Inside a Chinese APT's very flexible playbook
Full article618 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
New research from Dell Secureworks is a reminder that adversaries will sooner dust off and refashion old tools than build new ones.
A maxim of cybersecurity holds that hackers will exert just enough resources to compromise a network or avoid detection. Why deploy new, top-shelf tools when you can just refashion old ones?
The strategy is on full display in research on a Chinese government-linked hacking group that Dell Technologies’ Secureworks published Wednesday. The hackers — categorized as an advanced persistent threat by researchers and usually labeled APT27 or Bronze Union — dusted off and upgraded a couple of long-available digital weapons to carry out intrusions in 2018, the report said.
“The threat actors have access to a wide range of tools, so they can operate flexibly and select tools appropriate for intrusion challenges,” the research says.
One remote access trojan (RAT) was developed over a decade ago, but Bronze Union added a packet redirection tool and digital certificates signed by two Chinese technology companies before deploying it last year, according to the research. The group also modified the well-known Gh0st RAT and used it on multiple systems to achieve its objective within a breached environment, Secureworks said.
“The fact that Secureworks observes the use of these tools nearly 13 years later by Bronze Union speaks to the effectiveness of this threat group,” Matthew Webster, senior security researcher at Secureworks Counter Threat Unit, told CyberScoop.
Bronze Union, the researchers said, was “one of the most prolific and active” hacking outfits they tracked in 2017 and 2018. In 2017, the group broke into a Mongolian national data center, allowing the hackers to plant malware on Mongolian government websites, CyberScoop has reported. And in the last three years, the group has targeted the networks of political, humanitarian, technology and manufacturing organizations, according to Secureworks.
The determination and ability to maintain prolonged access to a victim network is typical of hackers on a well-funded mission.
“After accessing a network, the threat actors are adept at circumventing common security controls, escalating privileges, and maintaining their access to high-value systems over long periods of time,” the Secureworks research says.
The report comes as the Trump administration has pressured China to curtail its alleged hacking for economic gain through a series of indictments and public condemnations. U.S. officials earlier this month warned companies about how another Chinese hacking group, known as APT10, has evolved in its alleged efforts to steal corporate data.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Jail time for Maine child in 764 marks turning point in federal law enforcement
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/apt27-chinese-secureworks-report/