Security News > 2020 > April > South Korea-Linked Hackers Targeted Chinese Government via VPN Zero-Day

South Korea-Linked Hackers Targeted Chinese Government via VPN Zero-Day
2020-04-06 18:20

A threat actor linked to South Korea has launched attacks against Chinese government agencies using a zero-day vulnerability affecting a local VPN service, Chinese cybersecurity firm Qihoo 360 reported on Monday.

Qihoo 360 does not directly accuse South Korea of being behind the attacks, but says the threat actor is located in the Korean Peninsula and notes that its victims include North Korea.

According to Qihoo 360, DarkHotel targeted many Chinese institutions starting in March.

The Chinese cybersecurity firm said the attackers served the malware from roughly 200 compromised VPN servers.

A few weeks ago, Qihoo 360 reported that DarkHotel had exploited zero-day vulnerabilities in Firefox and Internet Explorer in attacks aimed at Chinese government organizations.


News URL

http://feedproxy.google.com/~r/Securityweek/~3/dDjI326S_Mw/south-korea-linked-hackers-targeted-chinese-government-vpn-zero-day