified by other names such as Bronze Mohawk, Gingham Typhoon (formerly Gadolinium), ISLANDDREAMS, Kryptonite Panda, Leviathan, Red Ladon, TA423, and TEMP.Periscope, APT40 has been operational since at least 2011, focusing primarily on cyber attacks against organizations in the Asia-Pacific region. It is believed to operate from Haikou.

In July 2021, a formal attribution linked the group to China’s Ministry of State Security (MSS), with several of its members facing indictment for orchestrating a multi-year campaign targeting various sectors to steal trade secrets, intellectual property, and valuable information.

Recently, APT40 has been connected to attacks utilizing the ScanBox reconnaissance tool and exploiting a vulnerability in WinRAR (CVE-2023-38831, CVSS score: 7.8) through a phishing campaign aimed at Papua New Guinea, deploying a backdoor known as BOXRAT.

Earlier this year, in March, the New Zealand government connected APT40 to the breach of the Parliamentary Counsel Office and the Parliamentary Service in 2021.

“APT40 is proficient in discovering new exploits in widely used public software like Log4j, Atlassian Confluence, and Microsoft Exchange to target the associated vulnerabilities,” the advisory states.

“Regular reconnaissance is a hallmark of APT40’s strategy, including probing networks of interest in the agencies’ countries, seeking opportunities to breach targets. This proactive approach enables the group to quickly identify and exploit vulnerable, outdated, or unsupported devices on these networks.”

The group’s tactics include deploying web shells to maintain persistent access and utilizing Australian websites for command-and-control (C2) operations. They also use outdated or unpatched devices, such as small-office/home-office (SOHO) routers, to facilitate their attacks and avoid detection—strategies reminiscent of those used by other China-based groups like Volt Typhoon.

According to Mandiant, a Google-owned cybersecurity firm, this reflects a broader shift in Chinese cyber espionage practices towards increased stealth, focusing on weaponizing network edge devices, operational relay box (ORB) networks, and living-off-the-land (LotL) techniques to avoid detection.

APT40’s attack methods typically involve reconnaissance, privilege escalation, and lateral movement using remote desktop protocol (RDP) to capture credentials and exfiltrate sensitive data.

To counter these threats, organizations are advised to implement robust logging practices, enforce multi-factor authentication (MFA), maintain an effective patch management system, replace outdated equipment, disable unnecessary services, ports, and protocols, and segment networks to safeguard sensitive information.

More Articles & Posts