Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cyberwarfare

Stealthy APT Gelsemium Seen Targeting Southeast Asian Government

A stealthy APT known as Gelsemium has been observed targeting a government entity in Southeast Asia for persistence and intelligence collection.

A stealthy advanced persistent threat (APT) actor known as Gelsemium has been observed targeting a government entity in Southeast Asia to establish persistence and collect intelligence, cybersecurity firm Palo Alto Networks reveals.

As part of the observed activity, spanning over a period of six months in late 2022 and into 2023, the threat actor deployed a variety of web shells to support lateral movement and malware delivery, along with backdoors, a Cobalt Strike beacon, and various other tools.

Palo Alto Networks did not make any claims regarding attribution, but noted that others linked Gelsemium to China in the past. 

The cybersecurity firm identified three web shells used in these attacks, namely reGeorg, China Chopper, and AspxSpy (publicly available). In some instances, the threat actor deployed a shell-like tool to run additional commands, and several privilege escalation tools.

At the next step, malware such as OwlProxy, SessionManager, a Cobalt Strike beacon, SpoolFool, and EarthWorm was deployed to ensure persistence in the compromised environment. To check systems’ internet connectivity, the attackers pinged a known Chinese web portal.

SessionManager is a custom backdoor for Internet Information Services (IIS) that allows attackers to run commands, download and upload files, and use the web server as a proxy, based on commands received via inbound HTTP requests.

Advertisement. Scroll to continue reading.

As part of the observed activity, Gelsemium unsuccessfully attempted to deploy SessionManager on victims’ network, Palo Alto Networks says.

Another custom tool, OwlProxy is an HTTP proxy that also has backdoor functionality, and which was previously used in attacks targeting governments in East Asia and the Middle East.

During the observed attack, after OwProxy’s deployment was blocked, the attackers attempted to use a replacement tool called EarthWorm, a publicly available SOCKS tunneler used by various Chinese threat actors in malicious attacks.

Gelsemium deployed EarthWorm to create a tunnel between their command-and-control (C&C) and the local area network.

For privilege escalation, the attackers used the Potato Suite (which includes the JuicyPotato, BadPotato, and SweetPotato tools), along with SpoolFool, a publicly available proof-of-concept (PoC) exploit targeting CVE-2022-21999 (a Windows Print Spooler bug).

Based on the unique combination of malware used in these attacks, such as SessionManager and OwlProxy, Palo Alto Networks believes that the observed activity can be attributed to the Gelsemium APT group.

Active since at least 2014, the group is known for the targeting of education, government, electronics manufacturers, and religious organizations, mainly in East Asia and the Middle East. The APT was seen targeting South Eastern governments as well.

Related: New ‘GoldenJackal’ APT Targets Middle East, South Asia Governments

Related: New ‘Sandman’ APT Group Hitting Telcos With Rare LuaJIT Malware

Related: Ivanti Zero-Day Exploited by APT Since at Least April in Norwegian Government Attack

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we explore why exploitation is outpacing remediation, where risk is growing fastest, and what security leaders can do to close the gap before attackers take advantage.

Register

CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!

Register

People on the Move

The Department of Energy has appointed Andrew McClure as Director of the Office of Cybersecurity, Energy Security, and Emergency Response (CESER).

Sumo Logic has appointed Chris Malone as CEO and Conor Burns as CFO.

Nozomi Networks has appointed co-founder Andrea Carcano as CEO.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.