HomeSecurityChinese hackers used F5 BIG-IP devices for cyber espionage

Chinese hackers used F5 BIG-IP devices for cyber espionage

Chinese hackers involved in cyber espionage are believed to be behind a long-running attack on an unnamed organization in East Asia. The attackers are said to have been on the Asian company's network for about three years, using legacy F5 BIG-IP appliances and acting as internal command-and-control.

Chinese hackers F5 BIG-IP for cyber espionage

Cybersecurity firm Sygnia has been monitoring activity under the name Velvet Ant and has observed strong abilities and frequent changes in techniques to adapt to situations and evade detection.

Velvet Ant is a sophisticated and innovative threat actor ,” the Israeli company said . “ They collect sensitive information over a long period of time, focusing on customer and financial information .”

See also: Espionage: Chinese hackers breached 20,000 Fortigate systems

The attack chains include the use of the backdoor PlugX (also known as Korplug). This is a modular RAT that has been widely used for cyber espionage and has been linked to Chinese interests. PlugX relies heavily on a technique called DLL side-loading to infiltrate devices.

Researchers observed that Chinese hackers attempted to disable security software before installing PlugX.

Additionally, another variant of PlugX was detected that used an internal file server for C&C, thereby allowing malicious traffic to blend with legitimate network activity.

This meant that the threat actor deployed two versions of PlugX within the network,” the company noted. “The first version, configured with an external C&C server, was installed on endpoints with direct access internet extraction of sensitive information. The second version had no C&C configuration and was deployed exclusively on legacy servers.”

See also: Chinese hackers collaborate for cyber espionage

Specifically, the second variant abused unpatched devices F5 BIG-IPas a covert communication channel with the external C&C server. The goal was to issue commands via a reverse SSH tunnel.

There is only one thing required for a mass exploitation incident and that is a vulnerable service, i.e. a piece of software that is accessible from the Internet ,” WithSecure said in a recent analysis.

Devices like these are often intended to make a network more secure, however, vulnerabilities have repeatedly been discovered that attackers can exploit to gain a perfect foothold in a target network.“.

Chinese hackers used F5 BIG-IP devices for cyber espionage

Analysis of the compromised F5 devices also revealed the presence of a tool called PMCD, which waits 60 minutes to look for commands to execute from the C&C server. Additional programs for capturing network packets and a SOCKS tunneling tool called EarthWorm , which has been used by groups such as Gelsemium and Lucky Mouse, were also found.

Currently, it is not known how the initial access is achieved.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: Chinese hackers turn to ORB proxy networks

Attacks by Chinese hackers can cause significant losses for organizations. For this reason, preventive protection measures must be taken. Organizations must constantly be informed about the latest cybersecurity and the techniques used by attackers.

Additionally, it is important to have a strong information security system that includes regularly reviewed security policies and procedures, as well as the use of attack protection technologies . Applying the latest updates to all systems and applications helps address vulnerabilities that could be exploited by Chinese hackers.

Staff training is equally critical. Staff must be aware of current threats and protection methods, as well as the importance of protecting the organization's information. It is important to be able to recognize suspicious emails and messages , as system infections are often carried out through phishing.

Source: thehackernews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS