Security News > 2020 > August > US Government Warns of a New Strain of Chinese 'Taidoor' Virus

"[The] FBI has high confidence that Chinese government actors are using malware variants in conjunction with proxy servers to maintain a presence on victim networks and to further network exploitation," the US Cybersecurity and Infrastructure Security Agency, the Federal Bureau of Investigation, and the Department of Defense said in a joint advisory.
The US Cyber Command has also uploaded four samples of the Taidoor RAT on the public malware repository VirusTotal to let 50+ Antivirus companies check the virus's involvement in other unattributed campaigns.
In an analysis by Trend Micro researchers in 2012, the actors behind Taidoor were found to leverage socially engineered emails with malicious PDF attachments to target the Taiwanese government.
Calling it a "Constantly evolving, persistent threat," FireEye noted significant changes in its tactics in 2013, wherein "The malicious email attachments did not drop the Taidoor malware directly, but instead dropped a 'downloader' that then grabbed the traditional Taidoor malware from the Internet."
In addition to executing remote commands, Taidoor comes with features that allow it to collect file system data, capture screenshots, and carry out file operations necessary to exfiltrate the gathered information.
News URL
http://feedproxy.google.com/~r/TheHackersNews/~3/WyH5HVBucA4/chinese-hacking-malware.html
Related news
- Chinese cyber-spies reportedly targeted sanctions intel in US Treasury raid (source)
- US sanctions Chinese company linked to Flax Typhoon hackers (source)
- US adds web and gaming giant Tencent to list of Chinese military companies (source)
- US Treasury Department Sanctions Chinese Company Over Cyberattacks (source)
- US Treasury hack linked to Silk Typhoon Chinese state hackers (source)
- US Chip Export Rule Proposes Limits to Thwart Chinese GPUs (source)
- FBI wipes Chinese PlugX malware from over 4,000 US computers (source)
- FBI deletes Chinese PlugX malware from thousands of US computers (source)
- US sanctions Chinese firm, hacker behind telecom and Treasury hacks (source)
- Chinese hackers breach more US telecoms via unpatched Cisco routers (source)