HomeSecurityGerman government: APT27 group breaches business networks

German government: APT27 group is breaching business networks

German domestic intelligence agency BfV (short for Bundesamt für Verfassungsschutz) is warning of ongoing attacks coordinated by the Chinese hacking group APT27.

APT27

See also: Mirai botnets exploit lax IoT security

This active campaign targets German commercial organizations, with attackers using HyperBro remote access trojans (RATs) to bypass their networks.

HyperBro helps threat actors maintain persistence in victims' networks by acting as a memory backdoor with remote management capabilities.

The agency said the group's goal is to steal sensitive information and may attempt to target their victims' customers in supply chain attacks.

The BfV has published both indicators of compromise (IOCs) and YARA rules to help targeted German organizations check for HyperBro infections and connections to APT27 command-and-control (C2) servers.

See also: New DeadBolt ransomware targets QNAP NAS devices

Network breach via Zoho and Exchange servers

APT27 (also tracked as TG-3390, Emissary Panda, BRONZE UNION, Iron Tiger, and LuckyMouse) is a Chinese threat group that has been active since at least 2010 and is known for its focus on information theft and cyberespionage campaigns.

The German intelligence agency reports that the APT27 group has been exploiting flaws in Zoho AdSelf Service Plus software, an enterprise password management solution for Active Directory and cloud applications, since March 2021.

German government: APT27 group is breaching business networks

This aligns with previous reports that Zoho ManageEngine installations were targeted by multiple campaigns in 2021, coordinated by nation-state hackers using tactics and tools similar to those used by APT27.

They initially used a zero-day ADSelfService exploit until mid-September, then switched to an n-day AdSelfService exploit and began exploiting a ServiceDesk flaw starting on October 25th.

In these attacks, they successfully breached at least nine organizations from critical sectors worldwide, including defense, healthcare, energy, technology, and education, according to researchers at Palo Alto Networks.

See also: Google Drive: Warns about suspicious files used for phishing/malware

In light of these campaigns, the FBI and CISA issued joint advisories warning APT actors who exploit ManageEngine flaws to drop web shells into the networks of compromised critical infrastructure organizations.

APT27 and other Chinese-backed hacking groups were also linked to attacks exploiting critical ProxyLogon flaws in early March 2021 that allowed them to take over and steal data from unpatched Microsoft Exchange servers worldwide.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS