Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

Iran’s state TV is driven in the middle of his brother amid geopolitical tensions; 90 million dollars stole in the cry

June 20, 2025

A massive DDOS attack 7.3 TBPS provides 37.4 TV in 45 seconds, focusing on the hosting provider

June 20, 2025

6 Steps to 24/7 Internal Success SoC

June 20, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » Researchers reveal espionage tactics of Chinese APT groups in Southeast Asia
Global Security

Researchers reveal espionage tactics of Chinese APT groups in Southeast Asia

AdminBy AdminDecember 11, 2024No Comments3 Mins Read
Espionage Tactics of Chinese Hackers
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


December 11, 2024Ravi LakshmananCyber ​​espionage / Cyber ​​attack

Spy tactics of Chinese hackers

The alleged Chinese threat actor has been linked to a series of cyberattacks targeting prominent organizations in Southeast Asia since at least October 2023.

The espionage campaign targeted organizations in a variety of sectors, including government ministries in two different countries, an air traffic control organization, a telecommunications company and the Symantec Threat Hunter Team’s media. said in a new report shared with The Hacker News.

The attacks, which used tools previously identified as linked to China’s Advanced Persistent Threat Groups (APTs), are characterized by the use of both open source and life-off-the-land (LotL) techniques.

Cyber ​​security

This includes the use of reverse proxies such as Rakshasa and A stowawayas well as asset discovery and identification tools, keyloggers, and password stealers. Also deploys during attacks PlugX (aka Korplug), a remote access Trojan used by several Chinese hacking groups.

“Threat actors also install customized DLLs that act as authentication mechanism filters, allowing them to intercept login credentials,” Symantec wrote. The Broadcom-owned company told The Hacker News that it could not determine the original infection vector in any of the attacks.

In one attack on the facility, which spanned three months from June to August 2024, the adversary conducted reconnaissance and reset passwords, installed a keylogger, and executed DLL payloads capable of capturing user login information.

Symantec noted that attackers were able to maintain covert access to compromised networks for extended periods of time, allowing them to harvest passwords and display interesting networks. The collected information was compressed into password-protected archives using WinRAR and then uploaded to cloud storage services such as File.io.

“This extended dwell time and calculated approach highlight the sophistication and persistence of threat actors,” the company said. “The geographic location of the targeted organizations, as well as the use of tools previously associated with Chinese APT groups, suggests that these activities are the work of Chinese actors.”

Notably, the ambiguity in attributing these attacks to a specific Chinese threat actor underscores the difficulty of tracking cyber espionage groups when they often share tools and use the same techniques.

Cyber ​​security

Geopolitical tensions in Southeast Asia are over continues territorial disputes in the South China Sea have been complemented by a series of cyberattacks targeting the region, as evidenced by threat groups tracked as Unfading sea mist, Mustang Panda, CeranaKeeperand Operation Raspberry Palace.

The development comes a day after SentinelLabs’ SentinelOne and Tinexta Cyber opened attacks carried out by the China-nexus cyber-espionage group have targeted major business-to-business IT service providers in southern Europe as part of a cluster of activities called Operation Digital Eye.

Last week also Symantec revealed that an unnamed large US organization was hacked by suspected Chinese threat actors between April and August 2024, during which time they moved across the network, compromising multiple computers and potentially stealing data.

Did you find this article interesting? Follow us Twitter  and LinkedIn to read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

Iran’s state TV is driven in the middle of his brother amid geopolitical tensions; 90 million dollars stole in the cry

June 20, 2025

A massive DDOS attack 7.3 TBPS provides 37.4 TV in 45 seconds, focusing on the hosting provider

June 20, 2025

6 Steps to 24/7 Internal Success SoC

June 20, 2025

67 Trojanized GitHub repository found in the company, orientation on gamers and developers

June 20, 2025

Safe Coding Vibe: Full New Guide

June 19, 2025

Bluenoroff Deepfake Zoom AFM Hits Crypto employee with malicious MacOS software

June 19, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

Iran’s state TV is driven in the middle of his brother amid geopolitical tensions; 90 million dollars stole in the cry

June 20, 2025

A massive DDOS attack 7.3 TBPS provides 37.4 TV in 45 seconds, focusing on the hosting provider

June 20, 2025

6 Steps to 24/7 Internal Success SoC

June 20, 2025

67 Trojanized GitHub repository found in the company, orientation on gamers and developers

June 20, 2025

Safe Coding Vibe: Full New Guide

June 19, 2025

Bluenoroff Deepfake Zoom AFM Hits Crypto employee with malicious MacOS software

June 19, 2025

Discover the areas hiding in trusted instruments – find out how in this free expert session

June 19, 2025

Russian APT29 operates Gmail app passwords to get around 2FA in the target phishing campaign

June 19, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Iran’s state TV is driven in the middle of his brother amid geopolitical tensions; 90 million dollars stole in the cry

June 20, 2025

A massive DDOS attack 7.3 TBPS provides 37.4 TV in 45 seconds, focusing on the hosting provider

June 20, 2025

6 Steps to 24/7 Internal Success SoC

June 20, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.