In recent years, a Chinese hacking group is believed to be behind dozens of attacks against airlines in order to steal data to track some of them.

The attacks have been linked to a group of malicious actors named Chimera.
It is believed to operate on behalf of the Chinese state. CyCraft was the first to describe the hacking group's activities in 2020.
The initial report mentioned a series of coordinated attacks against Taiwan 's superconductor industry .
However, in a new report published last week by NCC and its subsidiary Fox-IT, the attacks are broader than initially thought, having also targeted the airline industry.
“NCC Group and Fox-IT observed this threat actor during various incidents that took place between October 2019 and April 2020,” the two companies.
These attacks targeted semiconductor companies and airlines in various regions, not just Asia, NCC and Fox-IT reported.

In some cases, hackers remained hidden within networks for up to three years before being discovered.
While the attacks against the semiconductor industry were aimed at stealing intellectual property (IP), the attacks against the airline industry focused on something else.
“Some victims appear to have been targeted for the purpose of obtaining PNR (Passenger Name Records),” the two companies said.
“The way this data is obtained likely varies per victim, but we observed the use of multiple custom DLL files used to continuously retrieve PNR data from the memory of systems where this data is typically processed, such as flight reservation servers.”
The joint NCC and Fox-IT report also outlines the typical process followed by the Chimera hacking group. It typically begins by collecting user login credentials leaked after data breaches at other companies.
This data is used for credential tampering or attacks on employee passwords, such as email.
Once inside an internal network, attackers typically deploy Cobalt Strike, a penetration testing framework, which they use to move laterally across as many systems, looking for IP and passenger details.

The two security firms said the hackers were patient and thorough, searching until they found ways to traverse sections of networks to reach systems of interest.
Once they found the data they were looking for, they regularly uploaded it to public cloud services like OneDrive, Dropbox, or Google Drive, knowing that traffic to these services is not inspected or blocked within compromised networks.
Although the NCC and Fox-IT report doesn't say for sure why the hacking group targeted the airline industry and why it stole passenger data, it's pretty obvious.
It is very common for state hacking groups to target airlines, hotel chains, and telecommunications to obtain data that they could use to monitor the movements and communications of persons of interest.
