Security News > 2020 > March > Chinese Hackers Exploit Cisco, Citrix Flaws in Massive Espionage Campaign
Between Jan. 20 and March 11, researchers observed APT41 exploiting vulnerabilities in Citrix NetScaler/ADC, Cisco routers and Zoho ManageEngine Desktop Central as part of the widespread espionage campaign.
Starting on Jan. 20, researchers observed the threat group attempting to exploit the notorious flaw in Citrix Application Delivery Controller and Citrix Gateway devices revealed as a zero-day then patched earlier this year.
On Feb. 21, researchers next observed APT41 switching gears to exploit a Cisco RV320 router at a telecommunications organization.
The threat actors downloaded an executable and linkable format binary payload. Researchers aren't sure what specific exploit was used in this case, but pointed to a Metasploit module combining two CVEs to enable remote code execution on Cisco RV320 and RV325 small business routers.
The first lull, between Jan. 23 and Feb. 1, was likely related to the Chinese Lunar New Year holidays: "This has been a common activity pattern by Chinese APT groups in past years as well," said researchers.
News URL
https://threatpost.com/chinese-hackers-exploit-cisco-citrix-espionage/154133/
Related news
- Russia-Linked Turla Exploits Pakistani Hackers' Servers to Target Afghan and Indian Entities (source)
- Researchers Uncover 4-Month Cyberattack on U.S. Firm Linked to Chinese Hackers (source)
- Hackers Target Uyghurs and Tibetans with MOONSHINE Exploit and DarkNimbus Backdoor (source)
- U.S. org suffered four month intrusion by Chinese hackers (source)
- Hackers Weaponize Visual Studio Code Remote Tunnels for Cyber Espionage (source)
- Chinese hackers use Visual Studio Code tunnels for remote access (source)
- U.S. Charges Chinese Hacker for Exploiting Zero-Day in 81,000 Sophos Firewalls (source)
- Hackers Exploit Webview2 to Deploy CoinLurker Malware and Evade Security Detection (source)
- Hackers exploit DoS flaw to disable Palo Alto Networks firewalls (source)
- White House links ninth telecom breach to Chinese hackers (source)