Chinese hackers are behind a hacking campaign targeting Japanese organizations.
The hackers are said to be from APT10 (also known as Cicada, Stone Panda , and Cloud Hopper). The group has been conducting espionage campaigns for the past ten years. The hackers have targeted managed service providers (MSPs) and many organizations linked to Japan.

In its recent campaign, APT10 is using a combination of live-off-the-land tools and malware, such as Backdoor.Hartip (new addition).
According to security researchers, Chinese hackers have compromised domain controllers and file servers and stolen data from the infected systems.
One of the main features of this particular hacking campaign was the extensive use of DLL side-loading.
The attacks likely began in mid-October 2019 and continued until at least early October 2020. In some cases, the Chinese hackers managed to be inside the compromised network for at least a year.
According to the researchers, the victims were mostly large, well-known organizations, many of which are based in or affiliated with Japan. In general, the attacks were focused on South and East Asia. One of the victims was a Chinese subsidiary of a Japanese organization.
The victims belonged to the following sectors: automotive (including suppliers of car parts), apparel, government services, general trade, industrial products, MSPs, pharmaceuticals and professional services, etc.
Chinese hackers used living-off-the-land, dual-use, and other publicly available tools for network scanning, credential , etc.
The scale and complexity of this campaign indicate that it is the work of a large state-owned group. Symantec researchers have found enough evidence to say with some confidence that the group behind the attacks is the Chinese APT10.
This week, another report from KELA, saying that data belonging to Japanese companies (government and educational) has been found on the Dark Web. The exposed data includes stolen credentials that provide access to internal networks.
Between June and October 2020, KELA observed 11 attacks against Japanese organizations (mainly ransomware).
Source: Security Week
