HomeSecurityChinese hackers were in a US organization's network for 4 months

Chinese hackers were on a US organization's network for 4 months

Chinese hackers are suspected of an attack on a major American organizationthat took place earlier this year and lasted four months.

Chinese hackers were on a US organization's network for 4 months

According to Symantec, the first evidence of malicious activity was detected on April 11, 2024, and the attack appears to have continued until August. However, the company does not rule out the possibility that the intrusion occurred earlier.

The attackers spread across the organization’s network, compromising multiple computers ,” the Symantec Threat Hunter team said in a new report .

See also: Chinese hackers target Tibetan organizations with Malware

The researchers noted that among the targets were Exchange servers, suggesting that the attackers were gathering information by harvesting emails. In addition, tools data extraction, apparently aimed at stealing valuable organizational data.

The name of the American organization breached by the Chinese hackers was not revealed, but researchers said it also has a significant presence in China.

Symantec believes the attackers are Chinese hackers due to some attack tactics and artifacts that have previously been linked to a Chinese state-owned enterprise, codenamed Crimson Palace.

See also: Chinese hackers Volt Typhoon “rebuild” the KV-Botnet

In addition, the victim organization had also been targeted in 2023 by an attacker associated with the Chinese hacking group Daggerfly (also known as Bronze Highland, Evasive Panda, and StormBamboo).

According to the researchers, in the latest attack, hackers used DLL side-loading (to execute malicious payloads) and open-source tools such as FileZilla, Impacket, and PSCP. Live off-the-land (LotL) programs such as Windows Management Instrumentation (WMI), PsExec, and PowerShell were also detected

The exact mechanism used to initially access and compromise the network remains unknown. According to Symantec, the machine on which the first indicators of compromise were detected included a command that was executed via WMI from another system on the network.

The fact that the command originated from another machine on the network suggests that the attackers had already compromised at least one other machine on the organization’s network and that the intrusion may have begun before April 11,” the company said.

See also: Chinese hackers MirrorFace target European diplomats

American organization Chinese hackers

Chinese hackers

Chinese hackers will continue to pose a significant threat in the world of cyberwarfare. It is essential for governments and organizations to remain vigilant and take the necessary measures to protect against potential attacks. In addition, countries must work together to address cyber threats and promote a secure digital landscape.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Taking some basic cybersecurity can also help prevent attacks. Creating strong passwords, avoiding suspicious emails, creating backups, using antivirus software, updating software and applications, and staying informed about the latest cyber threats can go a long way in protecting against Chinese hackers and other cyber attackers.

Source: thehackernews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS