HomeSecurityHackers exploit zero-day vulnerability to target internet service providers in the US

Hackers exploit zero-day vulnerability to target US internet service providers

Hackers linked to the Chinese government used a previously unknown software to target internet service providers in the US.

exploit zero=day

The Volt Typhoon gang exploited a vulnerability in a program called Versa Director that the manufacturer had not yet patched . The findings come from researchers at Black Lotus Labs, which is part of cybersecurity firm Lumen.

Read more: CISA: Volt Typhoon hackers target critical infrastructure – Protection tips

Versa software for network management and is used by internet service providers (ISPs) and managed service providers (MSPs), making it a “critical and attractive target” for hackers, researchers said in a report published Tuesday.

This is the latest discovery of the activities of Volt Typhoon, a group believed to be operating on behalf of the Chinese government. The group focuses on targeting critical infrastructure, such as communications and telecommunications networks, with the aim of causing “real-world damage” in a potential future conflict with the United States. U.S. government officials said earlier this year that the hackers were seeking to disrupt any U.S. military response to an expected future invasion of Taiwan.

According to researchers at Black Lotus Labs, the hackers’ goal was to steal and exploit credentials to target future customers of the compromised corporate victims. In other words, the hackers focused on the Versa servers as a connection point from which they could enter other networks associated with the vulnerable servers. Mike Horka, the security researcher who investigated the incident, told TechCrunch.

“This wasn’t just limited to telecommunications, but managed service providers and internet service providers,” Horka said. “These central locations that they can search, which then provide additional access.” Horka said these internet and networking companies are targets themselves, “very likely because of the access they could potentially provide to additional customers by extension.”

See also: US: Volt Typhoon hackers were in a critical infrastructure network for 5 years

Horka said he found four victims in the United States, two ISPs, an MSP and an IT provider. and one victim outside the US, an ISP in India. Black Lotus Labs did not disclose the names of the victims.

Versa's Chief Marketing Officer, Dan Maier, said in an email to TechCrunch that the company has patched the zero-day discovered by Black Lotus Labs.

"Versa confirmed the vulnerability and issued an emergency patch at that time. Since then, we have released a full fix which we have offered to all customers," Maier said, adding that researchers had alerted the company to the flaw in late June.

zero-day vulnerability

Maier told TechCrunch that Versa was able to confirm the vulnerability and track the “APT hacker” at the time of breaching it.

Read more: Proofpoint: Hackers exploited bug to send phishing emails

Black Lotus Labs announced that it had notified the U.S. cybersecurity agency CISA about the zero-day vulnerability and the hacking. On Friday, CISA added the vulnerability to its list of known vulnerabilities that have been exploited. The agency warned that “vulnerabilities of this type are frequently targeted by malicious cyber actors ,posing serious risks to federal operations.”

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Source: techcrunch

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS