Chinese Hackers - Printable Version +- Save-Point (https://www.save-point.org) +-- Forum: Official Area (https://www.save-point.org/forum-3.html) +--- Forum: Tech Talk (https://www.save-point.org/forum-87.html) +--- Thread: Chinese Hackers (/thread-7657.html) |
RE: Chinese Hackers - kyonides - 08-20-2020 Chinese APT40 Attacked Taiwanese Government Agencies
https://www.cyberscoop.com/taiwan-china-hacking-apt40/ They had attacked 10 agencies and 6,000 email accounts of officials in an escalation of Beijing’s long-running espionage on the island, says CyberScoop. Taiwan Investigation Bureau’s Cyber Security Investigation Officer Liu Chia-zung Wrote:Over the course of two years, Chinese hackers have infiltrated a variety of Taiwanese government offices in an effort to steal sensitive documents Let's take a look at their targets. CyberScoop Wrote:The Taiwanese semiconductor industry, a centerpiece of the global supply chain for smartphones, has also come under sustained assault from hackers that appear to be based in China, private researchers said earlier this month. Taiwanese authorities also feel they need to keep an eye on Hong Kongers that have been arriving as of late since China passed its law criminalizing protests. Here's how they did it. Hackers exploited VPN software, some sort of secure tunnel to a private network, to break into networks, and then smuggled the stolen data out using their own encrypted connections. Part of their malware is called Taidoor and US authorities had denounced Chinese hackers have been using it for over 12 years. Security firm Firefly stated they have been active in multiple Southeast Asian countries in support of China’s “Belt and Road” infrastructure development strategy. Just in case you don't recall what that term means, we're talking about the modern Silk Road here. CyberScoop also revealed that the American Institute in Taiwan is helping them find ways to detect their network flaws. RE: Chinese Hackers - kyonides - 09-09-2020 Back in July media alerted you about how China was hacking institutions related to studying the coronavirus and how to produce a working vaccine. They weren't providing many details back then besides the fact some of the facilities were located in Massachusetts and Maryland if talking about the US only. The following news article actually tells you the NAME of that company that the Chinese tried to vulnerate to steal or alter its data. China-backed hackers targeted
COVID-19 vaccine firm Moderna
https://www.reuters.com/article/us-health-coronavirus-moderna-cyber-excl/exclusive-china-backed-hackers-targeted-covid-19-vaccine-firm-moderna-idUSKCN24V38M What you might still ignore is that Moderna is located in Cambridge, Massachusetts! Reuters Wrote:The indictment said the Chinese hackers “conducted reconnaissance” against the computer network of a Massachusetts biotech firm known to be working on a coronavirus vaccine in January.And you can take for granted that those Chinese hackers are persistent indeed. By the way, they also add another state to the list, namely California. Reuters Wrote:The court filing describes the California firm as working on antiviral drug research and suggested the Maryland company had publicly announced efforts to develop a vaccine in January. Two companies that could match those descriptions: Gilead Sciences Inc and Novavax Inc. RE: Chinese Hackers - kyonides - 09-17-2020 US charges 5 Chinese citizens in global hacking campaign
https://apnews.com/abe63876eedc5a95c90a37ca88024809AP News Wrote:The Justice Department has charged five Chinese citizens with hacks targeting more than 100 companies and institutions in the United States and abroad, including social media and video game companies as well as universities and telecommunications providers, officials said Wednesday. Well, one thing was to see some Chinese hackers to publish a fake game that would allow them to steal data from users but another one is to steal actual videogames! Well, their digital currency at least, the very same money they sold on the black market later on. By the way, one of the suspects admitted he had a connection with the Chinese Ministry of State Security. RE: Chinese Hackers - kyonides - 09-26-2020 Microsoft says it nixed China-linked hackers' apps from Azure cloud
https://www.cyberscoop.com/microsoft-apt40-gadolinium-azure/I gotta admit I'm usually against MS for the way they make business or offer defective products, like the winspooler service for instance, but this time I'd have to state they took a wise decision. Curiously MS also made a serious mistake by not declaring China was behind the attacks. Especially after other organizations have already linked APT40 to China. CyberScoop Wrote:The hacking group — labeled Gadolinium by Microsoft and also known as APT40 — was hosting apps on the Azure Active Directory and using open source tools “to enhance weaponization of their malware payload, attempt to gain command and control all the way to the server, and to obfuscate detection,” the researchers said in a report published Thursday. Once again we get confirmation of an APT expanding its targets. It's not just the Trump administration, Microsoft is denouncing them as well. The cyber criminals are going after higher education and regional government organizations. RE: Chinese Hackers - kyonides - 10-02-2020 Facebook + $4 millions + China
https://www.cyberscoop.com/facebook-silentfade-malware-fraud-millions/CyberScoop Wrote:Hackers defrauded Facebook users out of more than $4 million in a scheme that security staffers have connected to a cybercrime network in China. And you still think you can trust the CCP? What a wise decision... The Details CyberScoop Wrote:Attackers breached hundreds of thousands of Facebook accounts, scouring for users with payment methods attached to their profile, such as PayPal. The attackers would disable users’ notifications, and abuse their access to the victim account to place advertisements for diet pills and counterfeit products. Facebook sued two Chinese guys and a company based in Hong Kong back in 2018 after their internal investigations had ended. RE: Chinese Hackers - kyonides - 10-05-2020 UEFI and Chinese Operatives
https://www.cyberscoop.com/kaspersky-uefi-implants-china/CyberScoop Wrote:The crucial computing code that manages that booting process, known as UEFI firmware, represents a valuable target for hackers, though also one that remains difficult to infiltrate. These events took place from 2017 to 2019, in an attempt to gather information on North Korea or the targets working there like two diplomatics. According to Kaspersky, parts of the code are based on the Italian HackingTeam's UEFI hacking tool. Experts think UEFI implants might become even more common every day that passes. Front Companies as Disguise for State Sponsored Hackers
https://www.cyberscoop.com/chinese-iranian-hackers-front-companies/Some time ago we reported the indictment of several Chinese and Malaysian citizens. Now authorities released more information pertaining their actual affiliation. CyberScoop Wrote:The Justice Department on Sept. 16 unsealed an indictment against five Chinese men and two Malaysian nationals for their alleged role in a years-long spying scheme that infected software including Asus, CCleaner and Netsarang with malware. But why would they do such a weird thing? Here's the answer to that question! CyberScoop Wrote:Intelligence analysts contend the Chinese government began outsourcing cyber-espionage work to nondescript companies after a 2014 agreement in which the U.S. and China agreed to not sponsor any malicious cyber activity for economic gain. The article also reminds us of Rana, an Iranian hacking group, and how it used similar tactics to recruit and organize their hackers. RE: Chinese Hackers - kyonides - 10-08-2020 Huawei is Spying on Britain
https://www.bbc.com/news/technology-54455112BBC Wrote:There is "clear evidence of collusion" between Huawei and the "Chinese Communist Party apparatus", a parliamentary inquiry has concluded. Emphasis is mine but I don't regret it. People should know Chinese enterprises aren't private at all. Or can you still believe Huawei is? Even after knowing how many billion dollars it was granted by the CCP!? BBC Wrote:But the committee says ministers should consider bringing the latter deadline forward to 2025 if relations with China deteriorate or pressure from the US and other allies makes it necessary. Something that will likely happen any time soon. BBC Wrote:They also back proposals to form a D10 group of democracies to provide alternatives to Chinese technology. Sounds logical. RE: Chinese Hackers - kyonides - 10-10-2020 China is targeting US, Russia, India and Other Countries
https://www.cyberscoop.com/chinese-hackers-espionage-russia-india-dhs-cisa-alert/CyberScoop Wrote:Malicious software used in the campaign, which the departments of Defense and Homeland Security have dubbed “SlothfulMedia,” is linked with “high confidence” to the Chinese government, according to one U.S. government official. Another U.S. government source said the hackers are suspected of having ties to Beijing, while a third government official described the group as operating a concerted hacking campaign based in China. What's curious about this report is that they didn't directly make a statement blaming China on October 1st but still let you guess that was the case. CyberScoop Wrote:The Oct. 1 disclosure coincided with a period of celebration in China known as the Moon Festival. Can we ever believe in coincidences? RE: Chinese Hackers - kyonides - 10-20-2020 Chinese Government trying to hack US Defense Contractors
https://www.cyberscoop.com/defense-contractors-chinese-government-hacking-nsa/CyberScoop Wrote:The hackers are specifically going after 25 known vulnerabilities that primarily affect products used for remote access or for external web services, which the NSA lays out in detail in the advisory. Vulnerabilities the Chinese hackers are exploiting include those of Pulse Secure VPNs, which could allow attackers to steal victim passwords, as well as F5 Networks’ Big-IP Traffic Management User Interface, Windows Domain Name System servers, a series of flaws in Citrix ADC and Gateway devices, and several others. Some of their favorite targets are the National Security Systems, Defense Industrial Base, and Department of Defense networks. Keep in mind Chinese hackers have already stolen data related to the F-35 jet fighter as another news media had found out some time ago. FBI and CISA had linked those hackers with the Chinese Ministry of State Security last month. RE: Chinese Hackers - kyonides - 11-18-2020 Symantec implicates Chinese APT10
in sweeping hacking campaign against Japanese firms
https://www.cyberscoop.com/apt10-china-japan-intellectual-property-symantec/CyberScoop Wrote:A Chinese government-linked hacking group whose operatives have been indicted by the U.S. and sanctioned by the European Union is suspected in a year-long effort to steal sensitive data from numerous Japanese companies and their subsidiaries, security researchers said Tuesday. They also mentioned the latest attacks indicate the resurgence of the APT10 / Cicada group. Back in 2018 US authorities had indicted several of their members but it seems that didn't stop them from hacking more companies around the world. |