Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

Langsmith Bug can expose the Openai keys and users’ data through malicious agents

June 17, 2025

How to protect backups

June 17, 2025

Silver Fox Apt has on target Taiwan with sophisticated GH0Stcringe and Holdinghands Rats Malicious Programs

June 17, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » Chinese hackers are using the CloudScout toolkit to steal session cookies from cloud services
Global Security

Chinese hackers are using the CloudScout toolkit to steal session cookies from cloud services

AdminBy AdminOctober 28, 2024No Comments3 Mins Read
Steal Session Cookies
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


October 28, 2024Ravi LakshmananCloud Security / Cyber ​​Attack

Steal session cookies

A government organization and a religious organization in Taiwan have been targeted by a China-linked threat known as The elusive panda which infected them with a previously undocumented post-compromise toolkit codenamed CloudScout.

“The CloudScout toolkit is capable of extracting data from various cloud services using stolen web session cookies,” ESET security researcher An Ho said. “Through the CloudScout plug-in, it works seamlessly with MgBot, Evasive Panda’s proprietary malware framework.”

A Slovak cybersecurity company used .NET-based malware that was discovered between May 2022 and February 2023. It includes 10 different modules written in C#, three of which are designed to steal data from Google Drive, Gmail and Outlook. The purpose of the remaining modules remains unknown.

Cyber ​​security

Evasive Panda, also tracked as Bronze Highland, Daggerfly and StormBamboo, appears cyber espionage group which has a track record of strikes at various organizations in Taiwan and Hong Kong. He is also known for orchestrating attacks on watering holes and supply chains targeting the Tibetan diaspora.

What sets the threat actor apart from the rest is the use of multiple initial access vectors, ranging from newly discovered security flaws to hacking the supply chain by poisoning DNS, hacking victim networks, and deploying MgBot and Nightdoor.

ESET said the CloudScout modules are designed to hijack authenticated web browser sessions by stealing cookies and using them to gain unauthorized access to Google Drive, Gmail and Outlook. Each of these modules is deployed using the MgBot plugin, programmed in C++.

“At the heart of CloudScout is the CommonUtilities package, which provides all the necessary low-level libraries for the modules to work,” Ho explained.

“CommonUtilities contains quite a few custom-implemented libraries, despite the large availability of similar open-source libraries on the Internet. These custom libraries give developers more flexibility and control over the inner workings of their implant compared to open source alternatives.”

This includes –

  • HTTPAccess, which provides functions for handling HTTP communication
  • ManagedCookie, which provides functionality to manage cookies for web requests between CloudScout and the target service
  • Lumberjack
  • SimpleJSON

The information collected by the three modules—mail folder lists, email messages (including attachments), and files with specific extensions (.doc, .docx, .xls, .xlsx, .ppt, .pptx, .pdf, and .txt)—is compressed into ZIP archive for subsequent exfiltration by either MgBot or Nightdoor.

However, new security mechanisms introduced by Google, such as device-linked session credentials (DBSK) and App-bound encryption sure to make the cookie-stealing malware obsolete.

Cyber ​​security

“CloudScout is a .NET toolkit that Evasive Panda uses to steal data stored in cloud services,” Ho said. “It is implemented as an extension to MgBot and uses a cookie transfer technique to intercept authenticated sessions from web browsers.”

The development comes after the Canadian government accused a “sophisticated state-sponsored threat actor” from China of conducting extensive intelligence operations over several months against multiple domains in Canada.

“The majority of affected organizations were Government of Canada departments and agencies, as well as federal political parties, the House of Commons and the Senate,” it said. said in the statement.

“They also targeted dozens of organizations, including democratic institutions, critical infrastructure, the defense sector, media organizations, think tanks and non-governmental organizations.”

Did you find this article interesting? Follow us Twitter  and LinkedIn to read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

Langsmith Bug can expose the Openai keys and users’ data through malicious agents

June 17, 2025

How to protect backups

June 17, 2025

Silver Fox Apt has on target Taiwan with sophisticated GH0Stcringe and Holdinghands Rats Malicious Programs

June 17, 2025

Google warns about scattered spider attacks focused on IT -commander by US insurance firms

June 17, 2025

Password “B” in Sitecore XP Sparks Sparks Erriss RCE when deploying businesses

June 17, 2025

Are you forgotten accounts of advertising services that leave you risk?

June 17, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

Langsmith Bug can expose the Openai keys and users’ data through malicious agents

June 17, 2025

How to protect backups

June 17, 2025

Silver Fox Apt has on target Taiwan with sophisticated GH0Stcringe and Holdinghands Rats Malicious Programs

June 17, 2025

Google warns about scattered spider attacks focused on IT -commander by US insurance firms

June 17, 2025

Password “B” in Sitecore XP Sparks Sparks Erriss RCE when deploying businesses

June 17, 2025

Are you forgotten accounts of advertising services that leave you risk?

June 17, 2025

New Flodrix Botnet Option Operates Langflow Ai Server RCE BUG to launch DDOS ATTACKS

June 17, 2025

Lack of the TP-Link Cve-2023-33538 router under active operation, CISA releases an immediate warning

June 17, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Langsmith Bug can expose the Openai keys and users’ data through malicious agents

June 17, 2025

How to protect backups

June 17, 2025

Silver Fox Apt has on target Taiwan with sophisticated GH0Stcringe and Holdinghands Rats Malicious Programs

June 17, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.