Cybersecurity Firm Warns of New Cyber Espionage Tactic by Chinese Hackers

5Mind. The Meme Platform
The Epoch Times Header

Chinese state-backed hackers took advantage of outdated hardware and software to access routers and take over computer networks.

A Chinese hacker group is targeting routers made by a major U.S. manufacturer, taking advantage of outdated software and hardware to hijack routers and access computer networks, a cybersecurity firm warned Wednesday.

It’s a new tactic in an increasingly sophisticated cybercrime landscape, according to the firm.

Mandiant, a Google subsidiary known for outing Chinese hackers, reported in a blog post March 12 that the state-backed hacker group UNC3886 targeted routers made by Juniper Networks.

The Silicon Valley-based tech company is a main competitor to Cisco, the leader in the U.S. router market. While many Juniper products are manufactured in China and other parts of Southeast Asia, most of its higher-end products are assembled in North America.

In mid-2024, Mandiant found that attackers had deployed a program that accessed victims’ computers by disabling login mechanisms.

Once in the system, the program could carry out active backdoor functions, which directly interfered with the system, or passive backdoor functions—“eavesdropping” or gathering information.

Mandiant noted that the back doors were based on an open-source, low-maintenance program named TINYSHELL.

According to Mandiant, the vulnerability that enabled the intrusions was the use of routers running outdated or “end-of-life” hardware and software.

A New Tactic

Mandiant noted that in 2022 and 2023, it reported that hacker group UNC3886 had breached server software such as VMware ESXi, Linux vCenter servers, and Windows virtual machines.

Wednesday’s blog post described “a development in UNC3886’s tactics, techniques and procedures,” and a focus on devices that may lack security monitoring and detection solutions.

Compromising routing devices is a new espionage tactic, the report said, “as it grants the capability for a long-term, high-level access to the crucial routing infrastructure, with a potential for more disruptive actions in the future.”

Mandiant described UNC3886 as “highly adept.” The hacker group’s modus operandi is to acquire “legitimate credentials” and use them to operate undetected.

Historically, the group has targeted network devices and virtualization technologies with “zero-day exploits,” cyber attacks that take advantage of previously unknown vulnerabilities in software, hardware, or firmware before vendors have a chance to patch them.

By Dave Malyon

Read Full Article on TheEpochTimes.com

Contact Your Elected Officials
The Epoch Times
The Epoch Timeshttps://www.theepochtimes.com/
Tired of biased news? The Epoch Times is truthful, factual news that other media outlets don't report. No spin. No agenda. Just honest journalism like it used to be.
00:02:08

A Movie That’ll Keep You Awake: A Great Awakening

So how does someone (me) who thinks they’ve just seen the greatest movie ever (A Great Awakening), persuade you to watch it?

Ring That Bell

If I could travel back in time to 1776,...

Thoughts On America 250

Before you, American reader, is the honor, blessing, and privilege of celebrating the 250th anniversary of our nation. A nation toward which God has been merciful, shining His great grace.
00:09:03

Two birthdays apart

The Bicentennial was not just a commemoration of 200 years of independence – it was a coast‑to‑coast block party of red, white and blue.
00:02:31

Is Charlie Kirk’s Assassination Looking More Like a Conspiracy?

Enough videos have been posted to the internet, plenty...
00:00:38

US Signs Nuclear Cooperation Deal With Saudi Arabia

The US and Saudi Arabia signed an agreement that will allow the Gulf kingdom to develop a civilian nuclear program on its soil.

ChatGPT Maker Says Its AI Autonomously Hacked Another Company in ‘Unprecedented’ Cyber Incident

OpenAI says ChatGPT AI models autonomously breached another company's production systems in what it calls an unprecedented cyber incident.

Rep. Greg Stanton Defeats Democratic Socialist Challenger in Arizona

Kai Newkirk centered his campaign on Stanton’s vote against...
00:03:23

Treasury Intercepted $99 Million in Federal Payments to Deceased People, Bessent Says

U.S. Treasury Secretary Scott Bessent said anti-fraud screening blocked nearly $100 million in federal payments bound for deceased recipients.
00:59:35

Trump Admin Pausing $1 Billion in Medicaid Payments to 2 States

The federal government is pausing more than $1 billion in Medicaid payments to two states, Health Secretary Robert F. Kennedy Jr. said on July 21.

National Guard Deployment to DC Will Continue Until Trump’s Term Ends

Extension of the National Guard’s deployment to Washington will keep guardsmen in the nation’s capital until President Trump’s term ends.
00:00:49

Trump Orders Review Related to Climate Guidance for Federal Judges

President Trump has ordered federal officials to review conduct related to climate guidance included in a scientific reference manual for federal judges.

Newly Declassified Docs Describe China’s Election Influence Efforts, Concern That US Intel Downplayed Connections

President Donald Trump released newly declassified documents July 16 related to foreign influence in U.S. elections.
spot_img

Related Articles

Popular Categories

MAGA Business Central