Threat Intelligence

China-linked cyberespionage aimed at influencing US policy uncovered

China Flag Made of Binary Code and Chinese Symbols on Red Backgr

China-linked hackers have compromised a U.S. non-profit entity as part of efforts to sway the country's policy on international issues earlier this year, The Hacker News reports.

After scanning for multiple exploits including the Apache Log4j flaw, tracked as CVE-2021-44228, the Atlassian Confluence vulnerability, tracked as CVE-2022-26134, and the Apache Struts issue, tracked as CVE-2017-9805 and eventually infiltrating the organization's server through suspected brute-forcing or credential stuffing on Apr. 5, attackers waited until almost two weeks later before running curl commands that sought to obtain network configurationn data, an analysis from Broadcom's Symantec and Carbon Black teams revealed.

Threat actors also created a scheduled task that activated a Microsoft binary executing an unknown payload believed to be a remote access trojan, as well as the Vipre AV component that enabled side-loading of a DLL previously harnessed by the Chinese threat operation Space Pirates.

"It is clear from the activity on this victim that the attackers were aiming to establish a persistent and stealthy presence on the network, and they were also very interested in targeting domain controllers, which could potentially allow them to spread to many machines on the network," said researchers, who noted that Chinese threat actors' prolonged tool sharing practice has been complicating attribution to a particular operation.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds