Malicious Chatbots Target Casinos in Southeast Asia

  /     /     /  
Publicated : 23/11/2024   Category : security


Malicious Chatbots Target Casinos in Southeast Asia


Dubbed ChattyGoblin, the China-backed actors use chatbots to scam Southeast Asian gambling companies.



A campaign dating back to October 2021 has turned its attention toward Southeast Asian gambling operations with a sneaky new tactic — targeting customer support agents with chatbots.
Researchers at ESET dubbed the campaign ChattyGoblin and traced it back to threat groups backed by China. ESET added that the threat actors rely primarily on Comm100 — which was first observed and documented by CrowdStrike — and LiveHelp apps.
ESET outlined one particular
ChattyGoblin attack
last March that used a
chatbot
to target a gambling company in the Philippines.
Written in C#, the initial dropper deployed by the attackers is named agentupdate_plugins.exe and was downloaded by the LiveHelp100 chat application, ESET noted. The dropper deploys a second C# executable based on the SharpUnhooker tool.
The SharpUnhooker tool then downloaded the ChattyGoblin attacks second stage, stored in a password-protected ZIP archive, ESET added.
The final payload is a Cobalt Strike beacon using duckducklive[.]top as its C&C server.

Last News

▸ ArcSight prepares for future at user conference post HP acquisition. ◂
Discovered: 07/01/2025
Category: security

▸ Samsung Epic 4G: First To Use Media Hub ◂
Discovered: 07/01/2025
Category: security

▸ Many third-party software fails security tests ◂
Discovered: 07/01/2025
Category: security


Cyber Security Categories
Google Dorks Database
Exploits Vulnerability
Exploit Shellcodes

CVE List
Tools/Apps
News/Aarticles

Phishing Database
Deepfake Detection
Trends/Statistics & Live Infos



Tags:
Malicious Chatbots Target Casinos in Southeast Asia