Chinese Hackers
#71
The following article talks about what happened about 2 weeks ago.


Quote:Dozens of systems used by government bodies and IT companies in Russia have reportedly become the targets of Chinese hackers.

Moscow-based cybersecurity provider Kaspersky Lab, revealed that the backdoor malware used to gain access to the systems was "GrewApacha," a Trojan used since at least 2021 by the Chinese cyber-espionage group known as APT31 (Advanced Peristent Threat 31).

APT31 is believed to have ties to China's civilian spy agency, the Ministry of State Security (MSS). Earlier this year, the United States Justice department indicted several Chinese nationals and one company for allegedly carrying out APT31 operations.

"During these attacks, attackers infected devices using phishing emails with attachments containing malicious shortcut files," read an August 8 report by Kaspersky Lab-managed website SecureList. Kaspersky has dubbed the Russia-centered hacking campaign "EastWind."

Clicking on these files prompts the installation of the malware, which receives commands from the Dropbox cloud storage.

"With the help of this software, the attackers downloaded additional Trojans to the infected computers, in particular, tools used by the APT31 cybergroup, as well as the updated CloudSorcerer backdoor," the report said.

A Trojan is a type of malware disguised as legitimate software to trick users into installing it. Once installed, Trojans can perform malicious actions on the infected system, such as spying on users, stealing data and providing cybercriminals with unauthorized access.

The SecureList report said the method observed in the recent cyberattacks was similar to the one previously used to target a U.S. organization.

A SecureList report released last month called the updated CloudSorcerer malware "a sophisticated toolset targeting Russian government entities."

Its "ability to dynamically adapt its behavior based on the process it is running in, coupled with its use of complex inter-process communication through Windows pipes, further highlights its sophistication."

The Russian and Chinese foreign ministries didn't immediately respond to a written request for comment.

Last year, the intelligence chiefs of the Five Eyes intelligence alliance—the U.S., the U.K., Canada, Australia and New Zealand—warned of the threat posed by China's use of cutting-edge technology to carry out hacking and intellectual property theft on a large scale.

An anonymous source earlier this year leaked evidence of a massive surveillance campaign by I-Soon, an MSS-affiliated Chinese contractor, whose targets ranged from foreign governments, politicians and think tanks to private Chinese citizens.

The Chinese foreign ministry responded to the leak by saying it "firmly opposes and cracks down on all forms of cyber attack in accordance with the law."

But this one is very recent! Shocked


Quote:China is increasingly suspected of involving "white hat" hackers--who typically identify cybersecurity weaknesses--in cyberattacks. This development is believed to be boosting China's offensive capabilities by utilising its top private hackers, according to a report by Nikkei Asia. The investigation conducted by Nikkei Asia and other organisations, reveals that since the introduction of mandatory vulnerability reporting to the Chinese government in 2021, the number of attacks with suspected Chinese involvement has witnessed a sharp rise.

White hats, who work for security companies or as freelancers, are responsible for bug hunting. They identify vulnerabilities, report them to developers, and receive compensation. Nikkei Asia further reported that developers issue patches and request users to install them to enhance security. In September 2021, concerns emerged in Europe and the US about the exploitation of vulnerabilities before patches could be deployed.

Later that year, Chinese media reported that the Ministry of Information and Technology had suspended Alibaba Group Holding's cloud computing operations from participating in a cybersecurity partnership for six months due to a failure to report issues. In collaboration with cybersecurity firm Trend Micro, Nikkei Asia collected data on 222 software vulnerabilities identified by the US government and others as being exploited by hacker groups believed to be linked to the Chinese government. These groups are suspected of using these vulnerabilities to infiltrate networks.

Katsuyuki Okamoto, a cybersecurity expert at Trend Micro, told Nikkei Asia, "In the past, the main method of cyberattack was phishing, involving tricking victims into downloading malware via email. Now, vulnerability attacks are mainstream." A search on OTX (Open Threat Exchange), a collaborative platform developed by AlienVault (now part of AT&T Cybersecurity) for sharing and accessing threat intelligence, found a total of 1,047 attacks exploiting these vulnerabilities.

