Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cyberwarfare

Stealthy APT Gelsemium Seen Targeting Southeast Asian Government

A stealthy APT known as Gelsemium has been observed targeting a government entity in Southeast Asia for persistence and intelligence collection.

A stealthy advanced persistent threat (APT) actor known as Gelsemium has been observed targeting a government entity in Southeast Asia to establish persistence and collect intelligence, cybersecurity firm Palo Alto Networks reveals.

As part of the observed activity, spanning over a period of six months in late 2022 and into 2023, the threat actor deployed a variety of web shells to support lateral movement and malware delivery, along with backdoors, a Cobalt Strike beacon, and various other tools.

Palo Alto Networks did not make any claims regarding attribution, but noted that others linked Gelsemium to China in the past. 

The cybersecurity firm identified three web shells used in these attacks, namely reGeorg, China Chopper, and AspxSpy (publicly available). In some instances, the threat actor deployed a shell-like tool to run additional commands, and several privilege escalation tools.

At the next step, malware such as OwlProxy, SessionManager, a Cobalt Strike beacon, SpoolFool, and EarthWorm was deployed to ensure persistence in the compromised environment. To check systems’ internet connectivity, the attackers pinged a known Chinese web portal.

SessionManager is a custom backdoor for Internet Information Services (IIS) that allows attackers to run commands, download and upload files, and use the web server as a proxy, based on commands received via inbound HTTP requests.

Advertisement. Scroll to continue reading.

As part of the observed activity, Gelsemium unsuccessfully attempted to deploy SessionManager on victims’ network, Palo Alto Networks says.

Another custom tool, OwlProxy is an HTTP proxy that also has backdoor functionality, and which was previously used in attacks targeting governments in East Asia and the Middle East.

During the observed attack, after OwProxy’s deployment was blocked, the attackers attempted to use a replacement tool called EarthWorm, a publicly available SOCKS tunneler used by various Chinese threat actors in malicious attacks.

Gelsemium deployed EarthWorm to create a tunnel between their command-and-control (C&C) and the local area network.

For privilege escalation, the attackers used the Potato Suite (which includes the JuicyPotato, BadPotato, and SweetPotato tools), along with SpoolFool, a publicly available proof-of-concept (PoC) exploit targeting CVE-2022-21999 (a Windows Print Spooler bug).

Based on the unique combination of malware used in these attacks, such as SessionManager and OwlProxy, Palo Alto Networks believes that the observed activity can be attributed to the Gelsemium APT group.

Active since at least 2014, the group is known for the targeting of education, government, electronics manufacturers, and religious organizations, mainly in East Asia and the Middle East. The APT was seen targeting South Eastern governments as well.

Related: New ‘GoldenJackal’ APT Targets Middle East, South Asia Governments

Related: New ‘Sandman’ APT Group Hitting Telcos With Rare LuaJIT Malware

Related: Ivanti Zero-Day Exploited by APT Since at Least April in Norwegian Government Attack

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Today’s attackers are no longer breaking in — they’re logging in. Join this live webinar as we break down the modern identity attack chain and examine how recent breaches exploited weaknesses in authentication, identity verification, and access management processes.

Register

AI has accelerated both sides of the fight. Adversaries are weaponizing vulnerabilities faster, while defenders are racing to ship detections and configurations. Join this live webinar as we explore how to prove your controls actually hold against new threats, map your security maturity, and unite breach simulation with automated pentesting into a single, coordinated program.

Register

People on the Move

Stephen Garcia has been named Chief Information Security Officer at BreachRx.

Kasper Lindgaard has been appointed Vice President of Security Strategy at CoreView.

Chaim Mazal has been named Chief Information Security Officer at GitLab.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.