Cybersecurity Firm Warns of New Cyber Espionage Tactic by Chinese Hackers

The Epoch Times Header

Chinese state-backed hackers took advantage of outdated hardware and software to access routers and take over computer networks.

A Chinese hacker group is targeting routers made by a major U.S. manufacturer, taking advantage of outdated software and hardware to hijack routers and access computer networks, a cybersecurity firm warned Wednesday.

It’s a new tactic in an increasingly sophisticated cybercrime landscape, according to the firm.

Mandiant, a Google subsidiary known for outing Chinese hackers, reported in a blog post March 12 that the state-backed hacker group UNC3886 targeted routers made by Juniper Networks.

The Silicon Valley-based tech company is a main competitor to Cisco, the leader in the U.S. router market. While many Juniper products are manufactured in China and other parts of Southeast Asia, most of its higher-end products are assembled in North America.

In mid-2024, Mandiant found that attackers had deployed a program that accessed victims’ computers by disabling login mechanisms.

Once in the system, the program could carry out active backdoor functions, which directly interfered with the system, or passive backdoor functions—“eavesdropping” or gathering information.

Mandiant noted that the back doors were based on an open-source, low-maintenance program named TINYSHELL.

According to Mandiant, the vulnerability that enabled the intrusions was the use of routers running outdated or “end-of-life” hardware and software.

A New Tactic

Mandiant noted that in 2022 and 2023, it reported that hacker group UNC3886 had breached server software such as VMware ESXi, Linux vCenter servers, and Windows virtual machines.

Wednesday’s blog post described “a development in UNC3886’s tactics, techniques and procedures,” and a focus on devices that may lack security monitoring and detection solutions.

Compromising routing devices is a new espionage tactic, the report said, “as it grants the capability for a long-term, high-level access to the crucial routing infrastructure, with a potential for more disruptive actions in the future.”

Mandiant described UNC3886 as “highly adept.” The hacker group’s modus operandi is to acquire “legitimate credentials” and use them to operate undetected.

Historically, the group has targeted network devices and virtualization technologies with “zero-day exploits,” cyber attacks that take advantage of previously unknown vulnerabilities in software, hardware, or firmware before vendors have a chance to patch them.

By Dave Malyon

Read Full Article on TheEpochTimes.com

The Epoch Times
The Epoch Timeshttps://www.theepochtimes.com/
Tired of biased news? The Epoch Times is truthful, factual news that other media outlets don't report. No spin. No agenda. Just honest journalism like it used to be.

Columns

Alleged Nazis (Likely Feds) Stage Tiny Protest, Armed Black Militias Now Patrol

All it takes for the corporate media to incite a race war is a less than a dozen (probably fed) Nazis to show up and wave a few Swastikas around.

Canada’s Threat of Loss of Pornhub – Hilarious Timing!

There are some things in life that are just...

Biden’s Autopen Was A Mighty Big Sword

The autopen was used to sign Biden's name on pardons and EO, even when he was out of the country. Did he know what was signed? Did he authorize the signatures?

I Refuse To Be A Serf

“How are people not furious about property taxes?” President Trump...

Putting it to rest

As the nation hits its taxation stride on its way to April 15th and DOGE continues to reveal waste and fraud, a review of the nation’s finances is overdue.

News

DOJ Announces Joint October 7 Task Force Targeting Hamas Terrorists, Affiliates for US Prosecution

The Department of Justice on March 17 announced the creation of Joint Task Force October 7 to combat anti-Semitism and terrorism.

Judge Orders More Info From Trump Admin on Deportations

Judge James Boasberg ordered Trump’s admin to provide info on its implementation of deportations of Venezuelan gang members using the Alien Enemies Act.

Doctors, Detransitioners Allege Medical Malpractice in Treating Gender Dysphoria

Surgeon says physicians can't handle shock after realizing prescribing drugs or performing surgeries for youth with gender dysphoria cause harm.

Democrats Wrestle With DOGE and Musk

Few issues unit Democrats like opposition to Musk and DOGE, a time-limited organization directed to maximize government efficiency and productivity.

Former Trump Prosecutor Fani Willis Ordered to Pay for Violating Open Records Laws

Fulton County DA Fani Willis has been ordered by Georgia judge to pay $54,000 for violating open records laws in relation to her prosecution against Trump.

Why the Egg Industry Is Pushing for a Bird Flu Vaccine

Vaccinating for bird flu is complex because vaccination would cut off more than half of US' poultry exports due to trade provisions forbidding vaccination.

White House Says Deportation Flights Didn’t Defy Judge’s Order

“A single judge in a single city cannot direct the movements of an aircraft ... full of foreign alien terrorists who were physically expelled from U.S. soil.”

Pentagon Taps 2 Firms That Partner With Ukraine to Make Drone Prototypes

Two Ukrainian companies will help manufacture prototype drones for the Pentagon, as the United States seeks to rapidly scale its unmanned capabilities.
spot_img

Related Articles

Popular Categories

MAGA Business Central