Posts

Showing posts with the label China

UK govt links 2021 Electoral Commission breach to Exchange server

Image
By Sergiu Gatlan,  Bleeping Computer The United Kingdom's Information Commissioner's Office (ICO) revealed today that the Electoral Commission was breached in August 2021 because it failed to patch its on-premise Microsoft Exchange Server against ProxyShell vulnerabilities. In March, the U.K. National Cyber Security Centre (NCSC) attributed the UK Electoral Commission breach to a Chinese state-backed threat actor. Tracked as CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207, these security flaws were chained to hack into the commission's Exchange Server 2016 and deploy web shells, which allowed the attackers to gain persistence after installing web shells and backdoors. While Microsoft released security updates in May 2021 that fixed the ProxyShell vulnerability chain, the commission failed to patch its systems promptly, exposing them to attacks. The attack and the deployed malware were discovered on October 28, 2021, when an employee found that the Commission's Exchan...

The Biggest Takeaways from Recent Malware Attacks

Image
Among the never-ending list of malicious software that threat actors use in cyber attacks are viruses, worms, trojans, ransomware, spyware, and adware. Today's malware is not just about causing immediate damage; some programs get embedded within systems to siphon off data over time, disrupt operations strategically, or lay the groundwork for massive, coordinated attacks.  A prime example is a recently found malicious backdoor in a popular compression tool, known as xz Utils. Thankfully the malicious code was identified early “due to bad actor sloppiness”, but the consequences could’ve been massive. Read on to get the lowdown on recent high-profile malware attacks along with strategies to help limit malware risks at your organization.  Recent High-Profile Malware Attacks Here's a detailed overview of recent malware attacks, highlighting key incidents and offering valuable insights and lessons learned from each event. StripedFly A prolific and advanced cross-platform malware fra...

CISA shares critical infrastructure defense tips against Chinese hackers

Image
By Sergiu Gatlan,  Bleeping Computer CISA, the NSA, the FBI, and several other agencies in the U.S. and worldwide warned critical infrastructure leaders to protect their systems against the Chinese Volt Typhoon hacking group. Together with the NSA, the FBI, other U.S. government agencies, and partner Five Eyes cybersecurity agencies, including cybersecurity agencies from Australia, Canada, the United Kingdom, and New Zealand, it also issued defense tips on detecting and defending against Volt Typhoon attacks. Last month, they also warned that Chinese hackers had breached multiple U.S. critical infrastructure organizations and maintained access to at least one of them for at least five years before being discovered. Authorities have observed that the cyber espionage group Volt Typhoon's targets and tactics differ from typical activities, suggesting their goal is to obtain access to Operational Technology (OT) assets within networks, which could be exploited to disrupt critical infra...

China fines Didi more than $1 billion for breaking data security laws

By Evelyn Cheng,  CNBC China’s cybersecurity authority fined ride-hailing giant Didi Global on Thursday in apparent closure of a yearlong probe that prevented the company from adding new users. The Cyberspace Administration of China said it fined Didi 8.026 billion yuan ($1.19 billion) after deciding the company violated China’s network security law, data security law and personal information protection law. The administration also fined two Didi executives 1 million yuan each. Didi said in an online statement it accepted the cybersecurity regulators decision. Didi did not immediately respond to a CNBC request for comment. The cybersecurity authority’s announcement did not say whether the fine meant that Didi would soon be able to add new users or restore its presence on app stores in China. The investigation was first announced last year, just days after Didi’s initial public offering on the New York Stock Exchange. Didi had come under fire after it reportedly pushed ahead wi...

China-Made GPS Tracker is Found to Be Risk for Vehicle Hacking

New research shows problems in trackers used by major companies and governments for fleet management. There’s no known fix.  By Jack Gillum,  Bloomberg Vulnerabilities in a popular GPS tracker made in China and used around the world could allow hackers to disrupt vehicles, cut off their fuel and surveil drivers’ movements, according to new research. Several “severe” flaws in the Micodus MV720 tracker affect customers, private companies and government agencies, creating a “high risk” of personal injury, vehicle disablement and supply-chain disruption, according to Boston-based BitSight Technologies. Researchers believe 1.5 million Micodus devices are in use in more than 160 countries. The US Department of Homeland Security issued several warnings Tuesday about the flaws. Micodus didn’t immediately respond to emails and phone calls seeking comment from Bloomberg News since early Monday. In a statement, Eric Goldstein, executive assistant director for the Cybersecurity Infrastruc...

US journalists targeted by foreign hackers who show sophisticated understanding of American politics

By Sean Lyngaas, CNN In the days before the January 6, 2021, insurrection, Chinese hackers sent out a flurry of malicious emails to prominent White House correspondents and other journalists at major US news outlets in an apparent intelligence collection effort, US cybersecurity firm Proofpoint said Thursday. As Chinese hackers scrambled to ascertain whether there would be a peaceful transfer of power in the US, they tried to break into the email accounts of high-profile US journalists, who can be softer targets for hackers than officials on US government networks. The newly revealed hacking campaign shows just how valuable a target journalists can be to intelligence services in search of clues about US policy. To try to lure them, the attackers wrote email subject lines about then-President Donald Trump's attempts to overturn the 2020 election, pandemic relief legislation and other enticing issues. It's unclear how successful the hacking campaign was -- Proofpoint said it bloc...

Chinese hackers use ransomware as decoy for cyber espionage

By Bill Toulas,  Bleeping Computer Two Chinese hacking groups conducting cyber espionage and stealing intellectual property from Japanese and western companies are deploying ransomware as a decoy to cover up their malicious activities. Threat analysts from Secureworks say that the use of ransomware in espionage operations is done to obscure their tracks, make attribution harder, and create a powerful distraction for defenders. Finally, the exfiltration of the sensitive information is masked as financially-motivated attacks, which isn't the case with Chinese government-sponsored threat groups.

Previously Undiscovered Team of State-Sponsored Chinese Hackers, Has Been Quietly Committing Cyber Espionage in the APAC Region for a Decade

By Scott Ikeda,  CPO Magazine A new advanced persistent threat (APT) group linked to China has been discovered by SentinelLabs, but only after conducting cyber espionage campaigns under the radar since 2013. The Chinese hackers have been given the name “Aoqin Dragon,” appear to specialize in targeting the Asia Pacific region and likes to lure victims with malicious documents that appear to be salacious ads for pornography sites.

U.S., EU Plan Joint Foreign Aid for Cybersecurity to Counter China

Russia’s invasion of Ukraine shows the importance of supporting countries vulnerable to nation-state cyberattacks, officials say By Catherine Stupp, Wall Street Journal The U.S. and the European Union plan to introduce joint funding of secure digital infrastructure in developing countries, according to officials involved in the talks. The effort marks the first time the EU and U.S. will work together to fund and help protect other countries’ critical infrastructure against cyberattacks. By working together on cybersecurity, the EU and U.S. aim to help countries that otherwise might be eager to accept funding from China, an EU official said. Initial projects, likely in Africa or Latin America, could be under way by the end of the year, officials said. Russia’s invasion of Ukraine has underscored the importance of supporting telecommunications networks and other hardware in countries vulnerable to nation-state cyberattacks, they said. The EU official said that Chinese technology can come...

