Proprietary · · 822 days

Able Desktop updates delivered APT malware

Able Desktop, a Mongolian business suite used by government agencies, delivered HyperBro, Korplug, and Tmanger through trojanized installers and a likely compromised update path.

ESET found Able Desktop in the middle of Operation StealthyTrident. The software was part of a Mongolian business-management suite and was advertised as used by more than 430 government agencies. ENISA later used it as a supply-chain taxonomy case; the Atlantic Council treated it as one of the historical roots that made Sunburst easier to understand.

The delivery was not a single file. ESET saw two trojanized 7-Zip SFX installers, and also saw legitimate Able Desktop clients download malware through the normal update mechanism. The update path saved the fetched executable as %USERPROFILE%\Documents\Able\Able Desktop.exe and then ran it.

The payloads changed over time. Trojanized installers carried the legitimate application plus HyperBro or Korplug. The update path delivered HyperBro by mid-2018 patterns and Tmanger by July 2020. The installers used DLL side-loading with legitimate Symantec and McAfee executables, loader DLLs, and XOR-encoded payloads in files such as thumb.db.

Attribution stayed cautious. HyperBro is associated with LuckyMouse, Tmanger with TA428, and one Tmanger command server overlapped ShadowPad infrastructure. Avast/GenDigital separately described a related East Asia campaign against Mongolian government networks. The stronger fact is the supply-chain failure: trusted Able Desktop distribution and update plumbing delivered remote-access malware into government environments.

Appendix · Affected releases

  • ESET assessed the update mechanism as compromised because the real Able Desktop client fetched malware from the expected update filename and path over HTTPS.
  • Able Soft told ESET that updates were halted after notification and that it had not observed further use after July 2020.
  • ESET observed two trojanized Able Desktop installers but did not confirm whether they were downloadable from Able's website or another distribution source.
  • The installers bundled the legitimate Able Desktop application with malware loaded through side-loaded DLLs and XOR-encoded payload files.

References

  1. Operation StealthyTrident: corporate software under attackwelivesecurity.com
  2. ENISA Threat Landscape for Supply Chain Attacksenisa.europa.eu
  3. Broken Trust: Lessons from Sunburstatlanticcouncil.org
  4. APT group targeting governmental agencies in East Asiagendigital.com
  5. Chinese APT suspected of supply chain attack on Mongolian government agencieszdnet.com
  6. Chinese APT suspected of supply chain attack on Mongolian government agenciesscceu.org
  7. The APT group targeting Mongolia's governmentblog.avast.com
  8. APT actor compromises website to distribute malwaresecurelist.com
  9. Able Desktop supply chain analysisblog.malwarebytes.com

Source record: proprietary/able/meta.yaml