Breaching Trust: The Evolving Landscape of Supply Chain Attacks - VMRay

Breaching Trust:  
The Evolving Landscape of Supply Chain Attacks

Q3 – 2023

Explore the evolving landscape of supply chain attacks: the tactics, strategies, and emerging threat actors.

Table of Contents

The intricacies of supply chain attacks continue to unfold, representing an advanced form of cyber threats where infiltrators breach trusted networks, impacting multiple systems without the victims’ awareness. This chapter delves into the latest developments, revealing the evolving tactics employed by threat actors to compromise and exploit these critical links in the digital ecosystem.


Behind the Veil: Lazarus’ PyPI Deception

In a specific case, state-sponsored hackers from North Korea, known as Lazarus, introduced harmful packages to PyPI, with one disguised as a VMware vSphere connector module titled vConnector. These packages mimicked well-known software projects and experienced several hundred downloads.

The harmful packages exhibited slight structural and content variations from the authentic ones, with alterations mainly focusing on initiating a harmful function that activates data harvesting from the compromised device. The collected data is subsequently transmitted to the assailant’s command and control centers, which reply with a concealed Python module containing the download URL for the subsequent payload.

Carderbee’s Tactical Assault: Targeting Asia with Supply Chain Intricacies

Another emerging threat actor, named “Carderbee” has been spotted conducting supply chain attacks, mainly focusing on entities in Asia. They employed authentic software, Cobra DocGuard, to infect the computers of their targets with PlugX malware.

This group strategically infiltrated high-value targets, introducing various malware types, including PlugX, through the software updater of DocGuard. The exploitation of a supply chain and the employment of digitally signed malware in these assaults reveal a considerable degree of stealth and planning.

Next Chapter: 
Developments in zero-day vulnerabilities

