Microsoft wins court approval to take over sites run by Chinese crime gang
- Reference: 1638855073
- News link: https://www.theregister.co.uk/2021/12/07/microsoft_nickel_takeover/
- Source link:
A [1]post attributed to Microsoft's corporate veep for customer security & trust, Tom Burt, states the US District Court for the Eastern District of Virginia has granted Microsoft to take control of malicious websites operated by a group called Nickel that has [2]been around since at least 2016 .
Burt's post indicates that Microsoft spotted Nickel trying to pinch information from "government agencies, think tanks and human rights organizations". Taking control of the websites Nickel owned will make it harder for the gang to conduct such attacks, Burt opined.
[3]
Nickel is also known as "KE3CHANG," "APT15," "Vixen Panda," "Royal APT" and "Playful Dragon".
[4]
[5]
Whatever the gang is called, it targets unpatched systems in the hope of owning and operating them with stealthy malware.
[6]The perils of non-disclosure? China 'cloned and used' NSA zero-day exploit for years before it was made public
[7]Bad: US govt says Chinese duo hacked, stole blueprints from just about everyone. Also bad: They extorted cash
[8]Ukrainian cuffed, faces extradition to US for allegedly orchestrating Kaseya ransomware infection
Burt explains that Nickel is fond of spearphishing to obtain user credentials, and is not above attacking VPN providers in pursuit of users to compromise. It also targets unpatched Exchange and SharePoint servers.
Readers will be shocked to learn that Burt's post does not consider whether Microsoft's software engineering practices might have any role in the problems Nickel exploits.
Rather, Burt opines, "No individual action from Microsoft or anyone else in the industry will stem the tide of attacks we've seen from nation-states and cybercriminals working within their borders." Burt wants collaboration among "industry, governments, civil society and others to … establish a new consensus for what is and isn't appropriate behavior in cyberspace".
[9]
The Register leaves it to readers to consider whether or not releasing buggy products is appropriate behaviour. ®
Get our [10]Tech Resources
[1] https://blogs.microsoft.com/on-the-issues/2021/12/06/cyberattacks-nickel-dcu-china/
[2] https://www.microsoft.com/security/blog/2021/12/06/nickel-targeting-government-organizations-across-latin-america-and-europe/
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Ya8@3Cv73Z2ZMr8mRztAggAAAVc&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Ya8@3Cv73Z2ZMr8mRztAggAAAVc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Ya8@3Cv73Z2ZMr8mRztAggAAAVc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[6] https://www.theregister.com/2021/02/23/microsoft_chinese_nsa/
[7] https://www.theregister.com/2020/07/21/feds_charge_chinese_hackers/
[8] https://www.theregister.com/2021/11/08/revil_ransomware_operators/
[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Ya8@3Cv73Z2ZMr8mRztAggAAAVc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[10] https://whitepapers.theregister.com/
Google isn't any better. We got DOSed by a Google IP address a couple of years back.
Their abuse address gives an automated reply, "we receive so many messages at this address that they are automatically deleted and never read." Phoning them just gives an automatic message to go and read the relevant part of their website - I never did find the part of their website that dealt with them being responsible for a DOS attack...
This is normal
Systems are designed and built to have features on the Internet, once they become popular and profitable then the manufacturers consider upgrading them by adding security features. Once these new features are added and distributed, they are tested to demonstrate that they work - "testing" is always performed to show that things work, never that they fail.
Re: This is normal
Technically I agree with you, but one must admit that the Internet is a very peculiar environment as far as software is concerned.
Before the Internet, the only way to attack a machine was to physically sit in front of it. In those days, a programmer was only concerned with making sure the product functioned as intended. Security was baked in because of the limitations of physical access.
Networks showed up, and suddenly computers had to be secured from unwarranted access, but that happened at the OS level, not at the program level.
Today, practically all computers are connected to the greatest network that has ever been implemented. The drawback is that now, programmers must not only ensure their product works, but also that it is protected from attacks that can happen any time, in any way. The minds that can concieve the attacks are intelligent, and more numerous than the minds that concieve the defenses. There is a basic inequality there.
Yes, buggy software is a nuisance that really should not exist, but that concerns functionality. Security is an ongoing concern because the miscreants have time to try things no programmer could protect against before the fact.
Re: This is normal
The minds that can conceive the attacks are intelligent, and more numerous than the minds that conceive the defenses. There is a basic inequality there.
Those who seek to destroy and plunder have entropy on their side. It's easier to steal than it is to make the things that get stolen. It easier to burn a building than to build one.
Black Hats are clever, not intelligent.
I'd be a lot happier...
...if MS had a Prevention of Digital Crimes Unit. As it stands, it sounds like they have set up a unit for producing digital crimes, but let's leave that to the Windows development team.
If Microsoft would only do something about the abuse of their Azure platform. They have umpteen different abuse departments and of course the Whois information usually doesn't actually provide the correct abuse contact information.