HomeSecurityCyber ​​​​espionage: Aquatic Panda hackers targeted 7 organizations

Cyber ​​espionage: Aquatic Panda hackers targeted 7 organizations

Chinese hackers Aquatic Panda were linked to a “global cyberespionage” that took place in 2022 targeting seven organizations.

Aquatic Panda Chinese hackers Cyber ​​espionage

Targets included governments, Catholic charities, non-governmental organizations (NGOs), and think tanks in Taiwan, Hungary, Turkey, Thailand, France, and the United States. According to ESET, the malicious campaign took place over a 10-month period between January and October 2022.

The Aquatic Panda hackers used implants, such as ShadowPad, SodaMaster , and Spyder, which have generally been linked to China.

See also: Chinese hackers MirrorFace target victims with ANEL and AsyncRAT

Aquatic Panda is also known as Bronze University, Charcoal Typhoon, Earth Lusca, and RedHotel and is a cyberespionage group from China that has been active since at least 2019. ESET tracks the group as FishMonger.

Cyberespionage attacks in 2022 are characterized by the use of five different malware families:

  • ScatterBee loader
  • ShadowPad
  • Spyder
  • SodaMaster
  • RPipeCommander

Researchers are unsure how initial access to target systems is achieved.

SodaMaster was originally used by the APT10, but its use in cyberespionage attacks suggests that it may be used by many Chinese APT groups.

See also: Chinese hackers target Juniper Networks routers

RPipeCommander, another C++ implant used by Chinese hackers Aquatic Panda, was deployed against a government agency in Thailand. It acts as a reverse shell that can execute commands (using cmd.exe) and collect outputs.

Cyber ​​espionage: Aquatic Panda hackers targeted 7 organizations

Chinese hackers pose a significant threat to organizations and governments around the world with highly adaptive techniques and use of advanced espionage tools.

See also: North Korean hackers “uploaded” spyware to Google Play

The 2022 attacks by Chinese hackers Aquatic Panda serve as a reminder of the ongoing threat posed by such cyber espionage campaigns and the need for enhanced cybersecurity measures. It is vital that government agencies and organizations remain vigilant and take the necessary steps to defenses cybersecurity. It is important for organizations to regularly update their systems, implement strong security measures, and educate employees about new threats.

At the same time, cooperation between countries to share information and implement strong security protocols can also help mitigate the risk of such attacks.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Source: thehackernews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS