Foreign state-sponsored hackers have launched a massive hacking operation targeting Chinese government agencies and their employees. The attacks began in March and appear to be linked to the ongoing COVID-19 pandemic . Chinese security firm Qihoo 360, which detected the attacks , said the hackers behind them exploited a zero-day vulnerability in Sangfor ’s SSL VPN servers , which are used to provide remote access to corporate and government networks . Qihoo said it had discovered more than 200 VPN servers compromised in the campaign . The security firm also said that 174 of these servers are located on networks belonging to Chinese agencies in Beijing and Shanghai as well as on networks of Chinese diplomatic missions operating in various countries, including Italy , the United Kingdom, Turkey , Indonesia, Thailand, South Korea, Israel and Saudi Arabia.

Qihoo researchers noted that the attacks carried out by this campaign targeting Chinese services were sophisticated and clever. The hackers exploited a zero-day vulnerability to gain control of Sangfor’s VPN servers, where they replaced a file called SangforUD.exe with a boobytrapped version. This file is an update to the Sangfor VPN desktop app, which employees install on their computers to connect to the VPN servers and gain access to their companies’ networks. Qihoo researchers said that whenever employees connected to the hacked VPN servers, they received the boobytrapped SangforUD.exe file, which later installed a trojan backdoor on their devices.
The Chinese security firm said the attacks were linked to a hacking group known as DarkHotel. The group is believed to be operating from the Korean peninsula, although it is not yet known whether it is based in North or South Korea. The group, which has been active since 2007, is considered one of the most sophisticated state-run operations . Google recently revealed that DarkHotel exploited more zero-day vulnerabilities in 2019 than any other state-run hacking operation. The group also exploited zero-day vulnerabilities in Firefox and Internet Explorer, targeting government organizations in China and Japan.

Qihoo researchers also said that recent attacks on Chinese government agencies could be linked to COVID-19. The Chinese security firm said that DarkHotel hackers may be trying to extract information about how the Chinese government is handling the pandemic outbreak. A few days ago, Reuters reported on a DarkHotel attack on the World Health Organization, exploiting the COVID-19 pandemic.
Qihoo said it reported the zero-day vulnerability to Sangfor on April 3, which declined to comment to ZDNet, but referred to a post it made on the company’s WeChat account, where it said only Sangfor VPN servers running firmware versions M6.3R1 and M6.1 were vulnerable and had been confirmed to have been hacked by DarkHotel. The company also said it will release patches for the current version of its SSL VPN server today, and for older versions tomorrow. The company also plans to release a script to investigate whether hackers have compromised VPN servers, as well as a second tool to remove files developed by DarkHotel. Sangfor customers can find additional details in the company’s WeChat post.
