Security researchers discovered a supply chain attack that occurred to the website of the Vietnam Government Certification Authority (VGCA): ca.gov.vn.
The government organization that issues digital certificates to be used to digitally sign documents, had two software installers on its website altered with a trojan that has a backdoor to compromise users of the legitimate application.
The files were gca01-client-v2-x32-8.3.msi and gca01-client-v2-x64-8.3.msi, and they were available on the organization's website for use on users' Microsoft Windows systems.
According to ESET researchers, between July 23 and August 5 of 2020, these files contained the PhantomNet backdoor Trojan, or also known as Smanager (Smanager_ssl.DLL).
In their report, the experts the malware was used as a framework for more powerful plugins. In particular, PhantomNet plugins can obtain proxy settings for bypassing corporate firewalls, and were also able to download and run additional malware. In all, the malware can be used to conduct reconnaissance campaign in the networks of victims or create more serious attacks.

According to ESET, both private companies and government agencies that downloaded and used the compromised software could have their systems hacked.
Vietnamese citizens, companies and government agencies that want to send files to the Vietnamese government have to sign their documents with a VGCA compliant digital certificate.
And VGCA here, besides providing the certificates, also provides client applications that Vietnamese can install on their computers and automate the process of signing documents.
The compromise of a certification authority website is a sure way for hackers to compromise victims, since people are likely to have a high level of trust in a state organization responsible for digital signatures.
VGCA is part of the Vietnamese's Government Cipher Committee. That committee, in turn, depends on the country's Ministry of Information and Communication.
The researchers named this hacking operation 'SignSight'.
"Supply-chain attacks are typically hard to find, as the malicious code is generally hidden among a lot of legitimate code, making its discovery significantly more difficult," the researchers said.

According to an explanation on ESET's website WeLiveSecurity:
The researchers reported their findings to the VGCA in December 2020, but by that time, the certification center already knew about the hack.
Because of this, simultaneously with ESET's public report, VGCA representatives also officially announced the hack and prepared a guide to help victims remove the malware.
While ESET didn't conclude or accuse anyone in particular for this hacking campaign, but in previous reports from researchers, they usually associate PhantomNet (Smanager) with cyber-espionage activities from Chinese hackers or APT hacking groups.
Similar PhantomNet infections have also been reportedly identified in the Philippines.





















































































































































































































































































































































































