Reuters reports that major Australian pension funds AustralianSuper, Australian Retirement Trust, Insignia, Hostplus, and Rest Super have disclosed being impacted by a series of attacks during the last weekend of March.
Despite being claimed by a source close to the matter to have had over 20,000 accounts compromised as a result of the incident, AustralianSuper only confirmed the theft of up to 600 member passwords as it noted immediate action to secure such accounts. On the other hand, Australian Retirement Trust and Rest Super reported having "several hundreds" and nearly 20,000 accounts affected, respectively. Meanwhile, an investigation into the extent of the incident is being conducted by the other funds. Such a development which comes more than two years after the attack against major Australian health insurance provider Medibank has already prompted Australian National Cyber Security Coordinator Michelle McGuinness to spearhead a coordinated response against attacks targeting the country's $2.6 trillion retirement savings industry.
The HelloNet campaign targets organizations using ViPNet, a Russian information-security product suite commonly used in government and regulated environments.
Zhuoying Chen, 27, and Haojie Zhang, 38, are accused of managing a network that transferred at least $43 million to China, based on information published by Bleeping Computer.
UAT-11795 utilizes novel tools, including the Python-based Starland RAT and the PowerShell-based WLDR agent, which operates entirely in-memory with encrypted beaconing and a Runspace execution engine.