Operation DRBControl — APT Profile

Operation DRBControl is the name Trend Micro gave in February 2020 to an espionage actor it found working exclusively against gambling and betting companies in Southeast Asia. The investigation began in the summer of 2019, when Talent-Jump Technologies handed Trend Micro an unfamiliar backdoor recovered during incident response at a company in the Philippines. Access came through spear-phishing: .DOCX attachments aimed at victims' customer-support inboxes, built so the recipient had to double-click an embedded image to trigger the code. The intrusions leaned on two backdoors that were unknown to researchers at the time, both loaded by DLL side-loading against the Microsoft-signed MsMpEng.exe binary; one ran its command-and-control through the Dropbox API and was developed quickly, going from version 1.0 in late May 2019 to version 9.0 by the start of October. The operators also fielded PlugX, HyperBro, the Trochilus RAT and Cobalt Strike. What they took was mostly databases and source code, which led Trend Micro to read the campaign as espionage or competitive intelligence rather than theft for direct profit, and shared mutexes, domain names and attacker commands tied the activity loosely to Winnti, while the use of HyperBro pointed toward Emissary Panda (also tracked as LuckyMouse and APT27).

Vendor research

Read the full analysis on IntelFusions