Full Report
An open directory and a SEA of victims reaching as far as LATAM all lead to TriBack Loader.
Analysis Summary
# Threat Actor: TriBack Loader (Associated with TA427 / Emerald Sleet)
## Attribution & Identity
* **Actor Identification:** The report identifies the activity as centered around the deployment of **TriBack Loader**.
* **Aliases/Associations:** The tactics and infrastructure overlap with North Korean nexus groups, specifically **TA427** (also known as **Emerald Sleet** or **Thallium**). The actor is characterized by their focus on intelligence gathering and the use of sophisticated social engineering.
## Activity Summary
Recent campaigns involve the use of highly targeted social engineering lures, often masquerading as technical documents or software installers related to AI and developer tools (e.g., "Claude Pro"). The campaign was uncovered through an exposed open directory on the actor's infrastructure, which revealed a broad range of victims and a global reach extending from Southeast Asia (SEA) to Latin America (LATAM).
## Tactics, Techniques & Procedures
* **Social Engineering:** Uses lures related to "Claude Pro" technical overviews and Windows installers to trick victims into executing malicious payloads.
* **Execution via DLL Side-Loading:** Utilizes legitimate executables to load malicious DLLs (e.g., `avk.dll`, `MpClient.dll`).
* **Script-Based Execution:** Employment of VBScripts (`pdf.vbs`, `Claude.vbs`) and LNK files for initial infection vectors.
* **Defense Evasion:** Use of scripts like `fuckaliyun.sh` to disable security monitoring tools on Linux environments.
* **MITRE ATT&CK IDs:**
* T1566 (Phishing)
* T1204.002 (User Execution: Malicious File)
* T1574.002 (DLL Side-Loading)
* T1059.005 (Command and Scripting Interpreter: Visual Basic)
* T1021.004 (Remote Services: SSH)
* T1090 (Proxy)
## Targeting
* **Sectors:** Foreign policy experts, think tanks, technical researchers, and organizations involved in strategic international relations.
* **Geography:** Primarily Southeast Asia (SEA) and Latin America (LATAM).
* **Victims:** Specific entities were not named, but the directory revealed a "sea of victims" including individuals targeted with tailored AI-themed lures.
## Tools & Infrastructure
* **Malware Families:**
* **TriBack Loader:** A custom loader used for persistent access.
* **GolddTV:** A modular malware component.
* **Utility Tools:**
* `fscan` (Internal network scanning)
* `suo5`, `iox`, `neoreg.py` (Tunneling and proxy tools)
* `nuclei` (Vulnerability scanning)
* **Infrastructure:**
* Open directories used for staging payloads.
* Abuse of legitimate cloud services (Alibaba Cloud, Cloudflare) for hosting or proxying traffic.
* **Filenames for Defanged Reference:**
* `Claude-Pro-Relay-Technical-Overview.zip`
* `Claude.msi`
* `DeviceSync.zip`
## Implications
The actor demonstrates a high level of persistence and adaptability, moving beyond traditional regional boundaries (SEA) to target LATAM. The use of AI-themed lures (Claude) shows they are keeping pace with current trends to increase the success rate of their social engineering. The presence of cross-platform tools (Windows and Linux) suggests an objective of deep network penetration and long-term intelligence collection.
## Mitigations
* **Email Security:** Implement robust attachment scanning to detect LNK, VBS, and suspicious ZIP files.
* **Endpoint Defense:** Enable EDR rules to detect DLL side-loading patterns, particularly from unusual or non-standard directories.
* **User Training:** Educate staff on the risks of downloading technical whitepapers or "Pro" software versions from non-official sources.
* **Network Monitoring:** Monitor for outbound traffic to known tunneling tools (iox, neoreg) and unauthorized internal scanning activity (`fscan`).