NSA says Chinese hackers are actively attacking flaw in widely used networking device
Full article827 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
A severe flaw in a Citrix device allowed hackers believed to be part of the group known as APT5 to carry out remote code execution.
The National Security Agency said on Tuesday that Chinese state-backed hackers are exploiting a flaw in a widely used networking device that allows an attacker to carry out remote code execution.
In its advisory, the NSA said it believes a Chinese hacking crew known as APT5 “has demonstrated capabilities” against an application delivery controller made by Citrix. Citrix released an emergency patch to fix the vulnerability on Monday and said that “exploits of this issue on unmitigated appliances in the wild have been reported.”
The spy agency’s advisory effectively burns down an apparent Chinese intelligence operation by exposing its tools and advising potential victims on how to prevent further attacks. The NSA has historically preferred to monitor such attacks rather than publicizing them, but in recent years it has grown more proactive in sharing intelligence on attackers such as APT5.
Now that they’ve been burned, the hackers behind the operation targeting Citrix may step up the pace of their attacks. “Chinese actors with a history of using zero days often ramp up after they’ve been discovered,” said John Hultquist, the vice president for intelligence analysis at Mandiant. While they are undetected, these groups will try to avoid tripping the alarm, but “after the zero day is observed all bets are off,” he said.
Active since at least 2007, APT5 is a well-known Chinese hacking group with a history of attacking networking companies and devices. The group has a history of attacking telecommunications and technology firms, with a particular interest in defense-related technology. In 2019, the group was caught attacking virtual private networks to steal user credentials and monitor traffic.
The revelation of the Citrix flaw on Tuesday comes a day after Fortinet revealed a severe vulnerability that also allows remote code execution for one of its VPN products. The company said it was aware of “an instance where this vulnerability was exploited in the wild” but did not attribute the attack. The company urged its customers to patch affected systems immediately.
The news of the Citrix vulnerability so shortly after the Fortinet flaws means that large numbers of systems may be exposed to attack until patches are implemented on affected systems.
“Combined with the recent Fortinet vulnerability it could make for a lousy Christmas,” said Allan Liska, an intelligence analyst at Recorded Future. “The two are equally bad in terms of being remote code execution and pre-auth. They are also both devices that tend to be publicly accessible from the internet, which means bad guys are likely already scanning for potential victims.”
More Scoops
Officials disrupt Chinese espionage operation that hit multiple federal agencies
The full hacking suite, seized by authorities, allowed Chinese government funded attackers to intrude highly sensitive networks undetected for more than eight years.
Sen. Wyden urges feds to discard older, insecure, public-facing VPNs
Where’s the Trump administration line on AI regulation?
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Jail time for Maine child in 764 marks turning point in federal law enforcement
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/citrix-china-apt5-hackers/