{"id":5448,"date":"2025-07-18T10:00:29","date_gmt":"2025-07-18T10:00:29","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/07\/18\/chinese-state-sponsored-hackers-attacking-semiconductor-industry-with-weaponized-cobalt-strike\/"},"modified":"2025-07-18T10:00:29","modified_gmt":"2025-07-18T10:00:29","slug":"chinese-state-sponsored-hackers-attacking-semiconductor-industry-with-weaponized-cobalt-strike","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/07\/18\/chinese-state-sponsored-hackers-attacking-semiconductor-industry-with-weaponized-cobalt-strike\/","title":{"rendered":"Chinese State-Sponsored Hackers Attacking Semiconductor Industry with Weaponized Cobalt Strike"},"content":{"rendered":"<p>    Chinese State-Sponsored Hackers Attacking Semiconductor Industry with Weaponized Cobalt Strike<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A sophisticated Chinese state-sponsored cyber espionage campaign has emerged targeting Taiwan\u2019s critical semiconductor industry, employing weaponized Cobalt Strike beacons and advanced social engineering tactics.<\/p>\n<p>Between March and June 2025, multiple threat actors launched coordinated attacks against semiconductor manufacturing, design, and supply chain organizations, reflecting China\u2019s strategic imperative to achieve technological self-sufficiency in this vital sector.<\/p>\n<p>The campaign represents a significant escalation in Chinese <a href=\"https:\/\/cybersecuritynews.com\/u-s-halts-cyber-operations\/\" target=\"_blank\" rel=\"noreferrer noopener\">cyber operations<\/a> against Taiwan\u2019s semiconductor ecosystem, with attackers leveraging employment-themed phishing emails to deliver malicious payloads.<\/p>\n<p>The timing of these operations coincides with heightened geopolitical tensions and ongoing export controls that have intensified China\u2019s focus on acquiring <a href=\"https:\/\/cybersecuritynews.com\/threat-actors-actively-attacking-semiconductor-companies\/\" target=\"_blank\" rel=\"noreferrer noopener\">semiconductor<\/a> technologies and intelligence through cyber means.<\/p>\n<p>The primary threat actor, designated UNK_FistBump, orchestrated the most technically sophisticated attacks during May and June 2025, specifically targeting Taiwan-based semiconductor manufacturers and their supply chain partners.<\/p>\n<p>These operations utilized compromised Taiwanese university email accounts to enhance credibility and bypass initial security screening mechanisms.<\/p>\n<p>Proofpoint analysts <a href=\"https:\/\/www.proofpoint.com\/us\/blog\/threat-insight\/phish-china-aligned-espionage-actors-ramp-up-taiwan-semiconductor-targeting\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> that UNK_FistBump employed a dual-payload strategy, delivering both Cobalt Strike Beacon implants and a custom backdoor called Voldemort through carefully crafted spearphishing campaigns.<\/p>\n<p>The attackers posed as graduate students seeking employment opportunities, using subject lines such as \u201cProduct Engineering (Material Analysis\/Process Optimization) \u2013 National Taiwan University\u201d to lure human resources personnel and recruitment staff.<\/p>\n<p>The malware\u2019s infection mechanism demonstrates remarkable technical sophistication, beginning with password-protected RAR archives containing malicious LNK files.<\/p>\n<p>Upon execution, the LNK file <code>\u5d17\u4f4d\u5339\u914d\u5ea6\u8aaa\u660e.pdf.lnk<\/code> triggers a VBS script named <code>Store.vbs<\/code> that performs several critical operations.<\/p>\n<p>The script copies four essential files to the <code>C:UsersPublicVideos<\/code> directory: <code>javaw.exe<\/code>, <code>jli.dll<\/code>, <code>rc4.log<\/code>, and a decoy PDF document to maintain operational security.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Advanced DLL Sideloading and Persistence Mechanisms<\/strong><\/h2>\n<p>The attack chain leverages <a href=\"https:\/\/cybersecuritynews.com\/double-dll-sideloading-technique-to-evade-detection\/\" target=\"_blank\" rel=\"noreferrer noopener\">DLL sideloading<\/a> techniques against the legitimate <code>javaw.exe<\/code> executable, which loads the malicious <code>jli.dll<\/code> library.