중국 정부 해커들이 유럽 조직을 성공적으로 감시했습니다, 호주 및 동남아시아

Chinese government hackers have been conducting a months-long cyber-espionage campaign against entities in Australia, Malaysia and Europe, as well as companies operating in the South China Sea.

The campaign targets Australian government agencies, Australian media and global heavy industry companies that maintain wind turbines in the South China Sea. In a joint report, Proofpoint 그리고 PwC attributed the espionage to APT40 (Leviathan, TA423, Red Ladon). 게다가, the Ministry of State Security of China (MGB PRC) is allegedly behind the activities of APT40.

우리도 그렇게 썼다는 것을 상기시켜 드리겠습니다. Trojan Woody Rat attacks Russian Organizations, 그리고 그것도 Media said that BMW 그리고 Hyundai have been hacked by Ocean Lotus.

Several waves of phishing campaigns were carried out between April 12 and June 15 and used initiating URLs from Australian media companies to deliver the ScanBox intelligence tool. The phishing emails contained topics such asSick Leave”, “User Research”, 그리고 “Cooperation Request”.

In the attack, the hacker posed as an employee of a fictitious Australian media outlet and provided a malicious domain URL, urging the victim to browse a website or share research content for publication on the site. APT40 uses a controlled domain that is used to deliver malware.

Chinese government hackers

ScanBox is JavaScript-based malware that allows a hacker to profile its victims and deliver a next-stage payload containing the HUI Loader, PlugX, 그리고 ShadowPad RAT trojans.

ScanBox extracts and launches several plugins in the victim’s web browser that:

  1. register keystrokes;
  2. remove the fingerprint of the browser;
  3. collect a list of installed browser add-ons;
  4. exchange data with infected machines;
  5. check for the presence of Kaspersky Internet Security (KIS).

또한, these attacks used malicious RTF documents to deliver a first stage loader, which then acted as a conduit to obtain encoded versions of the Meterpreter shellcode. One of the victims of this campaign in March 2022 was a European manufacturer of heavy industrial equipment for offshore wind farms in the Taiwan Strait.

Scanbox is already known to the cybersecurity community. It was used by Chinese cyber spies from APT 10 as part of a campaign against members of the US National Foreign Trade Council.

Also in 2019, unknown attackers compromised a Pakistani government website and infected it with a keylogger and other malware to collect data from users checking the status of their application for Pakistani citizenship.

저자 소개

카리나 윌슨

이상으로 10 온라인 및 인쇄 매체에 대한 수년간의 글쓰기 경험, 나는 명확하고 매력적인 카피를 제공하는 전문가입니다..

최고의 SEO 카피라이팅 에이전시와 영국에서 가장 잘 알려진 브랜드를 위해 글을 썼습니다., 잡지와 신문.

코멘트를 남겨주세요