Security News > 2020 > March > Chinese Hackers Exploit Cisco, Citrix Flaws in Massive Espionage Campaign
Between Jan. 20 and March 11, researchers observed APT41 exploiting vulnerabilities in Citrix NetScaler/ADC, Cisco routers and Zoho ManageEngine Desktop Central as part of the widespread espionage campaign.
Starting on Jan. 20, researchers observed the threat group attempting to exploit the notorious flaw in Citrix Application Delivery Controller and Citrix Gateway devices revealed as a zero-day then patched earlier this year.
On Feb. 21, researchers next observed APT41 switching gears to exploit a Cisco RV320 router at a telecommunications organization.
The threat actors downloaded an executable and linkable format binary payload. Researchers aren't sure what specific exploit was used in this case, but pointed to a Metasploit module combining two CVEs to enable remote code execution on Cisco RV320 and RV325 small business routers.
The first lull, between Jan. 23 and Feb. 1, was likely related to the Chinese Lunar New Year holidays: "This has been a common activity pattern by Chinese APT groups in past years as well," said researchers.
News URL
https://threatpost.com/chinese-hackers-exploit-cisco-citrix-espionage/154133/
Related news
- Chinese Hackers Exploit T-Mobile and Other U.S. Telecoms in Broader Espionage Campaign (source)
- Chinese hackers exploit Fortinet VPN zero-day to steal credentials (source)
- US says Chinese hackers breached multiple telecom providers (source)
- Chinese Hackers Use CloudScout Toolset to Steal Session Cookies from Cloud Services (source)
- Microsoft: Chinese hackers use Quad7 botnet to steal credentials (source)
- Sophos reveals 5-year battle with Chinese hackers attacking network devices (source)
- Sophos Versus the Chinese Hackers (source)
- FBI Seeks Public Help to Identify Chinese Hackers Behind Global Cyber Intrusions (source)
- Cisco bug lets hackers run commands as root on UWRB access points (source)
- HTTP your way into Citrix's Virtual Apps and Desktops with fresh exploit code (source)