Chinese white hats, known for their bug-hunting skills, are highly regarded worldwide. In 2021, when the vulnerability reporting obligation was introduced, there were 16 reported cases. This number surged to 267 in 2022 and nearly doubled again to 502 in 2023. The current year is following a similar trend, with 242 cases reported in the first half.

Taiwan-based cybersecurity firm TeamT5, which examined the leaked files, reports that i-Soon has employed numerous self-identified white hat hackers. However, a significant portion of their work has been commissioned by Chinese state security.

Here's the original article but you'd need to subscribe to Nikkei website in order to read the full text. Confused
"For God has not destined us for wrath, but for obtaining salvation through our Lord Jesus Christ," 1 Thessalonians 5:9

Maranatha!

The Internet might be either your friend or enemy. It just depends on whether or not she has a bad hair day.

[Image: SP1-Scripter.png]
[Image: SP1-Writer.png]
[Image: SP1-Poet.png]
[Image: SP1-PixelArtist.png]
[Image: SP1-Reporter.png]

My Original Stories (available in English and Spanish)

List of Compiled Binary Executables I have published...
HiddenChest & Roole

Give me a free copy of your completed game if you include at least 3 of my scripts! Laughing + Tongue sticking out

Just some scripts I've already published on the board...
KyoGemBoost XP VX & ACE, RandomEnkounters XP, KSkillShop XP, Kolloseum States XP, KEvents XP, KScenario XP & Gosu, KyoPrizeShop XP Mangostan, Kuests XP, KyoDiscounts XP VX, ACE & MV, KChest XP VX & ACE 2016, KTelePort XP, KSkillMax XP & VX & ACE, Gem Roulette XP VX & VX Ace, KRespawnPoint XP, VX & VX Ace, GiveAway XP VX & ACE, Klearance XP VX & ACE, KUnits XP VX, ACE & Gosu 2017, KLevel XP, KRumors XP & ACE, KMonsterPals XP VX & ACE, KStatsRefill XP VX & ACE, KLotto XP VX & ACE, KItemDesc XP & VX, KPocket XP & VX, OpenChest XP VX & ACE
Reply }


