HomeSecurityChina: Funds hackers for attacks on the US exploiting Exchange, Citrix, F5...

China: Funds hackers for attacks on the US by exploiting Exchange, Citrix, F5 bugs!

The US government is warning of hackers funded by China to launch attacks on government services, exploiting bugs in Microsoft Exchange, Citrix and F5 devices and servers.

Specifically, CISA and the FBI warn that hackers linked to China's Ministry of State Security (MMS) are attacking US government agencies and private companies, exploiting bugs in publicly exposed systems.

China vs USA

According to a recent indictment by the U.S. Department of Justice, hackers associated with MSS have targeted various industries in the U.S. and abroad. The sectors targeted include high-tech manufacturers, medical device manufacturers, government agencies, educational institutions, pharmaceutical companies, and the defense of the targeted countries. The attacks were carried out as part of a campaign that lasted more than a decade. These Chinese-funded hackers acted for both their own personal gain and the benefit of the Chinese MSS.

During their attacks, hackers linked to China search for vulnerable and publicly exposed devices, using the Shodan and vulnerability databases, such as CVE (Common Vulnerabilities and Exposure) and NVD (National Vulnerabilities Database).

hackers China-Exchange Citrix F5 bugs

According to BleepingComputer, CISA has observed that hackers are targeting bugs in F5, Citrix, and Microsoft Exchange Server to gain access to an organization's network and collect data. According to CISA, the most notable Exchange, Citrix, and F5 bugs that have been targeted by hackers are the following:

  • CVE-2020-5902: Bug in Big-IP F5 – This bug allows a remote attacker to access the BIG-IP application delivery controller (ADC) Traffic Management User Interface (TMUI) without authentication, as well as to proceed with remote code.
  • CVE-2019-19781: Citrix VPN Appliances – Bugs in Citrix Application Delivery Controller (ADC), Citrix Gateway, and Citrix SD-WAN WANOP allow unauthorized attackers to execute remote commands to gain access to a network.
  • CVE-2020-0688: Microsoft Exchange Server – This bug exists in the Exchange Control Panel (ECP) component and is caused by Exchange's failure to generate unique cryptographic keys during installation. Once exploited, attackers could perform remote code execution (RCE) on the server with system privileges.
Exchange Citrix F5 bugs

Additionally, once a network is compromised, Chinese-funded hackers download a range of tools that allow them to gain further access to computers on the compromised network. According to CISA, hackers typically download specific tools to enhance their attacks. Some of these include:

Cobalt Strike: Cobalt Strike is a legitimate adversary simulation platform intended for use by securityto assess the security of a network. Hackers use crafted URIs as part of their attacks, to backdoor access to compromised systems, and to deploy additional tools to the target network.

China Chopper Web Shell: This tool allows hackers to install PHP, ASP, ASPX, JSP and CFM webshells (backdoors) on publicly exposed web servers. Once the China Chopper Web Shell is installed, hackers gain full access to a remote server through the exposed site.

Mimikatz: Mimikatz is a tool that allows hackers to steal Windows credentials stored in a computer's memory. This tool is commonly used by hackers, along with ransomware, to gain access to admin credentials and compromise Windows domain controllers.

Using the above three tools, hackers can spread from a compromised system to other devices, until they gain complete control of the targeted network. In addition, CISA warned that hackers are exploiting the Microsoft Exchange CVE-2020-0688 RCE bug to harvest emails from Exchange servers located in Federal Government environments.

CISA-FBI recommendations

Therefore, CISA and the FBI recommend that organizations audit their infrastructure daily and update their management programs. They also recommend that they regularly review configuration programs to ensure they can monitor and mitigate emerging threats. This will prevent potential “operations” by sophisticated cyber threat actors and protect their resources and information.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS