216.73.217.22

QSC: new modular framework in CloudComputating campaigns

· Published 08/11/2024 11:37 · Modified 08/11/2024 18:52

Export JSON

Essential information

Published
08/11/2024 11:37
Modified
08/11/2024 18:52
Tags
2024-11-08 goclient backdoor lateral movement qsc framework quarian backdoor
Related entities
1 intrusion sets (apt), 22 techniques (mitre), 3 malware, 1 others

Description

Kaspersky researchers discovered QSC, a multi-plugin malware framework used by the CloudComputating group in cyber espionage campaigns. QSC consists of a Loader, Core module, Network module, File Manager module, and Command Shell module, allowing attackers to load specific plugins on demand. The framework was deployed alongside a new Golang-based backdoor called GoClient. Attackers used stolen domain admin credentials to move laterally and deploy QSC on other machines within compromised networks. The campaigns targeted telecommunication companies in South and West Asia, with attackers collecting system information, accessing domain controllers, and exfiltrating sensitive data.

External references