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjyglNZf8gsHrwHYlI1CKJN-7Y-k1OI_1sDFHjdjIhWVdu5V1EgTQ0jhYXbxJZr_RU2d0fHbWEdVwVI1wcINxZQOlST6p0AoJXYgyUbKzyPEiBvW1_X5MRKrNtgCWhp1QgdQ6y0AgxLN39CFw373P4NVjaSI72R1RP0S1sGqYOfKkXzqBmxEgiR_kfIrVo\/s16000\/Infection%2520chains%2520%28Source%2520-%2520Proofpoint%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Infection chains (Source \u2013 Proofpoint)<\/figcaption><\/figure>\n<\/div>\n<p>This DLL serves as a sophisticated loader that decrypts an RC4-encrypted Cobalt Strike Beacon payload stored in the <code>rc4.log<\/code> file using the hardcoded key <code>qwxsfvdtv<\/code>.<\/p>\n<p>The decryption process can be represented as:-<\/p>\n<pre class=\"wp-block-code\"><code>RC4_Decrypt(rc4.log, \"qwxsfvdtv\") \u2192 Cobalt Strike Beacon<\/code><\/pre>\n<p>The malware establishes <a href=\"https:\/\/cybersecuritynews.com\/detecting-and-responding-to-new-nation-state-persistence-techniques\/\" target=\"_blank\" rel=\"noreferrer noopener\">persistence<\/a> through registry modification, creating an entry at <code>HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionRun<\/code> that ensures the malicious <code>javaw.exe<\/code> executable launches during system startup.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjfs19VA9toRxDRqWOcd-aSvVCUIPavamIW6akqcxW22D3uWAkB3pC9zcQ8xsCqMSvBtcfbcgF6YnO80KgawIkv8V3BwwEebd9vZvU16iDH5ZXPxIodlBmxiWEv7CwOKYhVyo9xQWMoZRJKGZBud_bSMsT-pjxQeiWimbch73kUuADXY5PeAYEEKF6Ps6M\/s16000\/UNK_DropPitch%2520infection%2520chain%2520%28Source%2520-%2520Proofpoint%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">UNK_DropPitch infection chain (Source \u2013 Proofpoint)<\/figcaption><\/figure>\n<\/div>\n<p>The <a href=\"https:\/\/cybersecuritynews.com\/linux-version-of-cobalt-strike-malware-targets-organization-worldwide\/\" target=\"_blank\" rel=\"noreferrer noopener\">Cobalt Strike<\/a> Beacon subsequently establishes command and control communications with the server <code>166.88.61[.]35<\/code> over TCP port 443, utilizing a customized GoToMeeting malleable C2 profile to blend network traffic with legitimate collaboration software communications.<\/p>\n<p>This campaign underscores the evolving threat landscape facing Taiwan\u2019s semiconductor industry, where state-sponsored actors are increasingly deploying sophisticated multi-stage malware delivery systems to compromise critical infrastructure and intellectual property.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 90%,rgb(169,184,195) 100%)\"><strong>Boost detection, reduce alert fatigue, accelerate response; all with an interactive sandbox built for security teams -&gt;\u00a0<a href=\"https:\/\/any.run\/demo?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=top3_ciso_challenges&amp;utm_content=demo_1&amp;utm_term=160725\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Try ANY.RUN Now<\/a><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/chinese-state-sponsored-hackers-attacking-semiconductor-industry\/\">Chinese State-Sponsored Hackers Attacking Semiconductor Industry with Weaponized Cobalt Strike<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/chinese-state-sponsored-hackers-attacking-semiconductor-industry\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Chinese State-Sponsored Hackers Attacking Semiconductor Industry with Weaponized Cobalt Strike A sophisticated Chinese state-sponsored cyber espionage campaign has emerged targeting Taiwan\u2019s critical semiconductor industry, employing weaponized Cobalt Strike beacons and advanced social engineering tactics. Between March and June 2025, multiple threat actors launched coordinated attacks against semiconductor manufacturing, design, and supply chain organizations, reflecting China\u2019s [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-5448","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/5448"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=5448"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/5448\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=5448"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=5448"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=5448"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}