
A Chinese-speaking threat actor called Scarab has been linked to a custom backdoor dubbed HeaderTip as part of a campaign targeting Ukraine since Russia embarked on an invasion last month, making it the second China-based hacking group after Mustang Panda to capitalize on the conflict.
“The malicious activity represents one of the first public examples of a Chinese threat actor targeting Ukraine since the invasion began,” SentinelOne researcher Tom Hegel said in a report published this week.
SentinelOne’s analysis follows an advisory from Ukraine’s Computer Emergency Response Team (CERT-UA) earlier this week outlining a spear-phishing campaign that leads to the delivery of a RAR archive file, which comes with an executable that’s designed to open a decoy file while stealthily dropping a malicious DLL called HeaderTip in the background.
Scarab was first documented by the Symantec Threat Hunter Team, part of Broadcom Software, in January 2015, when it detailed highly targeted attacks against Russian-speaking individuals since at least January 2012 to deploy a backdoor called Scieron. Read more:https://bit.ly/3LiRpDv