Security News > 2024 > February > Chinese hackers breached Dutch Ministry of Defense
Chinese state-sponsored hackers have breached the Dutch Ministry of Defense last year and deployed a new remote access trojan malware to serve as a backdoor.
"The effects of the intrusion were limited because the victim network was segmented from the wider MOD networks," the Dutch Military Intelligence and Security Service and the General Intelligence and Security Service noted.
A new RAT. During an investigation of a intrusion in the MOD's newtork last year, MIVD and AIVD uncovered a previously unknown malware that they named Coathanger.
"The name is derived from the peculiar phrase that the malware uses to encrypt the configuration on disk: 'She took his coat and hung it up'," MIVD and AIVD explained in the security advisory.
Coathanger is a remote access trojan that was specifically built for Fortinet's FortiGate appliances.
In this particular incident, hackers gained initial access to FortiGate devices by exploiting the critical FortiOS pre-auth RCE vulnerability, downloaded Coathanger, carried out reconnaissance of the network and managed to steal a list of user accounts from the Active Directory server.
News URL
https://www.helpnetsecurity.com/2024/02/07/chinese-hackers-dutch-mod/
Related news
- CISA shares critical infrastructure defense tips against Chinese hackers (source)
- Chinese State Hackers Target Tibetans with Supply Chain, Watering Hole Attacks (source)
- Chinese Earth Krahang hackers breach 70 orgs in 23 countries (source)
- Hackers Hit Indian Defense, Energy Sectors with Malware Posing as Air Force Invite (source)
- A “cascade” of errors let Chinese hackers into US government inboxes (source)