Chinese Hackers Targeting Ships Across Europe With Malware on USB Sticks

Year

2024

Month

July

Reference number

20240702

Impact area

Vessel

Incident location

Norway, Greece, Netherlands

Incident country

Norway, Greece, Netherlands

Victim country

Norway, Greece, Netherlands

Victim identity

Unknown

Victim Type

Vessel

Method

Malware

Attacker country

China

Summary:

Mustang Panda, a threat actor, targeted cargo shipping companies in Europe in early 2024 using Korplug loaders. These loaders, dropped from USB drives with suspicious filenames, compromised systems in Norway, Greece, and the Netherlands. Some malware samples were blocked, but others had altered signatures and utilized DLL hijacking. The group also shares similarities with a separate actor, CeranaKeeper, which uses different tools like the TONESHELL backdoor. Both may have overlapping resources, but they operate independently.

Reference URL

https://www.supplychainbrain.com/articles/40018-chinese-hackers-targeting-ships-across-europe-with-malware-on-usb-sticks
https://www.nbcnews.com/news/world/china-linked-group-malware-spy-commercial-shipping-cargo-report-eset-rcna152129
https://web-assets.esetstatic.com/wls/en/papers/threat-reports/eset-apt-activity-report-q4-2023-q1-2024.pdf