Hackers Leverage Obsolete Software in Latest TAOTH Operation to Steal Data

A newly uncovered cybercrime campaign, dubbed TAOTH, has leveraged an abandoned Sogou Zhuyin Input Method Editor (IME) update server to infect users with several advanced malware strains, primarily targeting high-value individuals in Eastern Asia.

The operation exploited the update mechanism of the discontinued Sogou Zhuyin application, a tool designed for typing Mandarin Chinese using Zhuyin/Bopomofo, to deliver malicious payloads since October 2024.

Attackers repurposed the expired “sogouzhuyin[.]com” domain to disseminate legitimate software installers that turned malicious hours after installation by triggering a tainted update through “ZhuyinUp.exe.”

Once the malicious update process was executed, victims received one or more of four observed malware families: TOSHIS, DESFY, GTELAM, and C6DOOR.

These payloads enabled extensive surveillance and data theft capabilities across victim environments, especially among users in Taiwan and the wider overseas Taiwanese community. Attackers also modified Wikipedia pages to direct unsuspecting users to the malicious installer, further broadening their reach.

Multifaceted Attack Chains Target High-Value Victims

The TAOTH operation featured sophisticated infection chains that extended beyond supply chain compromise. In parallel with the software update attack, spear-phishing campaigns targeted dissidents, journalists, researchers, and business leaders in China, Taiwan, Hong Kong, Japan, South Korea, and even overseas.

The infection chain for the first operation

These phishing attempts used either tainted decoy documents or fake login and cloud storage pages designed to extract sensitive credentials and install additional malware.

Technical analysis reveals the following:

  • TOSHIS acts as a loader and stager, modifying legitimate Windows binaries to inject shellcode and fetch further malicious payloads, including Cobalt Strike and Merlin agent backdoors. TOSHIS targets computers set to languages like zh-TW, zh-CN, and ja-JP, with decryption routines and stager logic designed for stealth.
  • DESFY functions as spyware, collecting file names from specified directories for victim profiling, sending details to a remote server for screening high-value targets.
  • GTELAM exfiltrates document filenames using AES encryption and sends them to attacker-controlled Google Drive accounts.
  • C6DOOR, a custom Golang backdoor, supports a wide range of commands (e.g., executing OS commands, taking screenshots, file transfers, and network scanning) and reveals evidence of Chinese-speaking operators by embedded language artifacts.

Attackers further concealed their activity through third-party cloud storage and sophisticated web obfuscation, including the use of OAuth phishing to gain access to victim email accounts.

Telemetry suggests that post-exploitation efforts are primarily focused on reconnaissance, including system surveys and the establishment of tunnels using the Visual Studio Code CLI.

Persistence and Attribution

The overlap in infrastructure and tools links the TAOTH campaign to previously observed Chinese-speaking threat actors known for their supply chain and email-based intrusions.

Victimology distribution

Shared malware variants, C&C infrastructure, and consistent tactics across operations such as hijacked software updates, VSCode tunneling, and targeted spear-phishing underscore the persistence and evolving techniques of this group.

Security vendors like Trend Micro now detect and block related indicators of compromise, advising organizations to retire end-of-support software and rigorously monitor cloud app permissions to mitigate similar attacks.

IOC

SHA256									Malware
f8845b4957fdad691e2826aeb770103345e80375a67cc13772c48ca02e1812fc	Trojan.Win64.TOSHIS.ZTMH
79ce1bb062f6dcdaf01cc33125f68dc2d030da2390255c4fb39d362a22032da1	Trojan.Win64.TOSHIS.ZTMH
587e1fa9d32f2a7134c158d965a32751b58ce5ad3a07533436472105be46a481	Trojan.Win64.TOSHIS.ZTMH
0384733cfcdd32b008642391da7e439c390e7ce8d16e6d9d3bdcbc720b330b84	Trojan.Win64.TOSHIS.ZTMH
90a9be7cf4b7a1786697d5adfff781d9b6ed8db06da33ebef9438dee5a181106	TrojanSpy.Win64.DESFY.ZTMH
4c172211a462cc6e95d9537ecd917ca7c456512006474b4105c1342f0b138dfe	TrojanSpy.Win64.DESFY.ZYMH
c9e539a64275814e198db6830939f0d6c335574f7016696d3ee1cae42b97f838	TrojanSpy.MSIL.GTELAM.ZTMH
3bdac367a7aeab050b8b57c4303110d4db043b939a8f721f3052416c1c3b9fdc	TrojanSpy.MSIL.GTELAM.ZTMH

Find this Story Interesting! Follow us on Google News , LinkedIn and X to Get More Instant Updates

Priya
Priya
Priya is a Security Reporter who tracks malware campaigns, exploit kits, and ransomware operations. Her reporting highlights technical indicators and attack patterns that matter to defenders

Trending News

Related Stories