Firm draws link between APT1 espionage group and Siesta campaign

Share this article:
Senators introduce bill that would flag countries, products that benefit from espionage
The research links the Chinese-based attack group APT1 to those behind the Siesta campaign.

Attackers using evasive malware, which lies dormant until saboteurs are ready to trigger malicious features, have been linked to the Chinese-based espionage group APT1.

According to researchers at FireEye, attack tools and tactics used in a recently identified campaign, dubbed “Siesta,” are consistent with APT1's activities.

Last week, a different security firm, Trend Micro, revealed how the Siesta campaign targeted a diverse range of industries, including the energy, defense and telecommunications sector, via spear phishing emails sent to executives.

At the time, Trend Micro researchers told SCMagazine.com that one spear phishing ruse consisted of a spoofed email to an exec, designed to look like communication from an internal employee.

In actuality, the email contained an executable disguised as a PDF attachment.

The malware used in the attacks was crafted so that it would "sleep", or lay dormant for a period of time, cutting off connection to the C&C servers, only to later download and execute upon command. Trend Micro researchers believed the Siesta campaign was leveraged to glean valuable data from targeted organizations.

Now, researchers at FireEye have revealed why the Siesta campaign activities were likely executed by APT1 – or by an unknown group using similar attack techniques as the Chinese-based espionage group.

Mandiant, an incident response and forensic firm that first uncovered the inner workings of APT1 in February 2013, was recently acquired by FireEye. APT1 is infamously distinguished as the attack group that targeted numerous U.S. firms to extract sensitive data from victims.

On Wednesday, FireEye researchers Ned Moran and Mike Oppenheim wrote in a blog post that a spear phishing attack linked to the Siesta campaign shared similarities to methods used by APT1. The email targeted a victim in the telecommunications industry on Feb. 20, the researchers said.

Page 1 of 2
Share this article:

Sign up to our newsletters

More in News

Latest Citadel trick allows RDP access after malware's removal

Latest Citadel trick allows RDP access after malware's ...

Trusteer, an IBM company, said the new Citadel configuration was detected this month.

Cryptoblocker variant emerges, encryption differs from CryptoLocker

Trend Micro has detected a variant of CryptoLocker in the wild that relies on the advanced encryption standard.

Jimmy John's sandwich chain investigating possible breach

Some financial institutions have indicated that credit cards recently used at Jimmy John's locations have been used to make fraudulent purchases.