Security News > 2024 > February > Chinese hackers breached Dutch Ministry of Defense
Chinese state-sponsored hackers have breached the Dutch Ministry of Defense last year and deployed a new remote access trojan malware to serve as a backdoor.
"The effects of the intrusion were limited because the victim network was segmented from the wider MOD networks," the Dutch Military Intelligence and Security Service and the General Intelligence and Security Service noted.
A new RAT. During an investigation of a intrusion in the MOD's newtork last year, MIVD and AIVD uncovered a previously unknown malware that they named Coathanger.
"The name is derived from the peculiar phrase that the malware uses to encrypt the configuration on disk: 'She took his coat and hung it up'," MIVD and AIVD explained in the security advisory.
Coathanger is a remote access trojan that was specifically built for Fortinet's FortiGate appliances.
In this particular incident, hackers gained initial access to FortiGate devices by exploiting the critical FortiOS pre-auth RCE vulnerability, downloaded Coathanger, carried out reconnaissance of the network and managed to steal a list of user accounts from the Active Directory server.
News URL
https://www.helpnetsecurity.com/2024/02/07/chinese-hackers-dutch-mod/
Related news
- US says Chinese hackers breached multiple telecom providers (source)
- Chinese Hackers Use CloudScout Toolset to Steal Session Cookies from Cloud Services (source)
- Microsoft: Chinese hackers use Quad7 botnet to steal credentials (source)
- Sophos reveals 5-year battle with Chinese hackers attacking network devices (source)
- Sophos Versus the Chinese Hackers (source)
- FBI Seeks Public Help to Identify Chinese Hackers Behind Global Cyber Intrusions (source)
- Chinese hackers exploit Fortinet VPN zero-day to steal credentials (source)
- Chinese Hackers Exploit T-Mobile and Other U.S. Telecoms in Broader Espionage Campaign (source)
- Chinese hackers target Linux with new WolfsBane malware (source)
- Hackers abuse Avast anti-rootkit driver to disable defenses (source)