By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: Chinese APT41 Upgrades Malware Arsenal with DodgeBox and MoonWalk
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > Chinese APT41 Upgrades Malware Arsenal with DodgeBox and MoonWalk
Tech News

Chinese APT41 Upgrades Malware Arsenal with DodgeBox and MoonWalk

By Viral Trending Content 4 Min Read
Share
SHARE

Jul 11, 2024NewsroomCyber Espionage / Network Security

Chinese APT41

The China-linked advanced persistent threat (APT) group codenamed APT41 is suspected to be using an “advanced and upgraded version” of a known malware called StealthVector to deliver a previously undocumented backdoor dubbed MoonWalk.

The new variant of StealthVector – which is also referred to as DUSTPAN – has been designated DodgeBox by Zscaler ThreatLabz, which discovered the loader strain in April 2024.

“DodgeBox is a loader that proceeds to load a new backdoor named MoonWalk,” security researchers Yin Hong Chang and Sudeep Singh said. “MoonWalk shares many evasion techniques implemented in DodgeBox and utilizes Google Drive for command-and-control (C2) communication.”

APT41 is the moniker assigned to a prolific state-sponsored threat actor affiliated with China that’s known to be active since at least 2007. It’s also tracked by the broader cybersecurity community under the names Axiom, Blackfly, Brass Typhoon (formerly Barium), Bronze Atlas, Earth Baku, HOODOO, Red Kelpie, TA415, Wicked Panda, and Winnti.

Cybersecurity

In September 2020, the U.S. Department of Justice (DoJ) announced the indictment of several threat actors associated with the hacking crew for orchestrating intrusion campaigns targeting more than 100 companies across the world.

“The intrusions […] facilitated the theft of source code, software code signing certificates, customer account data, and valuable business information,” the DoJ said at the time, adding they also enabled “other criminal schemes, including ransomware and ‘crypto-jacking’ schemes.”

Over the past few years, the threat group has been linked to breaches of U.S. state government networks between May 2021 and February 2022, in addition to attacks targeting Taiwanese media organizations using an open-source red teaming tool known as Google Command and Control (GC2).

Chinese APT41

The use of StealthVector by APT41 was first documented by Trend Micro in August 2021, describing it as a shellcode loader written in C/C++ that’s used to deliver Cobalt Strike Beacon and a shellcode implant named ScrambleCross (aka SideWalk).

DodgeBox is assessed to be an improved version of StealthVector, while also incorporating various techniques like call stack spoofing, DLL side-loading, and DLL hollowing to evade detection. The exact method by which the malware is distributed is presently unknown.

“APT41 employs DLL side-loading as a means of executing DodgeBox,” the researchers said. “They utilize a legitimate executable (taskhost.exe), signed by Sandboxie, to sideload a malicious DLL (sbiedll.dll).”

Cybersecurity

The rogue DLL (i.e., DodgeBox) is a DLL loader written in C that acts as a conduit to decrypt and launch a second-stage payload, the MoonWalk backdoor.

The attribution of DodgeBox to APT41 stems from the similarities between DodgeBox and StealthVector; the use of DLL side-loading, a technique widely employed by China-nexus groups to deliver malware such as PlugX; and the fact that DodgeBox samples have been submitted to VirusTotal from Thailand and Taiwan, regions that are of strategic interest to China.

“DodgeBox is a newly identified malware loader that employs multiple techniques to evade both static and behavioral detection,” the researchers said.

“It offers various capabilities, including decrypting and loading embedded DLLs, conducting environment checks and bindings, and executing cleanup procedures.”

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.

You Might Also Like

Big data is transforming gaming experiences in Ireland

Commodore 64 Ultimate Review: An Astonishing Remake

Best New Tablet of the Year: Tech Advisor Awards 2025-26

Mustang Panda Uses Signed Kernel-Mode Rootkit to Load TONESHELL Backdoor

Samsung Galaxy Z Fold 8 Wide Edition: Features and Specs

TAGGED: Advanced Persistent Threat, Chinese Hackers, cyber espionage, Cyber Security, Internet, Malware, network security, Threat Intelligence
Share This Article
Facebook Twitter Copy Link
Previous Article Influencers Are Racing to Profit From the Trump Shooting
Next Article Thomas Matthew Crooks: What we know about the Trump attacker
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

How a governance failure led to the Unleash Protocol hack
Crypto
Shiba Inu Lead Dev Issues Must-Read Year-End Letter: What You Must Know
Crypto
Big data is transforming gaming experiences in Ireland
Tech News
Want to be a hit in the stock market? Here are 3 things super-successful investors do
Business
German paratrooper unit probed over alleged abuse, antisemitism and violence
World News
Asim Munir marries daughter to brother's son in Pakistan Army headquarters in Rawalpindi
Business
Today in History: December 30, Bill Cosby charged with sexual assault
World News

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

How a governance failure led to the Unleash Protocol hack

Investing £5 a day could help me build a second income of £329 a month!

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
How a governance failure led to the Unleash Protocol hack
December 30, 2025
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?