Google terminates coordinated influence operations linked to Russia, China, and Costa Rica

by Anna Zhadan,  Cyber News The technology giant terminated hundreds of YouTube and Ads accounts for their involvement in coordinated influence operations designed to support Russia’s invasion of Ukraine, criticize Costa Rican politicians, and upload spam content. Google’s Threat Analysis Group (TAG) updated a bulletin for the second quarter of 2022 detailing all coordinated influence operation campaigns terminated on Google’s platforms over that period. This comes as a part of the platform's initiative to prevent the spread of misinformation and disinformation. As such, TAG terminated 138 YouTube channels and two Ads accounts for a campaign linked to a Russian consulting firm. The campaign praised Russia’s aggression in Ukraine and expressed critical views of Ukraine and the NATO alliance, disseminating content in Russian. Similarly, 44 YouTube channels and nine Ads accounts were removed for another campaign linked to the Internet Research Agency (IRA.) The channels were supporti...

US Federal Agencies Uncover Massive Chinese Hacker Cyber Espionage Spying Campaign

By Nathan Wasson, Hot Hardware Much of the discussion surrounding cyberwarfare has centered around Russia and Ukraine, in recent months. While it may have been pushed into the background, however, China’s aggressive cyber activity continues apace, whether it rises to the level of warfare or not. Only a month ago, we covered news that Chinese state-sponsored hackers had been deploying malware to steal US intellectual property in an operation that went undetected for years. Just a month before that, we wrote about a Chinese state-sponsored hacking group that had been using VLC Media Player to deploy malware in targeted attacks on foreign governments and NGOs. Both of these Chinese-backed cyber operations were discovered by private cybersecurity researchers, but US federal agencies have been monitoring Chinese cyber activity as well. This week, the National Security Agency (NSA), Cybersecurity & Infrastructure Security Agency (CISA), and Federal Bureau of Investigation (FBI) published...

US: Chinese govt hackers breached telcos to snoop on network traffic

Image
By Sergiu Gatlan, Bleeping Computer Several US federal agencies today revealed that Chinese-backed threat actors have targeted and compromised major telecommunications companies and network service providers to steal credentials and harvest data. As the NSA, CISA, and the FBI said in a joint cybersecurity advisory published on Tuesday, Chinese hacking groups have exploited publicly known vulnerabilities to breach anything from unpatched small office/home office (SOHO) routers to medium and even large enterprise networks. Once compromised, the threat actors used the devices as part of their own attack infrastructure as command-and-control servers and proxy systems they could use to breach more networks. "Upon gaining an initial foothold into a telecommunications organization or network service provider, PRC state-sponsored cyber actors have identified critical users and infrastructure including systems critical to maintaining the security of authentication, authorization, and accou...

People’s Republic of China State-Sponsored Cyber Actors Exploit Network Providers and Devices

CISA, the National Security Agency (NSA), and the Federal Bureau of Investigation (FBI) have released a joint Cybersecurity Advisory (CSA) to provide information on ways in which People’s Republic of China (PRC) state-sponsored cyber actors continue to exploit publicly known vulnerabilities in order to establish a broad network of compromised infrastructure across public and private sector organizations. The advisory details PRC state-sponsored targeting and compromise of major telecommunications companies and network service providers. It also provides information on the top vulnerabilities associated with network devices routinely exploited by PRC cyber actors since 2020. CISA, NSA, and the FBI encourage organizations to review People’s Republic of China State-Sponsored Cyber Actors Exploit Network Providers and Devices to learn about PRC tactics, techniques, and procedures and to apply the recommended mitigations. 

Wray: FBI blocked planned cyberattack on children’s hospital

By Eric Tucker & Alan Suderman, NBC The FBI thwarted a planned cyberattack on a children’s hospital in Boston that was to have been carried out by hackers sponsored by the Iranian government, FBI Director Christopher Wray said Wednesday. Wray told a Boston College cybersecurity conference that his agents learned of the planned digital attack from an unspecified intelligence partner and got Boston Children’s Hospital the information it needed last summer to block what would have been “one of the most despicable cyberattacks I’ve seen.” “And quick actions by everyone involved, especially at the hospital, protected both the network and the sick kids who depended on it,” Wray said. The FBI chief recounted that anecdote in a broader speech about cyber threats from Russia, China and Iran, and the need for partnerships between the U.S. government and the private sector. He said the bureau and Boston Children’s Hospital had worked closely after a hacktivist attacked the hospital’s computer...

