Tag: china hackers

China-Backed Hackers Leverage SIGTRAN, GSM Protocols to Infiltrate Telecom Networks
News

China-Backed Hackers Leverage SIGTRAN, GSM Protocols to Infiltrate Telecom Networks

Since at least 2020, a new cyber espionage organization with ties to China has been implicated in a number of targeted cyberattacks against telecommunications companies in South Asia and Africa with the intention of facilitating intelligence gathering. The opponent, known as Liminal Panda, is being tracked by cybersecurity firm CrowdStrike, which claims that it has extensive knowledge of telecommunications networks, the protocols that support them, and the different linkages between providers. Custom tools that enable data exfiltration, command-and-control (C2), and clandestine access are part of the threat actor's malware arsenal read more about China-Backed Hackers Leverage SIGTRAN, GSM Protocols to Infiltrate Telecom Networks. Get up to date on the latest cybersecurity news an...
China-Aligned MirrorFace Hackers Target EU Diplomats with World Expo 2025 Bait
News

China-Aligned MirrorFace Hackers Target EU Diplomats with World Expo 2025 Bait

MirrorFace, a threat actor with ties to China, was seen attacking a diplomatic institution in the European Union, the first time the hacking team has targeted a regional body. According to ESET's APT Activity Report for the April–September 2024 period, the threat actor used the impending World Expo, which will take place in Osaka, Japan in 2025, as a lure during this attack. This demonstrates that MirrorFace is still focused on Japan and events associated with it despite this expanded geographic targeting. APT10, an umbrella organization that includes clusters tracked as Earth Tengshe and Bronze Starlight, is thought to include MirrorFace, also known as Earth Kasha read more about China-Aligned MirrorFace Hackers Target EU Diplomats with World Expo 2025 Bait. Get up to date on...
China-Linked Hackers Infiltrate East Asian Firm for 3 Years Using F5 Devices
News

China-Linked Hackers Infiltrate East Asian Firm for 3 Years Using F5 Devices

An extended assault against an unidentified East Asian organization over a period of approximately three years has been linked to a suspected China-nexus cyber espionage actor. The adversary established persistence using legacy F5 BIG-IP appliances and used it as an internal command-and-control (C&C) for defense evasion. The behavior is being tracked under the name Velvet Ant by the cybersecurity company Sygnia, which responded to the infiltration in late 2023. The company describes Velvet Ant as having strong ability to quickly pivot and adjust their methods to counter-remediation attempts. The Israeli company said in a technical study that it provided with The Hacker News that Velvet Ant is an inventive and clever threat actor. Over a protracted length of time, they gathered s...
China-Backed Hackers Exploit Fortinet Flaw, Infecting 20,000 Systems Globally
News

China-Backed Hackers Exploit Fortinet Flaw, Infecting 20,000 Systems Globally

By taking advantage of a known major security vulnerability between 2022 and 2023, state-sponsored threat actors supported by China were able to access 20,000 Fortinet FortiGate systems globally, suggesting that the operation had a wider effect than previously thought. The Dutch National Cyber Security Centre (NCSC) stated in a recent bulletin that the state actor behind this operation knew about the FortiGate system vulnerability at least two months before Fortinet revealed it. In just one "zero-day" period, 14,000 devices were infected by the actor alone. Numerous Western countries, international organizations, and a sizable number of defense industry businesses were the targets of the effort read more China-Backed Hackers Exploit Fortinet Flaw Infecting 20000 Systems Globally. ...
China-Linked Hackers Adopt Two-Stage Infection Tactic to Deploy Deuterbear RAT
News

China-Linked Hackers Adopt Two-Stage Infection Tactic to Deploy Deuterbear RAT

As part of a cyber espionage campaign aimed at the Asia-Pacific area this year, the China-linked BlackTech hacking gang deployed a remote access trojan (RAT) called Deuterbear, about which cybersecurity researchers have learned more. According to a recent investigation by Trend Micro researchers Pierre Lee and Cyris Tseng, Deuterbear exhibits improvements over Waterbear despite sharing many similarities, such as support for shellcode plugins, avoiding handshakes for RAT operation, and using HTTPS for C&C connection. In contrast to Waterbear, Deuterbear has anti-memory scanning, shares a traffic key with its downloader, and employs a shellcode format. The larger cybersecurity community also keeps an eye on BlackTech read more China-Linked Hackers Adopt Two-Stage Infection Tact...
China-Linked Hackers Used ROOTROT Webshell in MITRE Network Intrusion
News

China-Linked Hackers Used ROOTROT Webshell in MITRE Network Intrusion

Further information about the previously publicized cyberattack has been provided by the MITRE Corporation, which claims that the first indication of the infiltration now dates back to December 31, 2023. This attack was discovered a month ago and targeted MITRE's Networked Experimentation, Research, and Virtualization Environment (NERVE) by taking use of two zero-day vulnerabilities in Ivanti Connect Secure, which are identified as CVE-2023–46805 and CVE–2024–21887, respectively. Using a hacked administrator account, the attacker moved about the research network via VMware infrastructure. To stay persistent and obtain credentials, the attacker used a mix of web shells and backdoors, according to MITRE. Although the organization had previously revealed that the attackers began con...
China-Linked Hackers Suspected in ArcaneDoor Cyberattacks Targeting Network Devices
News

China-Linked Hackers Suspected in ArcaneDoor Cyberattacks Targeting Network Devices

According to recent research from attack surface management company Censys, China-linked attackers may have been responsible for the newly discovered cyber espionage campaign that targeted perimeter network devices from many vendors, including Cisco. Known as ArcaneDoor, the activity is believed to have started in July 2023, with the first attack against an anonymous target being confirmed in early January 2024. Two unique malware programs named Line Runner and Line Dancer were used in the targeted attacks, which were led by an as-yet-undocumented, presumed sophisticated state-sponsored actor and tracked as UAT4356 (aka Storm-1849). Although the initial access method that allowed the intrusions has not yet been identified, the attacker has been seen to continue using Line Runner ...
China-linked Hackers Deploy New ‘UNAPIMON’ Malware for Stealthy Operations
News

China-linked Hackers Deploy New ‘UNAPIMON’ Malware for Stealthy Operations

UNAPIMON is a new piece of malware that a threat activity cluster identified as Earth Freybug has been seen utilizing to evade detection. Earth Freybug is a cyberthreat group that specializes in espionage and financially motivated operations. It has been operating since at least 2012, according to a report released today by Trend Micro security expert Christopher So. It has been noted to target companies in a variety of industries in several nations. According to the cybersecurity company, Earth Freybug is a subsection of APT41, a China-affiliated cyber espionage organization that is also being monitored under the names Axiom, Brass Typhoon (formerly known as Barium), Bronze Atlas, HOODOO, Wicked Panda, and Winnti. To achieve its objectives, the hostile group is reported to re...
US and Japan warn of Chinese hackers backdooring Cisco routers
News

US and Japan warn of Chinese hackers backdooring Cisco routers

Law enforcement and cybersecurity organizations in the US and Japan issue alerts about Chinese 'BlackTech' hackers breaking into network devices to install personalized backdoors for access to business networks. The state-sponsored hacking gang is breaking into network devices at international subsidiaries in order to pivot to the networks of corporate headquarters, according to a joint report from the FBI, NSA, CISA, and the Japanese NISC (cybersecurity) and NPA (police). Since at least 2010, the Chinese state-sponsored APT group BlackTech (also known as Palmerworm, Circuit Panda, and Radio Panda) has been conducting cyberespionage assaults against Japanese read more US and Japan warn of Chinese hackers backdooring Cisco routers. Stay informed with the best cybersecurity news an...