HomeSecurityCyber ​​espionage campaign targets organizations around the world

Cyber ​​espionage campaign targets organizations around the world

Cybersecurity firm Palo Alto Networks warned over the weekend of a cyberespionage campaign that has already targeted at least nine organizations (globally) belonging to critical sectors, including defense, healthcare, energy, technology and education.

Cyber ​​espionage campaign
Cyber ​​espionage campaign targets organizations around the world

According to researchers, the attackers behind this cyber espionage campaign breached organizations by exploiting a critical vulnerability (CVE-2021-40539) in ADSelfService Zoho's, which allows remote code execution on unpatched systems.

See also: Phishing campaign used Proofpoint to scam users

The attacks observed by the researchers began in mid-September with scans for vulnerable servers, a few days after CISA warned of exploits being used by criminals.

Exploitation efforts began on September 22nd after five days of gathering information about potential targets who had not yet patched their systems.

“While we do not have a full picture of the organizations that were exploited during this campaign, we believe that, globally, at least nine organizations in the technology, defense, healthcare, energy, and education sectors have been compromised,” said .

“We believe that criminals have targeted at least 370 Zoho ManageEngine servers in the United States alone“.

Cyber ​​espionage campaign targets organizations around the world
Cyber ​​espionage campaign targets organizations around the world

Researchers believe that the scans for vulnerable systems were too general, given that targets could range from educational institutions to Department of Defense entities.

Researchers have observed another series of attacks that failed to breach their targets, suggesting that there may be multiple hacking groups attempting to compromise organizations using the vulnerability.

Currently, according to Palo Alto Networks scans, there are over 11,000 servers exposed to the Internet running the vulnerable Zoho software. However, it is not known how many systems have been updated.

See also: Phishing emails infect victims with MirCop ransomware

After successfully breaching an organization's systems (using the vulnerability), hackers deploy a malware dropper that delivers Godzilla web shells to compromised servers to gain and maintain access to victims' networks. Criminals also install malware, such as the open-source backdoor NGLite.

According to researchers, the hackers also used KdcSponge, a known credential stealer malware.

“After gaining access to the initial server, the criminals focused their efforts on collecting and extracting sensitive information from local domain controllers, such as the Active Directory database file (ntds.dit) and the SYSTEM hive from the registry,” the analysts said.

Essentially, the goal of hackers who targeted organizations in the defense, healthcare, education, etc. sectors was to steal credentials, maintain access to systems, and collect sensitive information.

APT27

Is the cyberespionage campaign linked to the Chinese state-run hacking group APT27?

Researchers can't say for sure who is behind the cyberespionage campaign. However, they suspect it may be the work of a Chinese-backed threat group. The hacking group is APT27 (also known as TG-3390, Emissary Panda, BRONZE UNION, Iron Tiger, and LuckyMouse).

See also: APT27: The Chinese hacking group behind a series of ransomware attacks

These suspicions arise from some of the tools and tactics used in this campaign that match previous attacks by APT27. Furthermore, these hackers tend to target organizations in the defense, technology, energy, etc. sectors.

The Palo Alto Networks report also includes analysis from U.S. government partners, including the NSA's Cybersecurity Collaboration Center.

Source: Bleeping Computer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS