New Insights into ScanBox Keylogger Tactics Used in Targeted Attacks
Evidence is mounting around a series of targeted cyber campaigns linked to APT TA423, also known as Red Ladon. This China-based threat actor has been active in deploying the ScanBox reconnaissance tool, a JavaScript-based framework, aimed primarily at Australian companies and offshore energy operations in the South China Sea.
These cyber espionage efforts appear to have started in April 2022 and continued until mid-June 2022, according to a detailed analysis from the Threat Research Team at Proofpoint and PwC’s Threat Intelligence unit.
Researchers attribute these tactics to TA423, noting its moderate association with the Ministry of State Security (MSS) in Hainan Province, China. “Proofpoint assesses with moderate confidence that this activity may be attributable to the threat actor TA423 / Red Ladon,” the report states, referencing multiple credible assessments.
Historically, the MSS has been heavily involved in cyber operations, tasked with state security, intelligence gathering, and various espionage activities. A recent indictment from the U.S. Department of Justice highlights TA423’s role in supporting these intelligence operations.
Understanding ScanBox
At the core of these attacks is the ScanBox framework. This tool allows cybercriminals to conduct reconnaissance without deploying traditional malware. Instead, they can gather intelligence simply by executing JavaScript in a web browser.
ScanBox's capacity to operate without writing malware to disk makes it particularly insidious. "ScanBox is particularly dangerous as it doesn’t require malware to be successfully deployed to steal information – the keylogging functionality only requires the JavaScript code to execute in a web browser," researchers from PwC noted in their insights from prior campaigns.
In these watering hole attacks, adversaries strategically compromise websites frequented by potential victims. By loading the malicious JavaScript framework onto these sites, they can covertly capture data from users who unwittingly visit them.
The initial stages of TA423's campaigns commenced through phishing emails bearing titles like "Sick Leave," "User Research," or "Request Cooperation." Many of these messages masqueraded as communications from the fictitious "Australian Morning News," urging targets to navigate to the compromised website: australianmorningnews[.]com.
Victims who clicked the links were redirected to web pages mimicking legitimate news outlets like the BBC and Sky News, each laced with the ScanBox framework designed to capture keystrokes and other sensitive data.
Information harvested through ScanBox is vital for threat actors in executing subsequent phases of their operations. This reconnaissance can facilitate tailored attacks based on the specific vulnerabilities and characteristics of their targets, a process often encapsulated under browser fingerprinting.
ScanBox identifies and collects crucial data, such as the operating system, browser details, and various software components on the target's device. It even inspects installed browser extensions and plugins.
A noteworthy function of ScanBox lies in its use of WebRTC technology to establish direct communications. “The module implements WebRTC technology, allowing it to connect to a set of pre-configured targets,” researchers explained, highlighting the framework's sophisticated capabilities.
This functionality also allows attackers to use STUN (Session Traversal Utilities for NAT) methods, a protocol that lets real-time communications navigate network address translators, enhancing their ability to infiltrate systems effectively.
The Broader Implications
The motivations driving TA423 center around strategic interests in the South China Sea, particularly regarding recent geopolitical tensions surrounding Taiwan. As noted by Sherrod DeGrippo, the VP of Threat Research and Detection at Proofpoint, "This group specifically wants to know who is active in the region, and while we can’t say for sure, their focus on naval issues is likely to remain a constant priority in places like Malaysia, Singapore, Taiwan, and Australia.”
While the group's activities predominantly target the Asia-Pacific region, their operations have global repercussions. A 2021 indictment revealed that TA423 has previously infiltrated organizations across multiple countries, including the United States, Germany, Canada, and the United Kingdom, accumulating sensitive trade secrets and confidential information across various critical sectors.
Despite past indictments, analysts report that there hasn’t been a notable decrease in TA423’s operational capabilities. The expectation remains that they will persist in their espionage endeavors, continuing to prioritize intelligence-gathering missions aimed at state interests.
The evolution of tactics employed by groups like TA423 showcases the complexity and adaptability of cyber threat actors, underlining the necessity for organizations globally to bolster their defenses against such sophisticated cyber threats.