Our battle with China over the future of the Internet is just beginning

By Joseph Marks & Aaron Schaffer, Washington Post Welcome to The Cybersecurity 202! Before the month is over consider checking out Louis Malle's 1990 film “May Fools” about the 1968 Paris student riots. Arcade Fire's “Month of May” isn't half bad either.  Below: Twitter will pay a $150 million fine for collecting users' personal information for security but using it for advertising, and the U.N. Security Council is poised to vote on sanctioning North Korean hackers.  The United States has mostly won the fight to restrict China’s role in building next-generation 5G telecom systems over spying concerns. But the battle over who will control the future of global communications technology is only beginning. Canada belatedly joined the U.S. and its closest allies this month in blocking the Chinese tech giant Huawei from its 5G system.  The move followed years of warnings from U.S. officials that Huawei is too closely tied to the Chinese Communist Party and could be leaned...

Chinese Hackers Tried to Steal Russian Defense Data, Report Says

The campaign detailed by a cybersecurity firm highlights Beijing’s increasingly sophisticated tactics to spy on an array of targets, including countries it considers friends.

Google's TAG provides update on cybersecurity activity in Eastern Europe

Image
By  Dev Discourse Google's Threat Analysis Group (TAG) has observed a continuously growing number of threat actors using the Russia-Ukraine conflict as a lure in phishing and malware campaigns and targeting critical infrastructure entities including oil and gas, telecommunications and manufacturing. "Government-backed actors from China, Iran, North Korea and Russia, as well as various unattributed groups, have used various Ukraine war-related themes in an effort to get targets to open malicious emails or click malicious links. Financially motivated and criminal actors are also using current events as a means for targeting users," TAG wrote in a blog post . Below is the campaign activity observed by Google's TAG: APT28 or Fancy Bear, a threat actor attributed to Russia GRU, was seen targeting users in Ukraine with a new variant of malware which was distributed via email attachments inside of password-protected zip files (ua_report.zip). The malware is a .Net executable...

Chinese hackers behind most zero-day exploits during 2021

Image
By Bill Toulas, Bleeping Computers Threat analysts report that zero-day vulnerability exploitation is on the rise, with Chinese hackers using most of them in attacks last year. Zero-day vulnerabilities are security weaknesses in software products that are either unknown or have not been fixed at the time of discovery Zero-day disclosures are of particular interest to hackers because they have a wider exploitation window until vendors address the flaws and clients start applying the updates. Number of recorded zero-day exploits (Mandiant) Typically, this window of opportunity lasts for at least a couple of days, and since not all admins apply security updates immediately, the number of vulnerable targets remains high for a while. 2021 zero-day landscape According to an analysis from cybersecurity firm Mandiant, last year there were 80 cases of zero-days exploited in the wild, 18 more than 2020 and 2019 combined. Most of them were attributed to cyberespionage operations from state-backed...

Researchers break world record for quantum-encrypted communications

Image
By S. Dent, Engadget Researchers in Beijing have set a new quantum secure direct communication (QSDC) world record of 102.2 km (64 miles), smashing the previous mark of 18 km (11 miles), The Eurasian Times reported . Transmission speeds were extremely slow at 0.54 bits per second, but still good enough for text message and phone call encryption over a distance of 30 km (19 miles), wrote research lead Long Guilu in Nature . The work could eventually lead to hack-proof communication, as any eavesdropping attempt on a quantum line can be instantly detected.  QSDC uses the principal of entanglement to secure networks. Quantum physics dictates that entangled particles are linked, so that if you change the property of one by measuring it, the other will instantly change, too — effectively making hacking impossible. In theory, the particles stay linked even if they're light-years apart, so such systems should work over great distances.  The same research team set the previous fiber r...