• Home
  • Science
  • Technology
  • Futurism
  • Weather Extreme

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Raytheon Ineligible For Reduced NY Tax Rate, ALJ Rules

March 24, 2023

The Sun, In All Its Glory

March 24, 2023

Crews fighting wildfire in the Shenandoah National Park

March 23, 2023
Facebook Twitter Instagram
Facebook Twitter Instagram YouTube
Futurist JournalFuturist Journal
Demo
  • Home
  • Science
  • Technology
  • Futurism
  • Weather Extreme
Futurist JournalFuturist Journal
Home » Chinese espionage group targets Israel while suggesting the source could be Iran • The Register
Futurism

Chinese espionage group targets Israel while suggesting the source could be Iran • The Register

NewsBy NewsAugust 11, 2021Updated:August 11, 2021No Comments3 Mins Read0 Views
Facebook Twitter Pinterest LinkedIn Telegram Tumblr Email
Share
Facebook Twitter LinkedIn Pinterest Email

Security vendor FireEye says it has spotted a Chinese espionage group that successfully compromised targets within Israel, and that trying to make its efforts look like the work of Iranian actors is part of the group’s modus operandi.

A FireEye blog post states the Chinese activity has been ongoing since 2019, when a group it names “UNC215” used the Microsoft SharePoint vulnerability CVE-2019-0604 “to install web shells and FOCUSFJORD payloads at targets in the Middle East and Central Asia”.

“In addition to data from Mandiant Incident Response and FireEye telemetry, we worked with Israeli defense agencies to review data from additional compromises of Israeli entities,” the post states. “This analysis showed multiple, concurrent operations against Israeli government institutions, IT providers and telecommunications entities beginning in January 2019.”

UNC215 changed tactics, techniques, and procedures (TTPs) through its ongoing campaign, but is consistently fond of installing web shells and attacking Exchange and Outlook Web Access, and has been observed stealing credentials to go about its unpleasant work.

“After identifying key systems within the target network, such as domain controllers and Exchange servers, UNC215 moved laterally and deployed their signature malware FOCUSFJORD,” wrote FireEye’s security team. “UNC215 often uses FOCUSFJORD for the initial stages of an intrusion, and then later deploys HYPERBRO, which has more information collection capabilities such as screen capture and keylogging.”

The group also tries to cover its tracks by erasing its malware, but can also be brazen and re-use code or revisit victims.

On one occasion FireEye observed “an operator repeatedly and infrequently revisited a compromised network whenever an Endpoint Detection and Response tool detected or quarantined tools like HYPERBRO and Mimikatz. After several months of repeated detections, UNC215 deployed an updated version of HYPERBRO, and a tool called ‘anti.exe’ to stop Windows Update service and terminate EDR and Antivirus related services.”

UNC215 also lays a false breadcrumb trail to Iran, using its official Farsi language in some strings. Some file paths include directories named /Iran.

FireEye has no hesitation attributing the group’s activities to “China’s consistent strategic interest in the Middle East.

“This cyber espionage activity is happening against the backdrop of China’s multi-billion-dollar investments related to the Belt and Road Initiative (BRI) and its interest in Israel’s robust technology sector,” the post states.

“China has conducted numerous intrusion campaigns along the BRI route to monitor potential obstructions – political, economic, and security – and we anticipate that UNC215 will continue targeting governments and organizations involved in these critical infrastructure projects in Israel and the broader Middle East in the near- and mid-term.”

All of which leaves one of the the world’s flashiest flashpoints dealing with ongoing Chinese offensive cyber ops on top of its myriad other geopolitical complexities.

What a time to be alive. ®

Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
News
  • Website

Related Posts

Raytheon Ineligible For Reduced NY Tax Rate, ALJ Rules

March 24, 2023

Microsoft Copilot could fix a long-running Office problem

March 23, 2023

A Brief Overview Of Vaccine Purification Technologies And Analytical Tools

March 23, 2023

Wave of the future: Goodwill clinic uses new tech to address brain injuries

March 23, 2023

Commercial quantum networks inch closer to primetime

March 23, 2023

New AI tools make it easy to create fake video, audio and text : NPR

March 23, 2023

Leave A Reply Cancel Reply

You must be logged in to post a comment.

Recent Posts
  • Raytheon Ineligible For Reduced NY Tax Rate, ALJ Rules
  • The Sun, In All Its Glory
  • Crews fighting wildfire in the Shenandoah National Park
  • The new Amazfit T-Rex Ultra is the ultimate rugged smartwatch
  • Microsoft Copilot could fix a long-running Office problem
Recent Comments
    Demo
    Top Posts

    How Emerging Technology is Helping Teams Save on Development Costs

    March 22, 20232 Views

    At Mavericks beach, climate change is reshaping big-wave surfing

    March 22, 20231 Views

    Sims sparks Ga. Tech to 45-22 upset of No. 21 North Carolina

    September 26, 20211 Views
    Don't Miss

    Raytheon Ineligible For Reduced NY Tax Rate, ALJ Rules

    March 24, 2023

    By Maria Koklanaris · March 23, 2023, 3:44 PM EDT A Raytheon Co. combined group…

    The Sun, In All Its Glory

    March 24, 2023

    Crews fighting wildfire in the Shenandoah National Park

    March 23, 2023

    The new Amazfit T-Rex Ultra is the ultimate rugged smartwatch

    March 23, 2023
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    Demo
    Most Popular

    How Emerging Technology is Helping Teams Save on Development Costs

    March 22, 20232 Views

    At Mavericks beach, climate change is reshaping big-wave surfing

    March 22, 20231 Views

    Sims sparks Ga. Tech to 45-22 upset of No. 21 North Carolina

    September 26, 20211 Views
    Our Picks

    Raytheon Ineligible For Reduced NY Tax Rate, ALJ Rules

    March 24, 2023

    The Sun, In All Its Glory

    March 24, 2023

    Crews fighting wildfire in the Shenandoah National Park

    March 23, 2023

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Futurist Journal
    Facebook Twitter Instagram Pinterest YouTube Dribbble
    • Contact Us
    • Privacy Policy
    © 2023 futuristjournal.com - All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.