Tick advanced persistent threat (APT) group hacked an East Asian data loss prevention (DLP) Software Firm. ESET researchers discovered that this group breached its update servers to deliver malware into the company’s network.
They then exploited trojanized installers of legitimate tools used by the company, leading to the compromise of two customers of DLP firm.
Threat Intelligence Report
Threat Intelligence Reports are a popular way for many companies to stay abreast of recent attack trends and predict what type of attacks may come next. These reports offer invaluable insights that help customers evaluate their information security programs and develop the skillset needed to withstand a wide variety of hazards.
ESET researchers recently identified an attack attributed to the Tick APT Group. This group targeted an East Asian DLP Software Firm and breached two of its clients by using various malware families on both internal update servers as well as third-party tools used for customer system management.
ESET researchers believe the cybercriminals sought to gain access to sensitive data at the company and steal confidential information for use in further intrusions.
Tick has a history of exploiting the ProxyLogon vulnerability to deliver ransomware and other malicious payloads. Additionally, it employs custom malware arsenals for persistence, reconnaissance, and data exfiltration.
The Tick APT group has been active since at least 2006, primarily targeting the Asia-Pacific region with their malware arsenal consisting of Locky ransomware and banking Trojans such as Dridex. Their attacks span multiple industry sectors such as education, finance, healthcare and hospitality across multiple countries worldwide.
Furthermore, the Tick APT group has been known to steal intellectual property from victims, potentially impacting their business and competitive edge. Furthermore, they have been accused of engaging in credential harvesting and automated exploitation activities.
Research by X-Force found that the financial industry was one of the most heavily targeted industries in 2019. Banking Trojans were particularly prevalent, and in 2019 X-Force observed these threats being actively developed and refined by threat actors – leading to an exponential rise in new strains of these threats.
Cybercrime is a lucrative target for threat actors, providing them with steady funds and rewards for successful attacks. The financial industry in particular appeals to hackers due to the large number of companies affected by it. Furthermore, this sector contains valuable data such as credit card details which could be mined by malicious actors.
Winnti Group
The Winnti Group, also known as APT41, Barium, Blackfly, Double Dragon and Wicked Panda among others, has had a long-running presence in the security industry. They are known for both cyberespionage operations and financially motivated attacks against various organizations around the world.
The Winnti Group has been active since 2007, targeting victims across numerous industries such as health, telecoms, high-tech, media, agriculture and education. Hackers typically launch their campaigns via spearphishing emails, stealing hundreds of gigabytes of information in the process.
In 2010, HBGary Security identified a security breach associated with the Winnti Group. Hackers gained access to an arcade video game company’s build environment in order to compromise legitimate software applications using PlugX, a backdoor with Chinese origins that had only previously been seen in attacks targeting Tibetan activists.
Over the years, this group’s attacks have targeted several gaming companies, including an American MMO-game publisher that was digitally signed with a stolen certificate from Kaspersky. These certificates were obtained from Chinese groups with connections to other hacker gangs.
Our investigation revealed that the Winnti Group has been theft digital code signing certificates for some time and selling them on the Chinese black market. This activity is similar to other Chinese cybercriminal gangs which collaborate in malware development and infrastructure.
Furthermore, The Winnti Group has been employing various malware toolsets and backdoors in its campaigns. Spyder Loader, a popular malware toolkit, is often utilized. This program can launch malware from a remote server, download data from the victim’s system, and store it locally on their hard disk.
Notably, the Winnti Group has also been observed exploiting automated build systems used by video game developers in South Korea and Taiwan. By taking control of the building software, attackers were able to include malicious coding within executable video game files.
The group also compromised an East Asian DLP software firm, stealing vast amounts of data and abusing known bugs. According to Cybereason’s report, they were able to conceal their activities inside the target’s network for over a year while amassing large caches of information. This persistence suggests they are highly motivated in stealing valuable intellectual property.
Tick APT Group
ESET reported the Tick APT Group had successfully exploited a ProxyLogon vulnerability in March 2021 to gain access to an East Asian DLP software firm with high-value customer portfolio including military and government organizations. Tick then utilized modified Q-Dir software to drop ReVBShell, an open-source VBScript backdoor, into their network.
Based on Tick’s profile and the compromised company’s high-value customer portfolio, this operation appears to have been cyberespionage. The attackers infiltrated DLP company’s internal update servers with malware, then trojanized installers of legitimate tools used by them that ultimately executed malware on customers’ devices.
Tick APT is an advanced persistent threat (APT) group that targets countries in the Asia-Pacific region and has a history of cyberespionage operations against Japanese companies, such as defense, manufacturing and biotechnology firms. It uses its own custom malware toolset for persistent access to compromised machines, reconnaissance, data exfiltration and download of tools.
The Tick APT Group first gained notoriety within the security community several years ago when they exploited ProxyLogon vulnerability, then a zero-day. This flaw allowed attackers to leverage webshells in order to gain remote code execution (RCE) access to targeted systems.
Researchers suspect the Tick APT Group is connected to China and specializes in attacking Japan’s defense, government, and manufacturing sectors. Furthermore, they conduct cyberespionage against other East Asian nations such as South Korea, Indonesia, and Singapore.
The Tick APT Group, active since 2006, targets organizations around the world with stealthy theft of intellectual property and classified data. With a particular focus on Asia-Pacific regions but presence across North America and Europe as well, their main tactics involve spearphishing emails using open-source malware and conducting DDoS attacks. Tick APT also employs custom malware such as Minzen, Daserf and HomamDownloader which have all been used successfully by them in past attacks.
China’s State-Sponsored Cybercriminals
Chinese cyberespionage group Tick has recently infiltrated an East Asian data loss prevention software firm and spread malware throughout their network and on customers’ computers. According to cybersecurity research firm ESET, this attack was carried out in March 2021 by an advanced persistent threat (APT) known as Tick.
Tick is a well-known Chinese APT that has been active since 2006 and primarily targets attacks in the Asia Pacific region. Its phishing campaigns can be sophisticated, and its hackers have an impressive record for exploiting zero-day vulnerabilities to infiltrate networks.
Security researchers recently uncovered China’s state-sponsored hackers are employing techniques that circumvent traditional cyber defense tools. They are infiltrating government and business networks, as well as spying on systems without typically installed anti-virus or endpoint detection protections.
It has become an increasing concern among cybersecurity professionals. Over the past year, China’s cyberattacks on businesses in telecommunications, retail and professional services have seen a dramatic spike.
Many attacks involve the supply chain. Hackers infiltrate suppliers and take advantage of valuable data about products being shipped out to consumers.
These attacks are a grave issue, as they can expose sensitive customer data and cause financial harm. This is particularly pertinent to the telecommunications sector, where suppliers provide telecom companies with equipment that helps safeguard their networks and customers’ communications.
Another major concern is the rise of Chinese cybercriminals who are targeting systems outside corporate firewalls. These hackers compromise devices at the edge of a network, such as routers or web servers, by exploiting software without typically having antivirus or endpoint protection built-in.
Josephine Wolff, associate professor of cybersecurity policy at Tufts University, noted that these hacks are being carried out by groups of cybercriminals with an intent to steal intellectual property. In some cases, these organizations have even hired mercenaries to execute these attacks on their behalf.
The United States, Australia and other countries have accused China’s Ministry of State Security of sponsoring and aiding these hackers. These alleged actions stand in stark contrast to their pledges not to use cyber-enabled theft of intellectual property or confidential information for commercial gain.


