These tiny islands are at the heart of an uncovered Chinese phishing campaign
Full article705 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
Chinese cyber-espionage campaigns frequently coincide with territorial disputes.
Suspected Chinese hackers are behind a phishing campaign apparently aimed at collecting data about Vietnamese government officials amid an ongoing territorial dispute between the two nations, according to new findings.
A hacking group known as Pirate Panda, which has possible ties to the Chinese government, is trying to trick Vietnamese government officials into clicking on malicious Microsoft Excel documents attached to emails purportedly detailing festivities for Vietnamese holidays, according to research the threat intelligence firm Anomali shared with CyberScoop.
Targeted individuals appear to be located in Da Nang, Vietnam, near a collection of landmasses in the South China Sea known as the Paracel Islands. The area is one of the most hotly contested regions of the South China Sea, with Beijing claiming ownership of much of the waterway. In recent days, Vietnam has said it does not recognize China’s claims over the islands, while China has said that Vietnamese claims to the area are illegal.
In this case, Pirate Panda appears to be using email lures which include itineraries for two Vietnamese holidays, Reunification Day and Labor Day, scheduled for April 30 and May 1, respectively. Malicious Microsoft Excel documents attached to the message are capable of infecting the victims with a malware similar to KeyBoy and ExileRat, which steal files and collect system information from a victims’ computer. The Pirate Panda group has used both tools in the past, Anomali noted.
The use of holidays so near on the calendar as bait may also indicate an urgency to collecting victims’ data, researchers suggested.
“It is possible that the national holidays are being used as a lure, because the threat actors may have an imminent desire for lateral movement and access to data,” the report said.
Technical evidence also suggests the intended victims work in a Vietnamese government data center in Da Nang, based on the contents of the malicious files shared through the email campaign.
Pirate Panda has seized on major news events in recent months to try to target victims. The same group tried using phishing lures highlighting the coronavirus pandemic in February, the security firm CrowdStrike found.
Chinese hackers frequently launch cyber-espionage campaigns against targets related to its territorial standoffs. In 2018, for example, attackers hit U.S. engineering and defense firms which had access to sensitive information related to the South China Sea disputes, such as radar range and how well a system could detect activity underwater — information that could work to Beijing’s advantage.
In recent days, FireEye exposed some suspected Vietnamese government-linked hacking campaigns targeting Chinese government entities in search of information on the coronavirus response in China. Whether that attack is linked to the Pirate Panda operation in any way remains unclear.
Neither China’s Ministry of Foreign Affairs nor Vietnam’s Ministry of Foreign Affairs returned messages seeking comment before press time.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Jail time for Maine child in 764 marks turning point in federal law enforcement
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/south-china-sea-maritime-hacking-vietnam/