ZeroHour
The Recordpublished ()ingested

China-linked hackers target European healthcare orgs in suspected espionage campaign

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-24919
Information Disclosure in Internet-Facing Check Point Quantum Security Gateways

Check Point Quantum Security Gateways contain an information disclosure flaw (CWE-200) that can expose information stored on the appliance to unauthorized parties. It is triggered when an attacker targets a gateway connected to the internet with IPSec VPN, Remote Access VPN, or Mobile Access enabled, sending crafted requests to the exposed VPN services. A successful attacker gains unauthorized access to information on the gateway, and CISA notes known use of this flaw in ransomware campaigns. The issue spans multiple Check Point product lines: CloudGuard Network, Quantum Scalable Chassis, Quantum Security Gateways, and Quantum Spark Appliances. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV catalog on 2024-05-30 with ransomware use listed, and EPSS assigns a 100% probability of exploitation within 30 days, though no public proof-of-concept is known.

Do: Apply the hotfix Check Point distributes per its advisory (SK170863) to all internet-facing gateways running IPSec VPN, Remote Access VPN, or Mobile Access; this is also the CISA KEV required action. Where the hotfix cannot be applied immediately, restrict or disable the Remote Access VPN and Mobile Access software blades as an interim mitigation. Review gateway and VPN logs for signs of exploitation and prioritize remediation given confirmed ransomware use.

8.6100% KEV ransomware
  • Check Point Quantum Security Gateways
  • Check Point CloudGuard Network
  • Check Point Quantum Scalable Chassis
  • +1 more
largetens of thousands of internet-exposed VPN gateways (10k-100k systems)
Full article488 words · extracted from therecord.media · click to collapse

A previously unknown hacking group has been spotted targeting European healthcare organizations using spyware linked to Chinese state-backed hackers and a new ransomware strain, researchers said.

The campaign, which took place in the second half of 2024, likely exploited a vulnerability in security products from an Israel-based cybersecurity firm, according to researchers at Orange Cyberdefense. 

The flaw, tracked as CVE-2024-24919, allows attackers to access sensitive data on Check Point’s Security Gateway. The vulnerability likely enabled the hackers to steal user credentials and access virtual private networks (VPNs) using legitimate accounts, the researchers said.

Check Point patched the flaw last May, but researchers said the devices targeted by hackers were likely still vulnerable at the time of their compromise.

Orange Cyberdefense said it could not attribute the campaign to a specific actor said the hackers were likely linked to China.

Connection to Chinese cyber groups

The hackers, dubbed Green Nailao, deployed ShadowPad and PlugX malware, both commonly associated with Chinese cyberespionage groups, as well as a previously undocumented ransomware strain called NailaoLocker.

Both ShadowPad and PlugX are widely used by China-aligned hacking groups. ShadowPad, a backdoor suspected to be privately shared or sold among Chinese cyber operators since at least 2015, has been deployed in cyberespionage campaigns against governments, energy firms, think tanks and technology companies.

Researchers identified a new version of ShadowPad in the latest campaign, which they said uses enhanced techniques to evade detection and analysis.

PlugX, another malware frequently used by Chinese state-backed hackers, was first observed in attacks on Japan in 2008 and has since been deployed against targets across Asia. In January, U.S. officials said they had removed PlugX from more than 4,200 American computers.

Ransomware for profit or espionage

NailaoLocker, the new ransomware strain discovered in the campaign, was described by researchers as “relatively unsophisticated and poorly designed.” It encrypts files and leaves a ransom note demanding payment in Bitcoin via a ProtonMail address.

Researchers said it was unusual for ShadowPad to be linked to ransomware deployment, raising questions about the hackers’ motives. While state-sponsored cyber groups typically focus on espionage, some could be using ransomware as a source of additional revenue, they said.

Alternatively, the ransomware may have been a false-flag operation intended to divert attention from the real objective — stealing sensitive data.

State-backed hackers, including those linked to China, have previously targeted healthcare organizations, researchers said.

“While such campaigns can sometimes be conducted opportunistically, they often allow threat groups to gain access to information systems that can be used later to conduct other offensive operations,” Orange Cyberdefense said.

No previous article

No new articles

Daryna Antoniuk

is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/china-linked-hackers-target-european-health-orgs