Messages In This Thread
Chinese Hackers - by kyonides - 02-19-2020, 05:17 AM
RE: Chinese Hackers - by KDC - 02-19-2020, 08:44 AM
RE: Chinese Hackers - by kyonides - 03-01-2020, 07:31 AM
RE: Chinese Hackers - by kyonides - 03-26-2020, 01:27 AM
RE: Chinese Hackers - by kyonides - 05-03-2020, 05:20 AM
RE: Chinese Hackers - by kyonides - 05-14-2020, 06:18 AM
RE: Chinese Hackers - by kyonides - 05-21-2020, 03:29 AM
RE: Chinese Hackers - by kyonides - 07-07-2020, 06:21 AM
RE: Chinese Hackers - by kyonides - 07-22-2020, 06:33 AM
RE: Chinese Hackers - by kyonides - 08-01-2020, 03:08 AM
RE: Chinese Hackers - by kyonides - 08-20-2020, 05:01 AM
RE: Chinese Hackers - by kyonides - 09-09-2020, 01:36 AM
RE: Chinese Hackers - by kyonides - 09-17-2020, 05:38 AM
RE: Chinese Hackers - by kyonides - 09-26-2020, 05:33 AM
RE: Chinese Hackers - by kyonides - 10-02-2020, 04:21 AM
RE: Chinese Hackers - by kyonides - 10-05-2020, 10:35 PM
RE: Chinese Hackers - by kyonides - 10-08-2020, 05:12 AM
RE: Chinese Hackers - by kyonides - 10-10-2020, 01:16 AM
RE: Chinese Hackers - by kyonides - 10-20-2020, 11:48 PM
RE: Chinese Hackers - by kyonides - 11-18-2020, 04:36 AM
RE: Chinese Hackers - by kyonides - 11-19-2020, 10:36 PM
RE: Chinese Hackers - by kyonides - 11-24-2020, 08:22 AM
RE: Chinese Hackers - by kyonides - 12-18-2020, 01:34 AM
RE: Chinese Hackers - by kyonides - 01-20-2021, 11:33 AM
RE: Chinese Hackers - by kyonides - 03-11-2021, 06:36 AM
RE: Chinese Hackers - by kyonides - 07-21-2021, 07:29 PM
RE: Chinese Hackers - by kyonides - 08-07-2021, 07:38 PM
RE: Chinese Hackers - by kyonides - 03-03-2022, 06:01 AM
RE: Chinese Hackers - by kyonides - 04-04-2022, 07:37 AM
RE: Chinese Hackers - by kyonides - 07-26-2022, 07:09 AM
RE: Chinese Hackers - by kyonides - 08-24-2022, 01:04 AM
RE: Chinese Hackers - by kyonides - 09-01-2022, 04:10 AM
RE: Chinese Hackers - by kyonides - 10-17-2022, 03:50 AM
RE: Chinese Hackers - by kyonides - 11-21-2022, 03:43 AM
RE: Chinese Hackers - by kyonides - 12-15-2022, 02:15 AM
RE: Chinese Hackers - by kyonides - 02-28-2023, 11:50 PM
RE: Chinese Hackers - by kyonides - 03-06-2023, 02:36 AM
RE: Chinese Hackers - by kyonides - 03-09-2023, 07:34 AM
RE: Chinese Hackers - by kyonides - 03-12-2023, 05:45 AM
RE: Chinese Hackers - by kyonides - 03-24-2023, 07:13 PM
RE: Chinese Hackers - by kyonides - 04-03-2023, 07:08 AM
RE: Chinese Hackers - by kyonides - 05-15-2023, 11:43 PM
RE: Chinese Hackers - by kyonides - 06-04-2023, 04:58 AM
RE: Chinese Hackers - by kyonides - 06-16-2023, 11:13 PM
RE: Chinese Hackers - by kyonides - 07-17-2023, 04:52 AM
RE: Chinese Hackers - by kyonides - 07-21-2023, 07:01 AM
RE: Chinese Hackers - by kyonides - 07-25-2023, 07:24 AM
RE: Chinese Hackers - by kyonides - 07-28-2023, 06:51 AM
RE: Chinese Hackers - by kyonides - 08-24-2023, 01:09 AM
RE: Chinese Hackers - by kyonides - 09-12-2023, 06:41 AM
RE: Chinese Hackers - by kyonides - 10-23-2023, 03:49 AM
RE: Chinese Hackers - by kyonides - 12-16-2023, 07:32 AM
RE: Chinese Hackers - by kyonides - 12-31-2023, 01:23 AM
RE: Chinese Hackers - by kyonides - 01-15-2024, 02:03 AM
RE: Chinese Hackers - by kyonides - 02-02-2024, 10:44 PM
RE: Chinese Hackers - by kyonides - 02-06-2024, 07:20 AM
RE: Chinese Hackers - by kyonides - 02-08-2024, 04:38 AM
RE: Chinese Hackers - by kyonides - 02-10-2024, 06:28 AM
RE: Chinese Hackers - by kyonides - 02-19-2024, 04:07 AM
RE: Chinese Hackers - by kyonides - 02-26-2024, 05:24 AM
RE: Chinese Hackers - by kyonides - 03-11-2024, 02:42 AM
RE: Chinese Hackers - by kyonides - 03-29-2024, 06:10 AM
RE: Chinese Hackers - by kyonides - 04-04-2024, 01:59 AM
RE: Chinese Hackers - by kyonides - 04-21-2024, 06:11 AM
RE: Chinese Hackers - by kyonides - 05-10-2024, 08:17 AM
RE: Chinese Hackers - by kyonides - 05-12-2024, 06:12 AM
RE: Chinese Hackers - by kyonides - 06-17-2024, 01:19 AM
RE: Chinese Hackers - by kyonides - 06-25-2024, 07:36 AM
RE: Chinese Hackers - by kyonides - 07-11-2024, 03:16 AM
RE: Chinese Hackers - by kyonides - 08-02-2024, 09:08 AM
RE: Chinese Hackers - by kyonides - 08-25-2024, 11:01 PM
RE: Chinese Hackers - by kyonides - 08-27-2024, 06:10 PM
RE: Chinese Hackers - by kyonides - 09-02-2024, 04:53 AM
RE: Chinese Hackers - by kyonides - Yesterday, 01:14 AM



Users browsing this thread: 1 Guest(s)