HomeSecurityUAT-5918 hackers target critical infrastructure with web shells

UAT-5918 hackers target critical infrastructure with web shells

Cisco Talos security researchers have discovered a new hacking group named UAT-5918 , which has been attacking critical infrastructure in Taiwan since at least 2023 .

critical infrastructure hackers UAT-5918

Cisco Talos says that UAT-5918 attempts to maintain long-term access to compromised systems to steal information and credentials. The hackers use a combination of web shells and open source tools to carry out malicious activities and establish persistence on victims' networks.

Hackers mainly target companies in the following industries: information technology, telecommunications, academia, and healthcare.

See also: Cyber ​​espionage: Aquatic Panda hackers targeted 7 organizations

Researchers believe this is an APT groupthat seeks to establish long-term access to victim environments. Commonalities have also been observed with several Chinese groups, monitored as Volt Typhoon, Flax Typhoon, Tropic Trooper, Earth Estries, and Dalbit.

How do attacks work?

The attacks involve exploiting N-day vulnerabilities in unpatched web and application servers exposed to the internet. Thanks to these vulnerabilities, hackers gain access to the victim's system , and then install open source tools to conduct reconnaissance, gather system information, and lateral movement.

Then, UAT-5918 hackers use Fast Reverse Proxy (FRP) and Neo-reGeorge to create reverse proxy tunnels to access compromised endpoints via remote hosts (controlled by the attackers).

See also: Hackers exploit Apache Tomcat RCE vulnerability

Security researchers also used tools such as Mimikatz, LaZagne, BrowserDataLite (a browser-based extractor for collecting credentials), Chopper web shell, Crowdoor , and SparrowDoor.

UAT-5918 hackers target critical infrastructure with web shells

BrowserDataLite, in particular, steals login information, cookies, and browsing history from browsers. The threat actor also engages in systematic data theft by scanning local and shared drives for data of interest.

See also: Hackers exploit Checkpoint driver in BYOVD attacks

The fact that UAT-5918 hackers are focused on long-term access and credential collection suggests that their primary goal is espionage and data theft, which could have serious consequences for organizations in the region. Furthermore, the use of open source tools and web shells makes detection more difficult.

If this attack continues or expands, it could affect government agencies, private companies, and infrastructure networks, reinforcing the need for increased surveillance and improved security measures. Taiwan needs to strengthen its defenses against such threats by incorporating more advanced detection and rapid response technologies.

source: thehackernews.com

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS