Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

Both Vextrio and affiliates control the global network

June 12, 2025

How to Decide Safety Expanding

June 12, 2025

The new tokenbreak attack combines AI moderation with a one -sided character change

June 12, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » A Chinese-speaking group of hackers is engaged in the study of human rights in the Middle East
Global Security

A Chinese-speaking group of hackers is engaged in the study of human rights in the Middle East

AdminBy AdminSeptember 5, 2024No Comments3 Mins Read
Chinese-Speaking Hacker Group
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


September 5, 2024Ravi LakshmananMalware / Human rights

A Chinese-speaking group of hackers

Unnamed government entities in the Middle East and Malaysia are being targeted by an ongoing cyber campaign from June 2023 by an attacker known as Tropic Trooper.

“The detection of this group (tactics, methods and procedures) in critical government structures in the Middle East, especially those involved in the study of human rights, represents a new strategic move for them,” – Sherif Magdi, Kaspersky security researcher. said.

A Russian cybersecurity vendor said it detected activity in June 2024 after discovering a new version of the China Chopper web shell, a tool used by many Chinese-speaking threat actors to remotely access compromised servers, on a public web server hosting an open source system content management system (CMS) called Umbraco.

Cyber ​​security

The attack chain is designed to deliver a malware implant called Crowdoorvariant of Art Sparrow door backdoor documented by ESET back in September 2021. Efforts were ultimately unsuccessful.

Tropic Trooper, also known as APT23, Earth Centaur, KeyBoy and Pirate Panda, of course for his own targeting government, healthcare, transportation and high-tech industries in Taiwan, Hong Kong and the Philippines. The Chinese-language group was estimated to have been active since 2011, sharing close ties with another intrusion group tracked as FamousSparrow.

The latest intrusion noted by Kaspersky is for the compilation of the China Chopper web shell as a .NET module for the Umbraco CMS, with further exploits leading to the deployment of network scanning tools, lateral movement and pre-Crowdoor protection evasion using the Sideloading Method DLL.

A Chinese-speaking group of hackers

Webshells are suspected to be delivered by exploiting known security vulnerabilities in public web applications such as Adobe ColdFusion (CVE-2023-26360) and Microsoft Exchange Server (CVE-2021-34473, CVE-2021-34523and CVE-2021-31207).

Crowdoor, first spotted in June 2023, also functions as a bootloader to dump Cobalt Strike and maintain resilience on infected hosts, and acts as a backdoor to collect sensitive information, launch a reverse shell, remove other malware files, and self-close.

Cyber ​​security

“When the actor became aware that their backdoor was discovered, they attempted to upload new samples to avoid detection, thereby increasing the risk of their new set of samples being discovered in the near future,” Maddy noted.

“The significance of this intrusion is that the Chinese-speaking actor targeted a content management platform that published research on human rights in the Middle East, particularly focusing on the situation surrounding the conflict between Israel and Hamas.”

“Our analysis of this intrusion showed that this entire system was the only target during the attack, indicating a deliberate focus on this particular content.”

Did you find this article interesting? Follow us Twitter  and LinkedIn to read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

Both Vextrio and affiliates control the global network

June 12, 2025

How to Decide Safety Expanding

June 12, 2025

The new tokenbreak attack combines AI moderation with a one -sided character change

June 12, 2025

AI AI agents work on secret accounts – learn how to fasten them in this webinar

June 12, 2025

Zero Press AI Vulnerability exposes Copilot Microsoft 365 data without interaction with users

June 12, 2025

Connecting to Turn Signing Signing Code Screenconnect with -wit security risks

June 12, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

Both Vextrio and affiliates control the global network

June 12, 2025

How to Decide Safety Expanding

June 12, 2025

The new tokenbreak attack combines AI moderation with a one -sided character change

June 12, 2025

AI AI agents work on secret accounts – learn how to fasten them in this webinar

June 12, 2025

Zero Press AI Vulnerability exposes Copilot Microsoft 365 data without interaction with users

June 12, 2025

Connecting to Turn Signing Signing Code Screenconnect with -wit security risks

June 12, 2025

More than 80,000 Microsoft Entra ID credits, directed using an open source Teamfiltration tool

June 12, 2025

Former Black Basta Members use Microsoft teams and Python scripts in 2025

June 11, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Both Vextrio and affiliates control the global network

June 12, 2025

How to Decide Safety Expanding

June 12, 2025

The new tokenbreak attack combines AI moderation with a one -sided character change

June 12, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.