ZeroHour
Infosecurity Magazinepublished ()ingested Kevin Poireault

Chinese APT ToddyCat Targets Asian Telecoms, Governments

criticalExploit / PoCimportance 60CVE-2022-23748

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-23748
DLL Sideloading Vulnerability in Audinate Dante Discovery (mDNSResponder.exe)

Audinate Dante Discovery's mDNSResponder.exe executable improperly specifies how, from which folder, and under what conditions it loads DLLs, enabling a DLL sideloading attack (CWE-114/CWE-426). An attacker who can place a crafted malicious DLL where the legitimate executable searches for libraries can trigger it to be loaded when the binary runs; the CVSS vector (AV:L, UI:R) indicates local access and some user interaction are required to start the vulnerable process. Because the malicious code executes under the cover of a valid, legitimate executable, the attacker gains code execution with high impact on confidentiality, integrity, and availability. The flaw affects Windows hosts running Audinate's Dante Discovery component, which ships with Dante software tooling and the Dante Application Library used in professional audio networking deployments. It was added to the CISA Known Exploited Vulnerabilities catalog on 2025-02-06, confirming exploitation in the wild; EPSS puts the 30-day exploitation probability at 9.1% (95th percentile), no public PoC is known, and ransomware use is unknown.

Do: Apply Audinate's mitigations or upgrade Dante Discovery / Dante Application Library to the latest vendor-recommended release per the CISA KEV required action, and discontinue use of the affected component if mitigations are unavailable. On Windows hosts, check for unexpected or unrecognized DLL files in the directory from which mDNSResponder.exe runs (and its DLL search paths), and restrict write permissions on the application folder to prevent malicious DLL placement. Given the KEV listing and 95th-percentile EPSS, prioritize patching internet-relevant and audio-control workstations in broadcast, live production, and installed-sound environments.

7.89% KEV
  • Audinate Dante Discovery (Dante Application Library component, mDNSResponder.exe)
large≈ hundreds of thousands of Windows hosts running Audinate Dante software (Dante Controller/Discovery and Dante Application Library deployments)
Full article326 words · extracted from infosecurity-magazine.com · click to collapse

Written by

A new malicious espionage campaign is targeting telecommunications organizations and governments across Central and Southeast Asia, CheckPoint Research has discovered.

The campaign, which CheckPoint tracks as ‘Stayin’ Alive’, has been active since at least 2021 and is tied to the Chinese cyber espionage group ToddyCat.

The campaign leverages spear-phishing emails to deliver archived files using DLL side-loading schemes, hijacking dal_keepalives[dot]dll in Audinate’s Dante Discovery software (CVE-2022-23748).

CheckPoint also found several loaders and downloaders, some were used as initial infection vectors against high-profile Asian organizations in Kazakhstan, Uzbekistan, Pakistan, and Vietnam.

One of them, CurKeep, is deployed by running the legitimate executable, signed by Zoom, which loads dal_keepalives[dot]dll. The DLL file then loads CurKeep.

Other tools include CurLu, CurCore and StylerServ. They are all custom-made.

“The simplistic nature of the tools we observed in the campaign and their wide variation suggests they are disposable, mostly utilized to download and run additional payloads. These tools share no clear code overlaps with products created by any known actors and do not have much in common with each other,” reads the CheckPoint report.

Their infrastructure led CheckPoint researchers to attribute the campaign to ToddyCat, which likely conducted the Stayin’ Alive campaign as part of a much broader espionage campaign.

Who Is ToddyCat?

ToddyCat is a Chinese-affiliated advanced persistent threat (APT) group that has been active since at least 2020. The group is known for targeting high-profile organizations in Asia, including telecoms, government agencies, and military contractors.

The group uses various techniques to gain access to target systems, including spear-phishing emails, zero-day exploits, and supply chain attacks. Once ToddyCat has gained access to a system, the group can deploy various malware, including backdoors, trojans, and keyloggers.

Questions remain over ToddyCat's goals, but the group is believed to be motivated by espionage. The group has been known to steal sensitive data, such as intellectual property, trade secrets, and government documents.

Read more: Sophisticated APT Clusters Target Southeast Asia

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/chinese-apt-toddycat-asian/