Cybersecurity Firm Warns of New Cyber Espionage Tactic by Chinese Hackers

The Epoch Times Header

Chinese state-backed hackers took advantage of outdated hardware and software to access routers and take over computer networks.

A Chinese hacker group is targeting routers made by a major U.S. manufacturer, taking advantage of outdated software and hardware to hijack routers and access computer networks, a cybersecurity firm warned Wednesday.

Itโ€™s a new tactic in an increasingly sophisticated cybercrime landscape, according to the firm.

Mandiant, a Google subsidiary known for outing Chinese hackers, reported in a blog post March 12 that the state-backed hacker group UNC3886 targeted routers made by Juniper Networks.

The Silicon Valley-based tech company is a main competitor to Cisco, the leader in the U.S. router market. While many Juniper products are manufactured in China and other parts of Southeast Asia, most of its higher-end products are assembled in North America.

In mid-2024, Mandiant found that attackers had deployed a program that accessed victimsโ€™ computers by disabling login mechanisms.

Once in the system, the program could carry out active backdoor functions, which directly interfered with the system, or passive backdoor functionsโ€”โ€œeavesdroppingโ€ or gathering information.

Mandiant noted that the back doors were based on an open-source, low-maintenance program named TINYSHELL.

According to Mandiant, the vulnerability that enabled the intrusions was the use of routers running outdated or โ€œend-of-lifeโ€ hardware and software.

A New Tactic

Mandiant noted that in 2022 and 2023, it reported that hacker group UNC3886 had breached server software such as VMware ESXi, Linux vCenter servers, and Windows virtual machines.

Wednesdayโ€™s blog post described โ€œa development in UNC3886โ€™s tactics, techniques and procedures,โ€ and a focus on devices that may lack security monitoring and detection solutions.

Compromising routing devices is a new espionage tactic, the report said, โ€œas it grants the capability for a long-term, high-level access to the crucial routing infrastructure, with a potential for more disruptive actions in the future.โ€

Mandiant described UNC3886 as โ€œhighly adept.โ€ The hacker groupโ€™s modus operandi is to acquire โ€œlegitimate credentialsโ€ and use them to operate undetected.

Historically, the group has targeted network devices and virtualization technologies with โ€œzero-day exploits,โ€ cyber attacks that take advantage of previously unknown vulnerabilities in software, hardware, or firmware before vendors have a chance to patch them.

Byย Dave Malyon

Read Full Article on TheEpochTimes.com

The Epoch Times
The Epoch Timeshttps://www.theepochtimes.com/
Tired of biased news? The Epoch Times is truthful, factual news that other media outlets don't report. No spin. No agenda. Just honest journalism like it used to be.

Columns

How Legal Immigration Is Keeping Farms Afloat

The H-2A visa program is an example of how legal immigration can supply labor in America, but farmers say reform is needed.

Trumpโ€™s EO to Reduce Drug Prices Explained

Trump signed an Executive Order to bring the prices Americans pay for prescription drugs in line with those paid by other nations around the world.

Parents of Autistic Children Weigh In on RFK Jr.โ€™s Plan to Find the Cause

โ€˜The bottom line is we want the truth. We want safe products for our kids,โ€™ said an Ohio dad with an autistic child.

Fighting the Idiocracy

Despite our country's noble efforts to defend freedom and liberty across the globe we now find ourselves defending democracy against idiocracy.

Recent Sun Activity Could Trigger Major Earthquakes

A number of scientists around the world are sharing concerns about an imminent global seismic event.

News

Supreme Court Wrestles With Nationwide Injunctions in Birthright Citizenship Case

Supreme Court grappled with how far federal judges could go in issuing sweeping blocks on policies such as Trumpโ€™s order restricting birthright citizenship.

Lawsuit Alleges Musk, Election PAC Failed to Pay Swing State Petition Signers

Lawsuit filed against Musk and his PAC accuses them of failing to pay registered voters in swing states for signing petition supporting candidate Trump.

Trump Weighs In on Supreme Court Case Involving Birthright Citizenship

President Trump weighed in on the U.S. Supreme Court hearing arguments in a case involving his order to limit birthright citizenship.

Russian-Born Harvard Scientist Detained by US Charged With Smuggling

Russian-born scientist and research asso. at Harvard Univ has been arrested and charged with allegedly attempting to smuggle clawed frog embryos into the U.S.

DOJ Charges High-Ranking Sinaloa Cartel Suspects With โ€˜Narco-Terrorismโ€™

Feds charged alleged leaders of Sinaloa cartelโ€™s Beltran Leyva Organization with narco-terrorism, terrorism support, and international drug trafficking.

Judge Orders HHS to Restore Jobs in Health Monitoring Program for West Virginia Coal Miners

West Virginia federal judge ordered HHS to reverse terminations of nearly 200 workers who oversee a health monitoring program for coal miners

Trump Admin Urges Supreme Court to Permit DOGE Access to Social Security Records

The DOJ urged the Supreme Court on May 13 to let the DOGE have access to Social Security data after lower courts blocked that access.

Deported Mother Who Took 2-Year-Old US Citizen Child With Her Drops Lawsuit Against Trump Admin

Lawsuit against Trump admin alleging it deported an illegal immigrant and her 2-year-old U.S. citizen child to Honduras without due process is being dropped.
spot_img

Related Articles