McAfee, the company, says Chinese attackers targeted Asian and US telcos
(2021/03/18)
- Reference: 1616050692
- News link: https://www.theregister.co.uk/2021/03/18/operation_dianxun/
- Source link:
Security vendor McAfee has detected an attack it believes was likely aimed at telecoms companies in the hope of stealing information related to 5G networks.
McAfee has [1]named the attack “Operation Diànxùn” and says it resembles past attacks perpetrated by groups named RedDelta and Mustang Panda. Both groups have been associated with China by other security researchers.
[2]
The attack begins, McAfee’s researchers assert, with visits to a faked Huawei careers page. Phishing may be a factor in driving traffic to that site, which serves up fake jobs and real malware.
“We discovered malware that masqueraded as Flash applications, often connecting to the domain hxxp://update.careerhuawei.net that was under control of the threat actor,” McAfee’s researchers write. “Moreover, the sample masquerading as the Flash application used the malicious domain name flach.cn which was made to look like the official web page for China to download the Flash application, flash.cn.”
[3]
“One of the main differences from past attacks is the lack of use of the PlugX backdoor. However, we did identify the use of a Cobalt Strike backdoor,” the researchers write.
McAfee to offload enterprise business for $4bn, focus on consumer security [4]READ MORE
If the attack works, victim machines become host to a backdoor that allows remote control through a command-and-control server and a Cobalt Strike Beacon.
McAfee telemetry suggested “possible targets based in Southeast Asia, Europe, and the US were discovered in the telecommunication sector” along with “strong interest in German, Vietnamese and India telecommunication companies.”
“Combined with the use of the fake Huawei site, we believe with a high level of confidence that this campaign was targeting the telecommunication sector. We believe with a moderate level of confidence that the motivation behind this specific campaign has to do with the ban of Chinese technology in the global 5G roll-out.”
The security firm concluded, with moderate confidence, that “this espionage campaign is aimed at stealing sensitive or secret information in relation to 5G technology.”
[5]
McAfee also suggests the attack should not be vastly difficult to defend, by – surprise! – using its products. Readers may also suggest not running Flash as a fine way to prevent such attacks, especially since it was deprecated. However, Flash [6]lives on in China , where it remains an much-used tool. ®
Get our [7]Tech Resources
[1] https://www.mcafee.com/blogs/other-blogs/mcafee-labs/operation-dianxun-cyberespionage-campaign-targeting-telecommunication-companies/
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YFMyy-LQKViUAfLXSY3zZQAAAI4&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YFMyy-LQKViUAfLXSY3zZQAAAI4&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[4] https://www.theregister.com/2021/03/08/mcafee_enterprise_sale_indictment/
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YFMyy-LQKViUAfLXSY3zZQAAAI4&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://www.theregister.com/2021/01/15/flash_still_works_in_china/
[7] https://whitepapers.theregister.com/
McAfee has [1]named the attack “Operation Diànxùn” and says it resembles past attacks perpetrated by groups named RedDelta and Mustang Panda. Both groups have been associated with China by other security researchers.
[2]
The attack begins, McAfee’s researchers assert, with visits to a faked Huawei careers page. Phishing may be a factor in driving traffic to that site, which serves up fake jobs and real malware.
“We discovered malware that masqueraded as Flash applications, often connecting to the domain hxxp://update.careerhuawei.net that was under control of the threat actor,” McAfee’s researchers write. “Moreover, the sample masquerading as the Flash application used the malicious domain name flach.cn which was made to look like the official web page for China to download the Flash application, flash.cn.”
[3]
“One of the main differences from past attacks is the lack of use of the PlugX backdoor. However, we did identify the use of a Cobalt Strike backdoor,” the researchers write.
McAfee to offload enterprise business for $4bn, focus on consumer security [4]READ MORE
If the attack works, victim machines become host to a backdoor that allows remote control through a command-and-control server and a Cobalt Strike Beacon.
McAfee telemetry suggested “possible targets based in Southeast Asia, Europe, and the US were discovered in the telecommunication sector” along with “strong interest in German, Vietnamese and India telecommunication companies.”
“Combined with the use of the fake Huawei site, we believe with a high level of confidence that this campaign was targeting the telecommunication sector. We believe with a moderate level of confidence that the motivation behind this specific campaign has to do with the ban of Chinese technology in the global 5G roll-out.”
The security firm concluded, with moderate confidence, that “this espionage campaign is aimed at stealing sensitive or secret information in relation to 5G technology.”
[5]
McAfee also suggests the attack should not be vastly difficult to defend, by – surprise! – using its products. Readers may also suggest not running Flash as a fine way to prevent such attacks, especially since it was deprecated. However, Flash [6]lives on in China , where it remains an much-used tool. ®
Get our [7]Tech Resources
[1] https://www.mcafee.com/blogs/other-blogs/mcafee-labs/operation-dianxun-cyberespionage-campaign-targeting-telecommunication-companies/
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YFMyy-LQKViUAfLXSY3zZQAAAI4&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YFMyy-LQKViUAfLXSY3zZQAAAI4&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[4] https://www.theregister.com/2021/03/08/mcafee_enterprise_sale_indictment/
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YFMyy-LQKViUAfLXSY3zZQAAAI4&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://www.theregister.com/2021/01/15/flash_still_works_in_china/
[7] https://whitepapers.theregister.com/
"the attack should not be vastly difficult to defend" (against)
Pascal Monett
Certainly not if you check the link before clicking on it and know who it is you work with.
I also imagine that the sender name is spoofed and that there are a number of ways to detect that the mail is not legit rather than seeing a logo that looks familiar and deciding to blindly trust the mail content.
For Pete's sake, how is it that people are still falling for crap like this after decades of mail spam ?
In general, from what I read, China is ahead in the roll out and use of 5G compared to much of the West.
That moderate confidence may be aimed more at increasing sales of McAfee's products than who should be on the naughty step.