ZeroHour
Recorded Futurepublished ()ingested Insikt Group®

China-Nexus TAG-112 Compromises Tibetan Websites to Distribute Cobalt Strike

highVulnerabilityimportance 42

Indicators of compromiseAll →

TypeIndicatorContext
domaincheckupdate.maskrisks.commecheap, with subdomains such as mail[.]maskrisks[.]com and checkupdate[.]maskrisks[.]com added for further operational flexibility. TAG-112’s Us
domaindnspod.cn500d2a45f412f9434287161de395a35ef5b4931cba12cf513b76962(*[.]dnspod[.]cn) 94569f64f62eff185ba47e991dba54bdeea6d1a9e205d6bec767be6a
domaingyudmedtantricuniversity.orgibet Post (tibetpost[.]net) and Gyudmed Tantric University (gyudmedtantricuniversity[.]org). The attackers exploited vulnerabilities in the Joomla c
domainmail.maskrisks.comed in March 2024 through Namecheap, with subdomains such as mail[.]maskrisks[.]com and checkupdate[.]maskrisks[.]com added for further ope
domainmaskrisks.comrs, some active as early as March 2024. The primary domain, maskrisks[.]com, was registered in March 2024 through Namecheap, with sub
domaintibetpost.netomised at least two Tibetan community websites: Tibet Post (tibetpost[.]net) and Gyudmed Tantric University (gyudmedtantricuniversity
domainupdate.maskrisks.comconnection with TAG-112’s command-and-control (C2) domain, update[.]maskrisks[.]com, which then returns an HTML page spoofing a legitimate
sha1d4938cb5c031ec7f04d73d4e75f5db5c8a5c04ce5d6bec767be6a864e4efb (Cloudflare Origin *.maskrisks[.]com) d4938cb5c031ec7f04d73d4e75f5db5c8a5c04ce (Stolen code-signing certificate KP MOBILE) URLs of malicio
sha2560e306c0836a8ee035ae739c5adfbe42bd5021e615ebaa92f52d5d86fb895651dbe23055e921eff46e5e6921ff1a20bb903fca83ea1f1294394c0df3f4cd 0e306c0836a8ee035ae739c5adfbe42bd5021e615ebaa92f52d5d86fb895651d f1f11e52a60e5a446f1eb17bb718358def4825342acc0a41d09a051359a
sha2561e42cbe23055e921eff46e5e6921ff1a20bb903fca83ea1f1294394c0df3f4cdche https[:]//update[.]maskrisks[.]com/cache Cobalt Strike: 1e42cbe23055e921eff46e5e6921ff1a20bb903fca83ea1f1294394c0df3f4cd 0e306c0836a8ee035ae739c5adfbe42bd5021e615ebaa92f52d5d86fb89
sha2561e7cb19f77206317c8828f9c3cdee76f2f0ebf7451a625641f7d22bb8c61b21b11dcc598922e4ab9ce5524110a8bfd2c6b6db540d180829ceb7a7253831 1e7cb19f77206317c8828f9c3cdee76f2f0ebf7451a625641f7d22bb8c61b21b Loaders: 8d4049ef70c83a6ead26736c1330e2783bdc9708c497183317
sha25631f11b4d81f3ae25b6a01cd1038914f31d045bc4136c40a6221944ea553d641437ad9253b1cabee1cee7ef080ddf52d1b378c (legitimate software) 31f11b4d81f3ae25b6a01cd1038914f31d045bc4136c40a6221944ea553d6414 Appendix B — Mitre ATT&CK Techniques Tactic: Technique ATT&
sha2568d4049ef70c83a6ead26736c1330e2783bdc9708c497183317fad66b818e44cb17c8828f9c3cdee76f2f0ebf7451a625641f7d22bb8c61b21b Loaders: 8d4049ef70c83a6ead26736c1330e2783bdc9708c497183317fad66b818e44cb E190c7e097a1c38dd45d9c149e737ad9253b1cabee1cee7ef080ddf52d1
sha25694569f64f62eff185ba47e991dba54bdeea6d1a9e205d6bec767be6a864e4efb9434287161de395a35ef5b4931cba12cf513b76962(*[.]dnspod[.]cn) 94569f64f62eff185ba47e991dba54bdeea6d1a9e205d6bec767be6a864e4efb (Cloudflare Origin *.maskrisks[.]com) d4938cb5c031ec7f04d73
sha256966d311dcc598922e4ab9ce5524110a8bfd2c6b6db540d180829ceb7a72538313a67480a0e2a822af1e87a727243dea16ac1a3c0513aec62bff71f06b27 966d311dcc598922e4ab9ce5524110a8bfd2c6b6db540d180829ceb7a7253831 1e7cb19f77206317c8828f9c3cdee76f2f0ebf7451a625641f7d22bb8c6
sha256d0972247c500d2a45f412f9434287161de395a35ef5b4931cba12cf513b76962.90.62[.]12 154.90.63[.]166 154.205.138[.]202 Certificates: d0972247c500d2a45f412f9434287161de395a35ef5b4931cba12cf513b76962(*[.]dnspod[.]cn) 94569f64f62eff185ba47e991dba54bdeea6d1a9e2
sha256e190c7e097a1c38dd45d9c149e737ad9253b1cabee1cee7ef080ddf52d1b378c9ef70c83a6ead26736c1330e2783bdc9708c497183317fad66b818e44cb E190c7e097a1c38dd45d9c149e737ad9253b1cabee1cee7ef080ddf52d1b378c (legitimate software) 31f11b4d81f3ae25b6a01cd1038914f31d045
sha256f1f11e52a60e5a446f1eb17bb718358def4825342acc0a41d09a051359a1eb3dc0836a8ee035ae739c5adfbe42bd5021e615ebaa92f52d5d86fb895651d f1f11e52a60e5a446f1eb17bb718358def4825342acc0a41d09a051359a1eb3d f4ded3a67480a0e2a822af1e87a727243dea16ac1a3c0513aec62bff71f
sha256f4ded3a67480a0e2a822af1e87a727243dea16ac1a3c0513aec62bff71f06b27e52a60e5a446f1eb17bb718358def4825342acc0a41d09a051359a1eb3d f4ded3a67480a0e2a822af1e87a727243dea16ac1a3c0513aec62bff71f06b27 966d311dcc598922e4ab9ce5524110a8bfd2c6b6db540d180829ceb7a72
Full article1,039 words · extracted from recordedfuture.com · click to collapse

Summary

In a recent cyber campaign, the Chinese state-sponsored threat group TAG-112 compromised two Tibetan websites, Tibet Post and Gyudmed Tantric University, to deliver the Cobalt Strike malware. Recorded Future’s Insikt Group discovered that the attackers embedded malicious JavaScript in these sites, which spoofed a TLS certificate error to trick visitors into downloading a disguised security certificate. This malware, often used by threat actors for remote access and post-exploitation, highlights a continued cyber-espionage focus on Tibetan entities. TAG-112’s infrastructure, concealed using Cloudflare, links this campaign to other China-sponsored operations, particularly TAG-102 (Evasive Panda).

Cyberattacks targeting ethnic and religious minority groups in China continue, with new developments pointing to a targeted campaign against Tibetan organizations. In a recent investigation, Recorded Future’s Insikt Group discovered a Chinese state-sponsored threat actor group, designated TAG-112, responsible for compromising Tibetan community websites and delivering Cobalt Strike, a potent cyber-espionage tool.

Key Findings

In late May 2024, TAG-112 compromised at least two Tibetan community websites: Tibet Post (tibetpost[.]net) and Gyudmed Tantric University (gyudmedtantricuniversity[.]org). The attackers exploited vulnerabilities in the Joomla content management system (CMS) used by these sites to implant malicious JavaScript. This JavaScript prompted visitors to download a fake security certificate, which, when opened, deployed the Cobalt Strike payload.

TAG-112’s infrastructure shows notable overlap with TAG-102 (Evasive Panda), a more sophisticated Chinese state-sponsored group known for targeting Tibetan entities. However, Insikt Group has identified TAG-112 as a separate entity due to differences in attack maturity and tactics, such as using Cobalt Strike rather than custom malware and foregoing JavaScript obfuscation.

Malicious JavaScript and Spoofed TLS Error

The attack begins with the malicious JavaScript embedded in the compromised websites. When a user visits one of these sites, the script detects the operating system and browser type, confirming compatibility with Windows. If compatible, the script initiates a connection with TAG-112’s command-and-control (C2) domain, update[.]maskrisks[.]com, which then returns an HTML page spoofing a legitimate TLS certificate error.

This spoofed error page is crafted to mimic Google Chrome’s TLS certificate warning, deceiving users into clicking a link to "download a security certificate." Upon clicking, users unknowingly initiate the download of Cobalt Strike, a legitimate tool commonly used by security testers but often exploited by attackers for remote access and command execution.

Exploiting Website Vulnerabilities

TAG-112 likely gained access to the compromised Tibetan websites through vulnerabilities in Joomla, a popular CMS. Websites built on Joomla are frequently targeted by attackers if they are not adequately maintained and updated. Likely by exploiting these weaknesses, TAG-112 was able to upload the malicious JavaScript file, which remains active on these sites as of early October 2024.

Infrastructure and Obfuscation Tactics

TAG-112’s infrastructure shows a level of sophistication in concealing its origins. The group used Cloudflare to shield its servers' IP addresses, complicating efforts to trace the infrastructure back to its origin. Insikt Group identified multiple IP addresses linked to TAG-112’s C2 servers, some active as early as March 2024. The primary domain, maskrisks[.]com, was registered in March 2024 through Namecheap, with subdomains such as mail[.]maskrisks[.]com and checkupdate[.]maskrisks[.]com added for further operational flexibility.

TAG-112’s Use of Cobalt Strike

Cobalt Strike is a commercial penetration testing tool that has become a favorite among threat actors due to its versatility and powerful capabilities for remote access, lateral movement, and command-and-control. Insikt Group identified six distinct Cobalt Strike Beacon samples linked to TAG-112, with their C2 communication directed to mail[.]maskrisks[.]com. This malware enables TAG-112 to monitor and control compromised systems, gathering intelligence and potentially leveraging these infected systems for further espionage activities.

Connections to TAG-102 (Evasive Panda)

TAG-112 shares several operational characteristics with TAG-102 (Evasive Panda), another Chinese APT known for targeting the Tibetan community. Both groups have used similar methods, including spoofed error pages to deliver malicious files. However, TAG-112’s operations are less sophisticated than TAG-102, indicating that it may be a subgroup or less experienced branch. For instance, while TAG-102 has deployed customized malware and used obfuscation techniques, TAG-112 relies on the readily available Cobalt Strike tool without obfuscating its JavaScript.

Despite the lack of obfuscation, TAG-112’s tactics and overlaps with TAG-102 highlight the Chinese government’s ongoing interest in Tibetan and other ethnic and religious minority communities. Such campaigns are part of a broader strategy of surveillance and control, targeting groups perceived as threats to the stability and control of the Chinese Communist Party (CCP).

Mitigation Recommendations

TAG-112’s campaign underscores the importance of proactive cybersecurity measures, particularly for organizations that may be high-value targets for state-sponsored actors. Recorded Future recommends the following steps:

  1. Intrusion Detection and Prevention: Configure intrusion detection (IDS) and intrusion prevention systems (IPS) to alert on any indicators of compromise (IoCs) associated with TAG-112. Consider blocking connections to known TAG-112 infrastructure after a thorough review.
  2. User Training: Educate users to exercise caution when handling files downloaded from untrusted sources. Advise users against opening files that download automatically without input, as these could be part of phishing or drive-by download attacks.
  3. Cobalt Strike Detection: Enable real-time monitoring for malicious Cobalt Strike C2 servers using threat intelligence modules such as Recorded Future’s Intelligence Cloud.
  4. Network Monitoring: Regularly monitor network traffic for signs of compromise, particularly for connections to known threat infrastructure. Malicious Traffic Analysis (MTA) can help detect unusual activity, alerting security teams to potential C2 communications.

Outlook

TAG-112’s operations against Tibetan organizations reflect a longstanding objective within Chinese cyber-espionage campaigns to monitor and control ethnic and religious minorities, especially those seen as potentially destabilizing. Other groups and regions with similar CCP-designated risk profiles are likely targets of similar state-sponsored attacks.

To read the entire analysis, click here to download the report as a PDF.

Appendix A — Indicators of Compromise

Compromised Websites:
tibetpost[.]net
gyudmedtantricuniversity[.]org

C2 Domains:
maskrisks[.]com
mail[.]maskrisks[.]com
update[.]maskrisks[.]com
checkupdate[.]maskrisks[.]com

C2 IP Addresses:
154.90.62[.]12
154.90.63[.]166
154.205.138[.]202

Certificates:
d0972247c500d2a45f412f9434287161de395a35ef5b4931cba12cf513b76962(*[.]dnspod[.]cn)
94569f64f62eff185ba47e991dba54bdeea6d1a9e205d6bec767be6a864e4efb (Cloudflare Origin *.maskrisks[.]com)
d4938cb5c031ec7f04d73d4e75f5db5c8a5c04ce (Stolen code-signing certificate KP MOBILE)

URLs of malicious JavaScript:
https[:]//gyudmedtantricuniversity[.]org/templates/lt_interiordesign/js/custom.js
https[:]//tibetpost[.]net/templates/ja_teline_v/js/gallery/jquery.blueimp-gallery.full.js

Malicious URLs:
https[:]//update[.]maskrisks[.]com/download
https[:]//update[.]maskrisks[.]com/?type=Chrome
https[:]//update[.]maskrisks[.]com/?type=Edge
http[:]//mail[.]maskrisks[.]com/api/view.php
http[:]//154.205.138[.]202/GetUrl/cache
https[:]//checkupdate[.]maskrisks[.]com/cache
https[:]//update[.]maskrisks[.]com/cache

Cobalt Strike:
1e42cbe23055e921eff46e5e6921ff1a20bb903fca83ea1f1294394c0df3f4cd
0e306c0836a8ee035ae739c5adfbe42bd5021e615ebaa92f52d5d86fb895651d
f1f11e52a60e5a446f1eb17bb718358def4825342acc0a41d09a051359a1eb3d
f4ded3a67480a0e2a822af1e87a727243dea16ac1a3c0513aec62bff71f06b27
966d311dcc598922e4ab9ce5524110a8bfd2c6b6db540d180829ceb7a7253831
1e7cb19f77206317c8828f9c3cdee76f2f0ebf7451a625641f7d22bb8c61b21b

Loaders:
8d4049ef70c83a6ead26736c1330e2783bdc9708c497183317fad66b818e44cb
E190c7e097a1c38dd45d9c149e737ad9253b1cabee1cee7ef080ddf52d1b378c (legitimate software)
31f11b4d81f3ae25b6a01cd1038914f31d045bc4136c40a6221944ea553d6414

Appendix B — Mitre ATT&CK Techniques

Tactic: Technique

ATT&CK Code

Resource Development: Acquire Infrastructure: Server

Resource Development: Acquire Infrastructure: Web Services

Resource Development: Compromise Infrastructure: Server

Initial Access: Drive-by Compromise

Defense Evasion: Hijack Execution Flow: DLL Side-Loading

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.recordedfuture.com/research/china-nexus-tag-112-compromises-tibetan-websites