Daily Tech News, Interviews, Reviews and Updates

Iron Tiger used compromised servers of MiMi to launch malware

In recent attacks, cyberespionage group Iron Tiger abused the compromised servers of MiMi – an instant messaging application available on Windows, macOS, Android and iOS. The advanced persistent threat (APT) group used the server to deliver malware. The desktop version of the chat application is built using the cross-platform framework ElectronJS.  

Iron Tiger has been active since around 2010. It is known to have targeted hundreds of organizations worldwide for cyberespionage purposes. The group is also referred to as APT27, Bronze Union, Emissary Panda, Lucky Mouse and TG-3390 (Threat Group 3390). 

According to reports, Iron Tiger compromised the server hosting the legitimate installers of the chat installer for a supply chain attack. Trend Micro downloaded a malicious MiMi installer for macOS this June from the legitimate severs and later reported the ongoing complication.

The sample was capable of fetching ‘rshell’, a macOS backdoor. This can further collect system information and send it to the command and control (C&C) server. Along with it, it could execute commands that it receives from its operators and then sends the results to the C&C. 

After that, based on the commands received, the backdoor can open or close a shell, execute commands in a shell, list our directories, read files, write to a file, close a file, prepare files for download or upload or even delete files. 

Reports by Trend Micro asserted that they have found multiple rshell samples. This een includes some that targets Linux. The last of these samples was uploaded in June 2021. 

 



Readers like you help support The Tech Outlook. When you make a purchase using links on our site, we may earn an affiliate commission. We cannot guarantee the Product information shown is 100% accurate and we advise you to check the product listing on the original manufacturer website. Thetechoutlook is not responsible for price changes carried out by retailers. The discounted price or deal mentioned in this item was available at the time of writing and may be subject to time restrictions and/or limited unit availability. Amazon and the Amazon logo are trademarks of Amazon.com, Inc. or its affiliates Read More
You might also like

This website uses cookies to improve your experience. We'll assume you're ok with this, but you can opt-out if you wish. Accept Read More