
Microsoft disclosed on Tuesday that Chinese hackers , known as DEV-0322 , are exploiting a zero-day vulnerability in the SolarWinds Serv-U FTP server that allows remote code execution (RCE). The Chinese hackers are using the SolarWinds vulnerability to target U.S. defense companies.
See also: Microsoft Patch Tuesday July 2021: Fixes 117 vulnerabilities
SolarWinds released fixes for the zero-day vulnerability a few days ago, which could allow an attacker to execute code on vulnerable systems. This means they could install and execute malicious payloads or view and modify sensitive data.

The zero-day vulnerability in the SolarWinds Serv-U FTP server has been reported as CVE-2021-35211 and allows code execution when Serv-U's Secure Shell (SSH) protocol is enabled. While it was previously revealed that the attacks were limited in scope, SolarWinds said it is "ignoring the identity of potentially affected customers."
See also: EU: 6 out of 14 organizations using SolarWinds Orion were hacked
The Microsoft Threat Intelligence Center (MSTIC) states with some certainty that the attacks using the SolarWinds vulnerability originate from the Chinese hacking group DEV-0322 (short for “Development Group 0322”), based on the victims and tactics observed. The researchers found that the Chinese hackers have targeted American defense and software companies.
See also: UK, Canada, EU and NATO blame Russia for SolarWinds hack

“This group is based in China and has been observed using commercial VPN solutions,” according to MSTIC, which discovered the zero-day vulnerability after detecting up to six malicious processes from the main Serv-U process.
This is the second time that Chinese hackers have exploited SolarWinds software vulnerabilities to target corporate networks
More details about the SolarWinds vulnerability and breach indicators can be found here.
Source: The Hacker News
