Cybersecurity Firm Warns of New Cyber Espionage Tactic by Chinese Hackers

The Epoch Times Header

Chinese state-backed hackers took advantage of outdated hardware and software to access routers and take over computer networks.

A Chinese hacker group is targeting routers made by a major U.S. manufacturer, taking advantage of outdated software and hardware to hijack routers and access computer networks, a cybersecurity firm warned Wednesday.

It’s a new tactic in an increasingly sophisticated cybercrime landscape, according to the firm.

Mandiant, a Google subsidiary known for outing Chinese hackers, reported in a blog post March 12 that the state-backed hacker group UNC3886 targeted routers made by Juniper Networks.

The Silicon Valley-based tech company is a main competitor to Cisco, the leader in the U.S. router market. While many Juniper products are manufactured in China and other parts of Southeast Asia, most of its higher-end products are assembled in North America.

In mid-2024, Mandiant found that attackers had deployed a program that accessed victims’ computers by disabling login mechanisms.

Once in the system, the program could carry out active backdoor functions, which directly interfered with the system, or passive backdoor functions—“eavesdropping” or gathering information.

Mandiant noted that the back doors were based on an open-source, low-maintenance program named TINYSHELL.

According to Mandiant, the vulnerability that enabled the intrusions was the use of routers running outdated or “end-of-life” hardware and software.

A New Tactic

Mandiant noted that in 2022 and 2023, it reported that hacker group UNC3886 had breached server software such as VMware ESXi, Linux vCenter servers, and Windows virtual machines.

Wednesday’s blog post described “a development in UNC3886’s tactics, techniques and procedures,” and a focus on devices that may lack security monitoring and detection solutions.

Compromising routing devices is a new espionage tactic, the report said, “as it grants the capability for a long-term, high-level access to the crucial routing infrastructure, with a potential for more disruptive actions in the future.”

Mandiant described UNC3886 as “highly adept.” The hacker group’s modus operandi is to acquire “legitimate credentials” and use them to operate undetected.

Historically, the group has targeted network devices and virtualization technologies with “zero-day exploits,” cyber attacks that take advantage of previously unknown vulnerabilities in software, hardware, or firmware before vendors have a chance to patch them.

By Dave Malyon

Read Full Article on TheEpochTimes.com

The Epoch Times
The Epoch Timeshttps://www.theepochtimes.com/
Tired of biased news? The Epoch Times is truthful, factual news that other media outlets don't report. No spin. No agenda. Just honest journalism like it used to be.

Columns

 The Trump Curse is Real 2.0

The Trump curse (karma or cause and effect) holds that those who wrongfully attack Donald J. Trump will have it come back to bite them in the end.

Donald Trump, The People’s President

Trump has a special bond with the American people. Unlike many elected officials, President Trump prefers to be with everyday Americans, not elitists.

30 Bills in 37 Years: Guardianship Reforms Stall Despite Decades of Fraud

Reports of fraud and abuse by court-appointed guardians inspired over 30 bills to be introduced in Congress over past 37 years. Most never made it out of committee.

USAID’s Epic Failed Venture in Vietnam

USAID launched a project against environmental pollution worth US$11.3 million for Vietnam and the venture produced zero tangible results.

 NGO “Feeding Our Future” Fraud Case Prosecuted

A court case being prosecuted in Minnesota is being kept quiet by mainstream media because it involved organized criminality with an NGO.

News

Federal Judge Blocks Deportation of 2 Venezuelans Accused of Tren de Aragua Gang Ties

Judge in CO has temporarily blocked deportation of two Venezuelan nationals accused of gang ties, issuing emergency order to preserve court’s jurisdiction.

FDA Grants Fast-Track Designation for Possible mRNA Bird Flu Vaccine, Company Says

FDA moved to fast-track mRNA vaccine candidate for a type of bird flu, that sickened more than 70 Americans this year, according to developer of vaccine.

Harvard Rejects Trump Administration’s Demands Tied to $9 Billion Federal Funding

Harvard Univ will not comply with Trump admin’s demands to dismantle DEI programs or limit student protests for continued access to federal research funding.

US Strips Benefits From Thousands of Criminal Aliens, Those on Terror Watchlist

Trump admin ended temporary immigration parole and revoked federal benefits for thousands of foreign nationals flagged as national security risks.

Arson Suspect Admitted Hatred Against Pennsylvania Governor, Officials Say

Man accused of carrying out an arson attack on PA Gov. Josh Shapiro’s mansion in Harrisburg admitted “harboring hatred” against governor.

Bill Maher Describes White House Dinner With President Trump

Bill Maher shared details of a recent private dinner with President Trump, offering a different view of the president than what Maher voices on his show.

Nvidia to Manufacture AI Supercomputers in US

Nvidia Corp. is beginning to produce chips in the United States and will soon build multiple “supercomputer manufacturing plants.”

Blue Origin Sends All-Women Crew Into Space

Nguyen became the first Vietnamese American woman, and the...
spot_img

Related Articles

Popular Categories

MAGA Business Central