Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data

Summary

Chinese government-linked cyber threat actors are employing a combination of automated scanning tools, botnets, and hands-on exploitation to steal sensitive data from global organizations, including US critical infrastructure. The advisory details their methods, which include exploiting vulnerabilities via cross-site scripting and password spraying on Microsoft Exchange servers, and establishing persistence through VPN software. Recommended mitigations include disabling unused services, sanitizing web inputs, implementing multifactor authentication, and timely patching.

IFF Assessment

FOE

This advisory details sophisticated tactics and tools used by state-sponsored threat actors to steal sensitive data, posing a significant risk to organizations.

Severity

10.0 Critical

CISA KEV: Listed as actively exploited. Federal patch due: November 17, 2021. Known ransomware use: Known.

Defender Context

This article highlights the evolving tactics of state-sponsored threat actors, emphasizing the need for robust defense-in-depth strategies. Defenders should be particularly vigilant about detecting and preventing unauthorized scanning, credential stuffing, and the exploitation of common web vulnerabilities. Proactive patching and securing VPN access are critical to mitigating the risks described.

Read Full Story →