Chinese Hacking Groups Used Shared Attack Tool Against US Aerospace Firms, NGOs

Chinese cyber-espionage groups used the same sophisticated hacking tool in campaigns targeting U.S. aerospace companies, nongovernmental organizations, mining companies, and commodity traders, according to two cybersecurity firms that separately investigated the activity.

Volexity, a Virginia-based cybersecurity firm, said on Sept. 21 its discovery of another Chinese hacking group using the same tool added to evidence of coordinated sharing within China’s cyber-espionage community.

The company said the widespread adoption “suggests a coordinated effort within the Chinese CNE community,” referring to computer network exploitation, and assessed that the core tool was likely shared, customized, and used by multiple groups.

Proofpoint, a U.S. cybersecurity company, separately documented on Sept. 9 the same capability in campaigns against a small number of U.S. NGOs, mining companies, commodity-trading firms, and multiple U.S. aerospace companies. It found several espionage groups adopting the tool within days of one another, with most of the observed clusters having a suspected China nexus.

Neither company has publicly identified who developed the tool or how it reached the different hacking groups.

The Epoch Times asked both companies whether they had identified its developer or distributor and whether they had found additional U.S. targets. Neither responded by publication time.

Same Tool, Different Targets

The hacking groups pursued different victims and installed different spying software after gaining access, but researchers found that they relied on the same underlying break-in capability.

The attacks took advantage of previously unknown weaknesses in Google Chrome and Microsoft Windows. If successful, they could allow hackers to install spying software and maintain access to a victim’s computer.

Volexity said the additional Chinese operator it identified used the same attack chain on Sept. 3 and 4, when the vulnerabilities were still unpatched.

The company cautioned that what Volexity and Proofpoint have observed may represent only part of the activity.

“The full scope and impact are likely far broader,” Volexity said.

Keep reading

Unknown's avatar

Author: HP McLovincraft

Seeker of rabbit holes. Pessimist. Libertine. Contrarian. Your huckleberry. Possibly true tales of sanity-blasting horror also known as abject reality. Prepare yourself. Veteran of a thousand psychic wars. I have seen the fnords. Deplatformed on Tumblr and Twitter.

Leave a comment