News: 1585231392

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Hey, China. Maybe you should have held your hackers off for a bit while COVID-19 ravaged the planet. Just a suggestion

(2020/03/26)


Proving that no good crisis ever goes to waste, Chinese government hacking crew APT41 launched a campaign that abuses vulns in Citrix Netscaler and Zoho ManageEngine, according to threat intel outfit FireEye.

As well as targeting load balancers and network management suites, the Chinese interference operatives spent three months, at the height of Wuhan's COVID-19 coronavirus outbreak, exploiting weaknesses in Cisco routers.

"This activity is one of the most widespread campaigns we have seen from China-nexus espionage actors in recent years," intoned FireEye in a statement.

Their targets were indiscriminate, ranging from governments, banking and finance, oil and gas, pharmaceutical, tech, defence and more.

During January and February APT41's attacks were concentrated against Cisco devices using previously revealed vulnerabilities and what FireEye speculated was a pre-compiled list of vulnerable devices connected to the internet. Those devices did not have mitigations applied.

In early March the Chinese hackers picked up on CVE-2020-10189, a zero-day remote code execution vuln in Zoho ManageEngine Desktop Central. The proof of concept was released on 5 March; three days later APT41 was using it to exploit "more than a dozen FireEye customers", the firm said in [1]a blog post .

While Zoho published a workaround for the vuln back in January, and a full patch was published on 7 March, that two-day gap was all the Chinese needed.

"It is notable that we have only seen these exploitation attempts leverage publicly available malware such as Cobalt Strike and Meterpreter," commented FireEye. "While these backdoors are full featured, in previous incidents APT41 has waited to deploy more advanced malware until they have fully understood where they were and carried out some initial reconnaissance."

Earlier this year APT41, also known as the Winnti Group, was seen targeting Hong Kong protesters as part of the communist state's ongoing campaign to [2]crush pro-democracy sentiment in the one-time British colony. The crew's first publicly noted tactics were the use of [3]stealing security certificates to rip off video games firms , among others. ®



[1] https://www.fireeye.com/blog/threat-research/2020/03/apt41-initiates-global-intrusion-campaign-using-multiple-exploits.html

[2] https://www.theregister.co.uk/2020/01/31/winnti_hackers_students/

[3] https://www.theregister.co.uk/2013/04/11/video_game_cyberespionage/

Fight Fair?

Nunyabiznes

Culturally the Chinese (current government at least) look at our "fight fair" doctrines and are baffled. If you are going to fight, fight to win. They are waging a campaign to win global dominance from the West, and are getting it done.

Re: Fight Fair?

Anonymous Coward

Russia has a similar attitude - use any means necessary to achieve your goals. Fortunately today they have much less capabilities and worse organization than China or former USSR.

Re: Fight Fair?

Sir Runcible Spoon

See 'The Art of War' by Sun Tzu

Well ain't that nice and neighborly

Pascal Monett

Somebody spike their computers.

Re: Well ain't that nice and neighborly

idiottaxpayerhere previously ishtiaq/theghostdeejay

Somebody spike their computers? Absolutely, Just as somebody spiked Cisco routers

Cheers… Ishy

Pascal Monett

Since when has international diplomacy been based on turning the other cheek ?

Common Sense for Supreme Sublime Ruler Applications *

amanfromMars 1

"It is notable that we have only seen these exploitation attempts leverage publicly available malware such as Cobalt Strike and Meterpreter," commented FireEye. "While these backdoors are full featured, in previous incidents APT41 has waited to deploy more advanced malware until they have fully understood where they were and carried out some initial reconnaissance."

How very wise. And surely Most Commendable and Recommendable?

*Which may or may not yet be APT41 CyberIntelAIgent Intellectual Property for Hire and Bit Part Acquisition/Capitalised Purchase.

Re: Common Sense for Supreme Sublime Ruler Applications *

Anonymous Coward

So basically they walked along the street and tried every door. If the door opened they would take a look at whose house it was before sending someone in to nick the TV/shit in the wardrobe?

You're right, it could be a lot worse.

Re: Common Sense for Supreme Sublime Ruler Applications *

amanfromMars 1

So basically they walked along the street and tried every door. If the door opened they would take a look at whose house it was before sending someone in to nick the TV/shit in the wardrobe?

You're right, it could be a lot worse. ..... Anonymous Coward

No. It is much worse when they have they discovered your secret stash is clashing and clogging up their systems with fast foreign cash which they be minded to reinvest considerably better elsewhere, hence the occasional pause and change of tack in operations.

The Wild Wacky West though is hopelessly fated to be defaulted and configured for quarantine in the More of the Same Old Stuff for Further Past Nonsense Camp of Sub-Prime Executive Office Administrations ...... and that leaves one catastrophically vulnerable to exhaustive exploitation by practically everything new and/or almost new as in anything even slightly different and proving itself most attractive and appealing.

If that is wrong, there is much worse.

APT41 just doing their international good service

Anonymous Coward

And then the victims could perhaps be given "gratitude training" for uncovering their flaws.

China is good at viruses isn't it?

Anonymous Coward

^ see above. Cough.

edris90

Decorum is a silly social game. Concern for decorum represents screwing around and slacking off. Their is no room for such nonsense in any serious endeavor.

When the going gets weird, the weird turn pro.
-- Hunter S. Thompson