HomeSecurityAPT40: Exploits vulnerabilities within hours of their announcement

APT40: Exploits vulnerabilities within hours of their announcement

Cybersecurity agencies from Australia, Canada, Germany, Japan, New Zealand, South Korea, the United Kingdom and the United States have issued a joint statement regarding the Chinese cyberespionage group APT40, warning of its ability to exploit new security vulnerabilities within hours or days of their public announcement.

APT40 Rapid Exploit

«APT40 has in the past targeted organizations in various countries, including Australia and the United States», the services said. «In particular, APT40 possesses the ability to quickly transform and adapt proof-of-concept (PoC) vulnerabilities for targeting, reconnaissance and exploitation».

Read more: Why is Temu considered “dangerous malware”?

The hacking gang, also known as Bronze Mohawk, Gingham Typhoon (formerly Gadolinium), ISLANDDREAMS, Kryptonite Panda, Leviathan, Red Ladon, TA423 and TEMP.Periscope, has been active since at least 2013, carrying out cyberattacks in the Asia-Pacific region. The group is believed to be based in Haikou.

In July 2021, the United States and its allies officially accused China's Ministry of State Security (MSS) of overseeing a hacking group. Several members of this group were charged with orchestrating a multi-year campaign that targeted various sectors, aiming to steal trade secrets, intellectual property, and valuable information.

In recent years, the APT40 group has been linked to waves of attacks using the ScanBox recognition framework, as well as exploiting a security in WinRAR (CVE-2023-38831, CVSS score: 7.8). These actions are part of a phishing targeting Papua New Guinea, with the aim of delivering a backdoor known as BOXRAT.

Later, in March of the current year, the New Zealand government recognized the threat actor in the compromise of the Office of the Parliamentary Counsel and the Parliamentary Service in 2021.

“APT40 discovers new vulnerabilities in widely used public software, such as Log4j, Atlassian Confluence, and Microsoft Exchange, to target vulnerable infrastructure,” the authors said.

«The APT40 conducts systematic reconnaissance on significant networks, including those in the countries of the editors, seeking opportunities to endanger its targets. This tactical reconnaissance allows the group to identify vulnerable devices, devices that are at the end of their life or are no longer maintained, and to quickly exploit these vulnerabilities.»

See also: Neiman Marcus: Data breach exposes 31 million email addresses

Notable among the techniques used by the state-funded hacking crew is the development of web shells for persistence and maintaining access to the victim's environment, as well as the use of Australian websites for command and control purposes (C2).

It has also been observed that it incorporates unpatched or unupdated devices, such as small-office/home-office (SOHO) routers, as part of the attack infrastructure. This is done in an attempt to reroute malicious traffic and avoid detection. Its operation is similar to that used by other groups based in China, such as Volt Typhoon.

Σύμφωνα με την Mandiant, τη θυγατρική της Google, αυτό είναι μέρος μιας ευρύτερης μετάβασης στην κυβερνοκατασκοπεία που προέρχεται από την Κίνα, η οποία σκοπεύει να φέρει τη μυστικότητα στο προσκήνιο.Οι επιτιθέμενοι όλο και περισσότερο στρατολογούν προηγμένες συσκευές δικτύου, λειτουργικούς αναμεταδότες (ORB) και τεχνικές LotL (Living off the Land) για να δρουν απαρατήρητοι.

APT40 Rapid exploit

Attack chains also include reconnaissance activities, privilege escalation, and lateral movements. They use the Remote Desktop Protocol (RDP) to steal credentials and exfiltrate critical information.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Read more: 200 million Twitter data leaks online

To mitigate the risks from such threats, organizations must maintain adequate logging mechanisms, implement multi-factor authentication (MFA), adopt a robust patch management system, replace end-of-life equipment, disable unused services, ports, and protocols, and segment networks to prevent access to sensitive data.

Source: thehackernews

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS