FBI Seeks Public Help to Identify Chinese Hackers Behind Global Cyber Intrusions

November 5, 2024 at 12:36PM The FBI is investigating cyber intrusions involving malware targeting sensitive data from companies and government networks by Chinese state-sponsored groups. Reports by Sophos reveal attacks leveraging multiple vulnerabilities, shifting from widespread to targeted attacks since 2021, compromising critical infrastructure mainly in South and Southeast Asia. ### Meeting Takeaways: 1. **FBI … Read more

Sophos reveals 5-year battle with Chinese hackers attacking network devices

October 31, 2024 at 06:21PM Sophos revealed its “Pacific Rim” reports detailing ongoing conflicts with Chinese threat actors over five years. These groups exploit vulnerabilities in networking devices to deploy malware, monitor communications, and facilitate attacks. Sophos has investigated multiple incidents, attributing them to actors like Volt Typhoon, APT31, and APT41/Winnti. ### Meeting Takeaways: Sophos … Read more

China Accuses U.S. of Fabricating Volt Typhoon to Hide Its Own Hacking Campaigns

October 15, 2024 at 04:54AM China’s CVERC claims the Volt Typhoon cyber threat is a U.S. fabrication, alleging U.S. cyber espionage against multiple countries. They assert there’s strong evidence of U.S. false flag operations and misuse of technology to mislead investigations. The report calls for international collaboration on cybersecurity and counter-threat technology. **Meeting Takeaways:** 1. … Read more

Edge Devices: The New Frontier for Mass Exploitation Attacks

June 14, 2024 at 10:27AM The text discusses the increasing mass exploitation attacks targeting edge and infrastructure devices. It highlights the rise in criminal targeting, particularly through zero-day vulnerabilities, facilitated by the internet-facing nature of these devices. The research indicates a growing number of vulnerabilities in edge devices compared to non-edge devices, with high severity … Read more

Teetering on the Edge: VPNs, Firewalls’ Nonexistent Telemetry Lures APTs

April 23, 2024 at 08:09AM Mandiant Consulting’s incident response team linked a China-linked espionage group’s attack to a compromised edge device in a client’s network. The difficulty in detecting and investigating compromises of edge appliances has led to an increase in nation-state attackers targeting firewalls, email gateways, VPNs, and other devices. Attackers have also doubled … Read more

Magnet Goblin Hacker Group Leveraging 1-Day Exploits to Deploy Nerbian RAT

March 11, 2024 at 02:45AM Magnet Goblin, a financially motivated threat actor, rapidly exploits newly disclosed vulnerabilities to breach public-facing servers and edge devices. The group deploys malware, including a remote access trojan (RAT) called Nerbian and MiniNerbian, to execute arbitrary commands and steal credentials. Their campaigns are financially motivated and target areas previously left … Read more

China Caught Dropping RAT Designed for FortiGate Devices

February 8, 2024 at 09:08AM The Dutch Military Intelligence and Security Service (MIVD) uncovered a potent new malware strain called “Coathanger” being used by Chinese state-sponsored threat actors. It targets FortiGate devices and was deployed to spy on the Dutch Ministry of Defense in 2023. The report advises regular risk analysis and patching for edge … Read more