The US is warning that hackers working for China are exploiting publicly known flaws in network devices as part of broader attacks to steal and manipulate network traffic.
See also: Fraud and identity theft trial tests US anti-hacking law

The National Security Agency (NSA), the Federal Bureau of Investigation (FBI), and the Cybersecurity and Infrastructure Security Administration (CISA) have documented 16 flaws in network device software from 10 brands, including Cisco, Fortinet, Netgear, MikroTik, Pulse Secure, and Citrix that were publicly disclosed between 2018 and 2021. Most of the flaws are rated critical.
These flaws are the ones most frequently exploited by hackers backed by the People's Republic of China (PRC) since 2020, according to the agencies.
“Since 2020, DRC state-sponsored cyber actors have conducted extensive campaigns to rapidly exploit public security vulnerabilities,” the agencies warn.
See also: New SVCReady malware: Loads from Word doc properties
"This technique allowed hackers to gain access to victims' accounts using publicly available exploit code against virtual private network (VPN) services or public-facing applications – without using their own distinctive or identifiable malware – as long as the actors acted before the victims updated their systems.".
The warning concerns attacks that exploit flaws affecting small business routers, network-attached storage (NAS) devices, and corporate VPNs. However, the agencies detail scanning activity and compromises of specialized authentication servers used by large telecommunications companies and network service providers.
Network devices such as small business routers and NAS devices serve as additional access points for routing command and control (C2).
China-backed threat actors also used open-source software exploit frameworks for routers to scan for vulnerabilities in internet-facing devices.
To compromise telecommunications, the attackers targeted critical Remote Authentication Dial-In User Service (RADIUS) servers and then used SQL commands to dump user and admin credentials from the server's underlying database . RADIUS is a widely supported networking protocol standard for authenticating, authorizing, and accounting for users accessing a network.

Using credentials from the targeted RADIUS servers, the hackers then used custom automated scripts for Cisco and Juniper routers to authenticate to an affected router via Secure Shell (SSH) and execute router commands. The hackers saved the output of these commands, including individual router configurations, and then transferred the information to their own infrastructure.
Having obtained router configurations, as well as valid accounts and credentials, attackers could manipulate traffic within a targeted network and exploit traffic outside it.
See also: Shields: Data breach affects 2 million Americans
The services recommend repairing affected devices, removing or isolating compromised devices from the network, replacing hardware that has reached the end of its life cycle, disabling unused or non-essential services, ports, protocols , and devices, and enforcing multi-factor for all users, without exception.
Information source: zdnet.com
