LuoYu, the eavesdropper sneaking in multiple platforms
Abstract
We will present our most recent research on a new Chinese APT group Luoyu, which has not yet been grouped by the public. Luoyu is originally a Chinese mythological creature which was a fish with wings. The creature can swim in the river and fly in the sky, similar to the group which can intrude multiple platforms.
We have first found attacks from Luoyu against China in 2014, and kept following the group. Later in 2017, we found this group starting to attack Japan, South Korea, and Taiwan. We believe the attacks were from China because the TTPs they used were popular among Chinese APT groups. However, instead of attacking government agencies, which are usually Chinese actors’ favorite target, the group aimed at messaging apps. We believe this indicates the group might try to censor the people who are using these messaging apps.
In this presentation, we seek to shed a light on Luoyu’s campaigns and provide an analysis on the tool they used. We will provide case studies of their attacks, showing different TTPs they deployed in various attacks. We will also introduce their self-developed malware, ReverseWindow, which can be found on multiple platforms. We hope our findings can help related industries to develop a better defense against the APT group.
Speaker
Shui Lee
Leon Chang
Slides
English