Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Chinese Hackers Hit Citrix, Cisco Vulnerabilities In Sweeping Campaign
Cyberscoop ^ | 03/25/20 | Shannon Vavra

Posted on 03/25/2020 1:06:56 PM PDT by Enlightened1

Earlier this year, state-backed Chinese hackers embarked on one of the most sweeping Chinese espionage campaigns FireEye has seen in years, according to new research the security firm published Wednesday.

The campaign, which lasted between January 20 and March 11, targeted 75 organizations ranging in nearly every economic sector: telecommunications, healthcare, government, defense, finance, petrochemical, manufacturing, and transportation. The campaign, believed to be run by APT41, targeted nonprofit, legal, real estate, travel, education, and media organizations as well.

“This activity is one of the most widespread campaigns we have seen from China-nexus espionage actors in recent years,” researchers Christopher Glyer, Dan Perez, Sarah Jones, and Steve Miller said. “While APT41 has previously conducted activity with an extensive initial entry … this scanning and exploitation has focused on a subset of our customers, and seems to reveal a high operational tempo and wide collection requirements for APT41.”

APT41 zeroed in on victims by going after vulnerabilities in Citrix’s Application Delivery Controller (ADC), Cisco’s routers, and Zoho’s ManageEngine Desktop Central, according to FireEye.

The Citrix vulnerability was publicly revealed a month prior to APT41’s campaign, and a researcher only revealed code for a zero-day remote code execution vulnerability in ZohoManageEngine Desktop Central three days before the group took advantage, suggesting the group is interested in promptly taking advantages of reported flaws.

“This new activity from this group shows how resourceful and how quickly this group can leverage newly disclosed vulnerabilities to their advantage,” the researchers said.

FireEye does not have a copy of the malware deployed against the Cisco routers, but has reason to believe APT41 designed malware in-house to make its targeting a success, Glyer told CyberScoop.

“It is likely that APT41 had to develop custom malware to target Cisco routers because

(Excerpt) Read more at cyberscoop.com ...


TOPICS: Business/Economy; Chit/Chat; Computers/Internet; Miscellaneous
KEYWORDS: china; cisco; citrix; hackers
Navigation: use the links below to view more comments.
first 1-2021-32 next last

1 posted on 03/25/2020 1:06:56 PM PDT by Enlightened1
[ Post Reply | Private Reply | View Replies]

To: Enlightened1

Attacking during a pandemic...


2 posted on 03/25/2020 1:08:28 PM PDT by Enlightened1
[ Post Reply | Private Reply | To 1 | View Replies]

To: Enlightened1

Just shut them off


3 posted on 03/25/2020 1:09:49 PM PDT by AndyJackson
[ Post Reply | Private Reply | To 2 | View Replies]

To: Enlightened1

The ChiComs are really our friends. Just ask Joe and Hunter Biden.


4 posted on 03/25/2020 1:11:12 PM PDT by ConservativeInPA (It's official! I'm nominated for the 2020 Mr. Hyperbole and Sarcasm Award.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Enlightened1

Communists and Democrats, redundant — I know, never let a crisis go to waste.


5 posted on 03/25/2020 1:11:31 PM PDT by Rurudyne (Standup Philosopher)
[ Post Reply | Private Reply | To 2 | View Replies]

To: ConservativeInPA

Or the Clintons since the days of Charlie Trie.


6 posted on 03/25/2020 1:12:02 PM PDT by Rurudyne (Standup Philosopher)
[ Post Reply | Private Reply | To 4 | View Replies]

To: Enlightened1

I fear hey are working up to war.
Worst case?
Taiwan or a surprise takeout of a carrier group with surprise weapons?

If either, start by cutting off ALL food.
If that doesn’t work,

Then rods from god on Three Gorges Dam.

If that doesn’t work,
Then time for Russian collusion (”Hey, Vlad, this is Donald. Wanna nuke China with me?”)


7 posted on 03/25/2020 1:12:10 PM PDT by grey_whiskers (The opinions are solely those of the author and are subject to change with out notice.)
[ Post Reply | Private Reply | To 2 | View Replies]

To: ConservativeInPA

and Bloomberg.


8 posted on 03/25/2020 1:12:35 PM PDT by trublu
[ Post Reply | Private Reply | To 4 | View Replies]

To: Rurudyne

Ok, all Rats in general. We can hang that in them


9 posted on 03/25/2020 1:13:07 PM PDT by ConservativeInPA (It's official! I'm nominated for the 2020 Mr. Hyperbole and Sarcasm Award.)
[ Post Reply | Private Reply | To 6 | View Replies]

To: Enlightened1

If Earth is our home, the Chinese are its termites, cockroaches and bedbugs — all in one.


10 posted on 03/25/2020 1:13:51 PM PDT by Blurb2350
[ Post Reply | Private Reply | To 1 | View Replies]

To: ConservativeInPA

They’ve never been upset for a moment abut ChiCom interference in our elections. Nor the Soviets before them. Indeed, I look at their willingness to be upset over Russians to be an evidence that the Russians aren’t really communists anymore.


11 posted on 03/25/2020 1:15:11 PM PDT by Rurudyne (Standup Philosopher)
[ Post Reply | Private Reply | To 9 | View Replies]

To: Enlightened1

It is war. “Chinese hackers” are state actors. Inexplicably we don’t seem to have moved to bring critical medical and other supply manufacturing home, so that we don’t have to keep pretending otherwise.


12 posted on 03/25/2020 1:15:57 PM PDT by 9YearLurker
[ Post Reply | Private Reply | To 2 | View Replies]

To: Rurudyne

Quite true


13 posted on 03/25/2020 1:15:59 PM PDT by ConservativeInPA (It's official! I'm nominated for the 2020 Mr. Hyperbole and Sarcasm Award.)
[ Post Reply | Private Reply | To 11 | View Replies]

To: Blurb2350

No, the socialists.

In this instance the ChiComs. Non communist Chinese are great.


14 posted on 03/25/2020 1:16:13 PM PDT by Rurudyne (Standup Philosopher)
[ Post Reply | Private Reply | To 10 | View Replies]

To: Enlightened1

Cisco devices have some capabilities built in that allow for branching traffic unbeknownst to other recipients that allow for spying to occur on traffic

Been there for years and well known in the Tech industry


15 posted on 03/25/2020 1:20:53 PM PDT by 100American (Knowledge is knowing how, Wisdom is knowing when)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Enlightened1

I have nearly 20 years of Cisco Router configuration experience for some of the largest most well known financial institutions in the USA, the last company I was contracted with was a major energy company with a worldwide network of Cisco routers and switches.....

The one Cisco Router mentioned in the article was a RV320, which I had no knowledge of until I looked it up, the prices for one of these is usually under $300 which means it’s little more than a linksys router you could by a CompUsa or Office Depot store in the past...BTW, Cisco owns Linksys

I’m not trying to downplay this but I suspect the Chinese Group was targeting small companies and organizations who do not have the sophistication or money to harden or lock down these network devices...


16 posted on 03/25/2020 1:29:05 PM PDT by srmanuel
[ Post Reply | Private Reply | To 1 | View Replies]

To: AdmSmith; AnonymousConservative; Arthur Wildfire! March; Berosus; Bockscar; cardinal4; ColdOne; ...
Now look, just because this hacking cadre is based in China and made up entirely of Chinese hackers, doesn't mean calling it a Chinese hacking attack isn't racist. /sarc

17 posted on 03/25/2020 1:33:29 PM PDT by SunkenCiv (Imagine an imaginary menagerie manager imagining managing an imaginary menagerie.)
[ Post Reply | Private Reply | View Replies]

To: Enlightened1

Multi pronged attack plan. May have started last Nov (me) but triggered fully with trade sanctions. They won’t be able to cover this up too long.


18 posted on 03/25/2020 1:34:20 PM PDT by epluribus_2 (He, had the best mom - ever. my)
[ Post Reply | Private Reply | To 2 | View Replies]

To: Enlightened1
targeted 75 organizations ranging in nearly every ...[sector]..."

Including political discussion? Maybe the source of the DOS attacks on FR a few weeks ago.

19 posted on 03/25/2020 1:36:23 PM PDT by C210N
[ Post Reply | Private Reply | To 1 | View Replies]

To: Enlightened1

And as usual we do nothing to retaliate, which only invites even more attacks.


20 posted on 03/25/2020 1:39:59 PM PDT by Starboard
[ Post Reply | Private Reply | To 1 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-32 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson