Tonto Team Hackers Regularly Intimidate South Korean Institutions

Harper Stewart

Tonto Team, a hacking gang purportedly connected to China, has launched new attacks against political, diplomatic, and institutions related to education and construction in South Korea. According to a recent investigation by ASEC, “A group of attackers use a file associated with anti-malware solutions to carry out their malicious attacks.”

How the Attack Happened

The Tonto Team has a lot of experience hacking in Asia and Eastern Europe and has been active at least since 2009. Additionally, the group was implicated in a botched phishing attempt against a cybersecurity firm earlier this year. 

The attack chain identified by ASEC started with a Microsoft Compiled HTML Help (“.chm”) file that ran a binary file in preparation for the DLL Sideloading injection of a malicious library (slc.dll). Soon enough, ReVBShell, an open source VBScript backdoor, was released.

Attackers downloaded the genuine Avast software configuration file (wsc_proxy.exe) and a malicious DLL (wsc.dll) using ReVBShell, which eventually resulted in the installation of the Bisonal RAT trojan.

The Rise of Cyber Attacks

Experience demonstrates that other countries’ cybercriminals also employ CHM files as a means of distributing malware. ScarCruft, a North Korean gang that frequently targets South Korean companies with its attacks, also employs identical attack chains.

