Targeted malware intended for Tibet Administration intercepted by researchers
Researchers from Alien Vault have recently detected several targeted attacks against Tibetan activist organizations including the Central Tibet Administration and International Campaign for Tibet. They believe these attacks originate from the same group of Chinese hackers that launched the ‘Nitro’ attacks against chemical and defense companies late last year and are aimed at both spying on and stealing sensitive information about these organizations’ activities and supporters.
The attacks begin with a simple spear phishing campaign that uses a contaminated Office file to exploit a known vulnerability in Microsoft's product. The information in the spear phishing email is related to the Kalachakra Initiation, a Tibetan religious festival that took place in early January. After further investigation, the researchers discovered that the malware being used in this attack is a variant of Gh0st RAT remote access trojan - a primary tool used in the Nitro attacks last year and the variant uncovered in these attacks seem to come from the same actors they say.