FBI warns of China-linked hackers exploiting vulnerabilities to access stolen emails from multiple sectors

Published:

On October 8, the FBI, alongside agencies from six other countries, issued a warning regarding a group of hackers linked to a Chinese cybersecurity firm, Integrity Technology Group. This group has reportedly exploited vulnerabilities to access and steal emails from various sectors, including government organizations, law enforcement, healthcare systems, and religious institutions across Southeast Asia. The advisory highlights that these hackers have been active since at least January 2021, although specific details about the number of organizations affected remain undisclosed.

Integrity Technology Group has faced sanctions from both the U.S. and the UK due to its alleged involvement in cyber intrusions targeting U.S. entities. The hackers employed a range of tools, including a custom-built application that purportedly provides third-party access to the stolen email content, although the identities of these third parties have not been revealed.

Methods of Intrusion

The advisory outlines the techniques used by the hackers to infiltrate networks. They utilize open-source scanning tools such as Nmap and WPScan to identify vulnerabilities in web applications and networks. Their scanning efforts focus on common ports, including 21, 22, 53, 80, 443, and 1080. Additionally, they have been known to use a Python-based scanner called MicroScan, which contains over 1,300 scripts designed for penetration testing.

Among the vulnerabilities exploited by the hackers are several known flaws, including CVE-2014-6278 and CVE-2016-3081, which have been cataloged by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) as part of their Known Exploited Vulnerabilities (KEV) list. The advisory emphasizes that the hackers have also employed password spraying techniques, utilizing tools like EBurst to target Microsoft 365 and Exchange accounts.

Data Exfiltration Techniques

Once inside a network, the hackers deploy various methods to maintain access and exfiltrate data. They reportedly install SoftEther, a legitimate VPN software, disguised as a Windows file to evade detection. To harvest credentials, they utilize a tool named DC.exe, which employs the DCSync technique to extract data from domain controllers.

For email collection, the hackers have developed a bot that interfaces with Exchange Web Services (EWS) to gather emails, calendars, and contacts. This bot compresses and encrypts the collected data before uploading it to a remote server. Additionally, they have been observed manually downloading databases and email data from compromised accounts.

Defensive Recommendations

In light of these findings, the advisory provides several recommendations for organizations to bolster their defenses against such intrusions. Key measures include:

  • Disabling unused services and ports to minimize attack surfaces.
  • Implementing multifactor authentication (MFA) for critical accounts and services.
  • Regularly reviewing web application logs for signs of attack attempts.
  • Applying patches for known vulnerabilities, particularly those listed in the advisory.
  • Monitoring for unexpected Active Directory replication, which may indicate DCSync activity.

Organizations are urged to remain vigilant and proactive in their cybersecurity measures, especially given the sophisticated methods employed by these threat actors. The advisory also includes a comprehensive list of indicators of compromise (IOCs) associated with the hackers, which can aid in identifying potential breaches.

For further details on the advisory and the specific vulnerabilities exploited, refer to the report from The Hacker News.

CHAPTER X // CYBER AWARENESS CAMPAIGN
BEYOND THE BALLROOM
[C://ME] // CHAPTER X

REQUEST THE MEDIA KIT

Tell us where to send the Beyond the Ballroom media deck. Every field is required.

We will use these details to respond to your media-kit request. Privacy Policy

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

Microsoft emphasizes the need for organizations to test certificate ecosystems for post-quantum authentication readiness

As organizations prepare for the impending era of quantum computing, Microsoft emphasizes the critical need for testing certificate ecosystems to ensure readiness for post-quantum...

Workday expands UAE operations to enhance enterprise AI transformation efforts

Workday has officially launched its operations in the UAE, establishing a new office in Dubai to support the growing demand for enterprise AI transformation....

Red Hat OpenShift Container Platform 4.14.75 includes important security updates

Red Hat has released OpenShift Container Platform version 4.14.75, which includes critical security updates aimed at addressing vulnerabilities. This update has been classified as...

Let’s Encrypt to reduce SSL/TLS certificate lifetimes to 64 days starting February 2027

Let’s Encrypt has announced a significant change to its SSL/TLS certificate policy, reducing the lifetime of its free certificates from 90 days to 64...