SyncFuture Campaign Abuses Enterprise Security Tools to Deploy Malware
## Cybersecurity: SyncFuture Espionage Campaign Analysis
Cybersecurity: SyncFuture Espionage Campaign Analysis
A targeted espionage campaign has been identified, focusing on Indian residents through phishing emails that impersonate the Income Tax Department. This operation is known as the "SyncFuture Espionage Campaign" and involves using legitimate enterprise security software as its final payload.
The campaign initiates with phishing emails disguised as tax penalty notices. These emails use URL shorteners to direct victims to malicious archives. The initial infection employs DLL side-loading, a method where legitimate applications load malicious payloads, to avoid detection.
The first-stage loader includes advanced anti-debugging techniques, such as process environment block (PEB) manipulation and API hooking detection, to evade sandbox environments. Once these defenses are bypassed, the malware communicates with Command-and-Control servers to download additional payloads.
The second stage of the attack bypasses Windows User Account Control (UAC) through a COM-based elevation technique and disguises itself as the legitimate Windows explorer.exe application to avoid detection by endpoint monitoring tools.
A notable aspect of this campaign is its targeted evasion of Avast Free Antivirus, deploying a trojan that automates interactions with Avast's interface to add malicious files to the exclusion list.
A targeted espionage campaign has been identified, focusing on Indian residents through phishing emails that impersonate the Income Tax Department.
Persistent Access and Payload Deployment
The malware progresses through stages to establish persistent access using custom batch scripts and Windows services. The final payload includes deploying SyncFuture TSM, a commercial data security product developed by Nanjing Zhongke Huasai Technology Co., Ltd.
Dropped files show the attackers' focus on operational security, with executables carrying valid code-signing certificates from 2019-2024, indicating potential abuse of legitimate software distribution channels.
SyncFuture TSM is used as a comprehensive espionage framework, offering data encryption, surveillance features, screen recording, and remote control capabilities. Analysis of MpGear.dll suggests the use of specialized tools to clone a Microsoft binary's digital signature.
Organizations are advised to prioritize endpoint detection and response (EDR) deployment, security awareness training, and strict policies against unauthorized software to mitigate similar threats.
This campaign exemplifies advanced persistent threat activities by exploiting legitimate software, evading antivirus detection, and establishing multi-layered persistence mechanisms for sustained espionage.
Based on reporting by GBHackers.
