Tuesday, 02 February 2021 10:35

ESET team finds new supply-chain attack targeting gaming community

0
Shares
By
Image by ooceey from Pixabay

Researchers at the Slovakian security firm ESET say they have discovered a new supply-chain attack that targets the update infrastructure of NoxPlayer, an Android emulator for PCs and Macs.

In a blog post, researcher Ignacio Sanmillan said NoxPlayer was part of Hong Kong firm BigNox's product range and claimed to have more than 150 million users across the globe. The campaign has been given the name Operation NightScout.

However, he pointed out that though this user base was claimed to be spread across 150 countries where more than 20 languages were spoken, a majority of the NoxPlayer base was in Asia.

NoxPlayer is normally used for playing mobile games from a PC and Sanmillan said three different malware families had been distributed through customised malicious updates to selected victims.

The aim of the exercise appeared to be surveillance, he added.

"We spotted similarities in loaders we have been monitoring in the past with some of the ones used in this operation, such as instances we discovered in a Myanmar presidential office website supply-chain compromise on 2018, and in early 2020 in an intrusion into a Hong Kong university," Sanmillan wrote.

He said BigNox had denied being affected when it was contacted by ESET.

The indicators of compromise were first seen in September 2020 and the activity was monitored until 25 January 2021 when malicious activity that was explicit was noticed. At that point, BigNox was informed.

Sanmillan said there were very few victims in relation to the overall number of active NoxPlayer users.

"According to ESET telemetry, more than 100,000 of our users have Noxplayer installed on their machines. Among them, only five users received a malicious update, showing that Operation NightScout is a highly targeted operation. The victims are based in Taiwan, Hong Kong and Sri Lanka," he wrote.

The researchers were unable to find any common factors between the victims, but based on the compromised software, they concluded that the targets were limited to the gaming community.

Sanmillan's post detailed the method of infection, the specifics of the three malicious updates, and indicators of compromise.

"We have detected various supply-chain attacks in the last year, such as Operation SignSight or the compromise of Able Desktop among others," he wrote.

"However, the supply-chain compromise involved in Operation NightScout is particularly interesting due to the targeted vertical, as we rarely encounter many cyber-espionage operations targeting online gamers."


Subscribe to ITWIRE UPDATE Newsletter here

GRAND OPENING OF THE ITWIRE SHOP

The much awaited iTWire Shop is now open to our readers.

Visit the iTWire Shop, a leading destination for stylish accessories, gear & gadgets, lifestyle products and everyday portable office essentials, drones, zoom lenses for smartphones, software and online training.

PLUS Big Brands include: Apple, Lenovo, LG, Samsung, Sennheiser and many more.

Products available for any country.

We hope you enjoy and find value in the much anticipated iTWire Shop.

ENTER THE SHOP NOW!

INTRODUCING ITWIRE TV

iTWire TV offers a unique value to the Tech Sector by providing a range of video interviews, news, views and reviews, and also provides the opportunity for vendors to promote your company and your marketing messages.

We work with you to develop the message and conduct the interview or product review in a safe and collaborative way. Unlike other Tech YouTube channels, we create a story around your message and post that on the homepage of ITWire, linking to your message.

In addition, your interview post message can be displayed in up to 7 different post displays on our the iTWire.com site to drive traffic and readers to your video content and downloads. This can be a significant Lead Generation opportunity for your business.

We also provide 3 videos in one recording/sitting if you require so that you have a series of videos to promote to your customers. Your sales team can add your emails to sales collateral and to the footer of their sales and marketing emails.

See the latest in Tech News, Views, Interviews, Reviews, Product Promos and Events. Plus funny videos from our readers and customers.

SEE WHAT'S ON ITWIRE TV NOW!

BACK TO HOME PAGE
Sam Varghese

Sam Varghese has been writing for iTWire since 2006, a year after the site came into existence. For nearly a decade thereafter, he wrote mostly about free and open source software, based on his own use of this genre of software. Since May 2016, he has been writing across many areas of technology. He has been a journalist for nearly 40 years in India (Indian Express and Deccan Herald), the UAE (Khaleej Times) and Australia (Daily Commercial News (now defunct) and The Age). His personal blog is titled Irregular Expression.

Latest from Sam Varghese

Related items

Share News tips for the iTWire Journalists? Your tip will be anonymous