Taiwanese government agencies were hit by a sophisticated intrusion campaign that deployed Waterbear malware after attackers abused a weakness in a trusted data loss prevention (DLP) product for DLL hijacking and high-privilege execution. CyCraft identified dozens of affected endpoints in one environment and linked additional high-risk systems to the compromise, reporting that the attackers also reused access left behind from earlier intrusions, harvested administrative credentials, and expanded through victim networks using lateral movement methods including RDP and net use.
The operation used Waterbear Loader, a malware family previously associated with BlackTech, to maintain persistence, evade detection, and covertly control compromised hosts. Researchers said the malware injected shellcode into Windows services including Winmgmt, sens, Wuauserv, and LanmanServer, abused the IKEEXT service to load WLBSCTRL.DLL, and relied on techniques such as Heaven’s Gate, API hooking, RC4-encrypted payloads, forced DLL unloading, oversized binaries, and Kernel32.dll padding to frustrate analysis and bypass security tools.

See the actors and campaigns active against you right now.
8 events from the most recent confirmed update back to the earliest known activity.
CyCraft later published a detailed write-up of the April 2020 attacks, documenting Waterbear Loader tradecraft, malware samples, file paths, hashes, and ATT&CK mappings. The report included indicators such as SQLWVSS.DLL, IGTERM.DLL, OCI.DLL, SECUFILE.DLL, LIBGID.DLL, WLBSCTRL.DLL, SQLWVSS_NT.DLL, and LOG4C.DLL.
In August 2020, CyCraft separately reported that a Chinese APT group had targeted Taiwanese chip manufacturers in 2018 and 2019. The company said at least seven vendors were affected and sensitive semiconductor information including designs, source code, and SDKs was stolen.
In the April 2020 attacks, the malicious DLL injected shellcode into Windows services including Winmgmt, sens, Wuauserv, and LanmanServer, after which Waterbear deployed next-stage payloads and communicated with command-and-control infrastructure. CyCraft also reported abuse of the Windows IKEEXT service to load WLBSCTRL.DLL.
A key step in the April 2020 campaign was exploiting a trusted DLP tool that failed to verify DLL integrity, allowing malicious DLLs to be loaded with high privileges. CyCraft said the attackers modified LOG4C.DLL to force loading of malicious libraries such as SecureFile.dll or LIBDIG.dll.
CyCraft reported that malware and access left behind from an earlier intrusion had not been fully eradicated and were reused in the April 2020 campaign. Attackers leveraged previously compromised endpoints and harvested administrative credentials to reach internal systems.
During the April 2020 intrusions, CyCraft found 30 confirmed infected endpoints in one affected environment and linked 10 additional endpoints as high risk. The findings showed the campaign had established broad footholds inside the victim network.
In April 2020, multiple Taiwanese government agencies were targeted in a campaign that prominently used Waterbear Loader. CyCraft said the attackers exploited a weakness in trusted DLP software, reused remnants of earlier compromises, and moved laterally with stolen credentials.
Trend Micro published research on Waterbear, describing the malware's return and its use of API hooking to evade security product detection.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 31 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
3 references tracked. Mallory keeps watching after this page renders.
medium.com
Open sourcezdnet.com
Open sourcetrendmicro.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.