A few days ago, news broke that Mitsubishi Electric had been hacked. It is said that Chinese hackers. Now, more information has come to light. It is said that the hackers used a zero-day vulnerability in Trend Micro OfficeScan antivirus to gain access to the systems .
Trend Micro patched the vulnerability, but did not say whether the vulnerability was used in other attacks.

MITSUBISHI ELECTRIC
Following reports in local newspapers, the Japanese company officially announced on its website the breach incident, which took place in June 2019. Chinese hackers gained access to the company's internal network and stole files (approximately 200 MB).
According to a new press release, the files mainly contained information about employees and not details about business transactions and partners.
Mitsubishi Electric said the stolen documents included: employment application data for 1,987 people, the results of an survey completed by 4,566 people and conducted in 2012, data for 1,569 retired Mitsubishi Electric employees, and some sales records, etc.

Zero-day vulnerability
The breach is said to have started at a Chinese subsidiary of Mitsubishi Electric, and then spread to 14 divisions of the company.
The breach was discovered when staff spotted a suspicious file on one of the company's servers
The above information has not been confirmed by the company. It has been published by journalists.
What we know on a "technical level" is that Chinese hackers exploited a zero-day vulnerability in one of the antivirus programs used by Mitsubishi Electric.
According to information, the vulnerability used is CVE-2019-18187 and was found in Trend Micro OfficeScan antivirus.
In October, Trend Micro announced that , “vulnerable versions of OfficeScan could be used by an attacker to extract files.” This is an RCE vulnerability.
When Trend Micro patched CVE-2019-18187 (in October), it warned its customers to update their antivirus immediately, as the vulnerability was already being exploited by hackers.
Japanese media reports that the Chinese hacking group behind the attack is funded by the Chinese government and is targeting espionage. The group is known as Tick and has been linked to several other attacks on companies around the world.
