Security News

Suspected Chinese spies break into cloud accounts of News Corp journalists
2022-02-04 21:35

Online work accounts of News Corporation journalists were broken into by snoops with ties to China, it was claimed today. The cyber-attack "Included the targeting of emails and documents of some employees, including journalists," wrote defense editor Larisa Brown.

US bans major Chinese telecom over national security risks
2022-01-28 16:30

The Federal Communications Commission has revoked China Unicom Americas' license, one of the world's largest mobile service providers, over "Serious national security concerns." China Unicom Americas is the largest foreign subsidiary of China Unicom, a Chinese state-owned telecom company.

Australian Prime Minister's WeChat Shanghaied by Chinese patriots
2022-01-24 04:58

Australian Prime Minister Scott Morrison's WeChat account has been taken over by entities that have rebranded it "Australian Chinese new life" and used the account to offer advice on living in Australia for the nation's Chinese community. Morrison, leader of the right-of-centre Liberal Party of Australia, has used Tencent-owned WeChat as a campaigning tool to reach Australia's sizable Chinese community - many of whom are concentrated in particular seats and are therefore considered a sought-after voting bloc.

Chinese Hackers Spotted Using New UEFI Firmware Implant in Targeted Attacks
2022-01-23 22:26

A previously undocumented firmware implant deployed to maintain stealthy persistence as part of a targeted espionage campaign has been linked to the Chinese-speaking Winnti advanced persistent threat group. Kaspersky, which codenamed the rootkit MoonBounce, characterized the malware as the "Most advanced UEFI firmware implant discovered in the wild to date," adding "The purpose of the implant is to facilitate the deployment of user-mode malware that stages execution of further payloads downloaded from the internet."

Chinese APT Hackers Used Log4Shell Exploit to Target Academic Institution
2021-12-30 02:07

A never-before-seen China-based targeted intrusion adversary dubbed Aquatic Panda has been observed leveraging critical flaws in the Apache Log4j logging library as an access vector to perform various post-exploitation operations, including reconnaissance and credential harvesting on targeted systems. Cybersecurity firm CrowdStrike said the infiltration, which was ultimately foiled, was aimed at an unnamed "Large academic institution." The state-sponsored group is believed to have been operating since mid-2020 in pursuit of intelligence collection and industrial espionage, with its attacks primarily directed against companies in the telecommunications, technology, and government sectors.

New Flagpro malware linked to Chinese state-backed hackers
2021-12-28 19:23

BlackTech cyber-espionage APT group has been spotted targeting Japanese companies using novel malware that researchers call 'Flagpro'. The threat actor uses Flagpro in the initial stage of an attack for network reconnaissance, to evaluate the target's environment, and to download second-stage malware and execute it.

Alibaba Cloud slapped by Chinese ministry for mishandling Log4j
2021-12-23 05:58

China's Ministry of Industry and Information Technology has suspended Alibaba Cloud's membership of an influential security board to protest its handling of the Log4j flaw. The move appears odd as The Apache Software Foundation credited Alibaba Cloud's Chen Zhaojunfor identifying and reporting the Log4J flaw in the first place.

Microsoft wins court approval to take over sites run by Chinese crime gang
2021-12-07 05:31

Microsoft has revealed its Digital Crimes Unit won court approval to take control of websites a Chinese gang was using to attack targets across the world - often by exploiting vulnerabilities in Microsoft products. A post attributed to Microsoft's corporate veep for customer security & trust, Tom Burt, states the US District Court for the Eastern District of Virginia has granted Microsoft to take control of malicious websites operated by a group called Nickel that has been around since at least 2016.

Microsoft Seizes 42 Malicious Web Domains Used By Chinese Hackers
2021-12-07 00:14

Microsoft on Monday announced the seizure of 42 domains used by a China-based cyber espionage group that set its sights on organizations in the U.S. and 28 other countries pursuant to a legal warrant issued by a federal court in the U.S. state of Virginia. "Nickel has targeted organizations in both the private and public sectors, including diplomatic organizations and ministries of foreign affairs in North America, Central America, South America, the Caribbean, Europe and Africa," Microsoft's Corporate Vice President for Customer Security and Trust, Tom Burt, said.

Microsoft seizes sites used by APT15 Chinese state hackers
2021-12-06 21:53

Microsoft seized today dozens of malicious sites used by the Nickel China-based hacking group to target organizations in the US and 28 other countries worldwide. "Nickel has targeted organizations in both the private and public sectors, including diplomatic organizations and ministries of foreign affairs in North America, Central America, South America, the Caribbean, Europe and Africa," said Tom Burt, Corporate Vice President for Customer Security & Trust at Microsoft.