Cyber Hacking News

Chinese hackers breach Middle East Telecom providers

0

Telecommunication providers in the Middle East are the subject of new cyber-attacks that commenced in the first quarter of 2023.

The intrusion set which has been attributed to a Chinese cyber espionage actor is associated with a long-running campaign dubbed Operation Soft Cell based on tooling overlaps.

According to researchers from SentinelOne and QGroup, the initial attack phase involves infiltrating Internet-facing Microsoft Exchange servers to deploy web shells used for command execution.

Once a foothold is established, the attackers conduct a variety of reconnaissance, credential theft, lateral movement, and data exfiltration activities.

According to Cybereason, Operation Soft Cell, refers to malicious activities undertaken by China-affiliated actors targeting telecommunications providers since at least 2012.

The Soft Cell threat actor, also tracked by Microsoft as Gallium, is known to target unpatched internet-facing services and use tools like Mimikatz to obtain credentials that allows for lateral movement across the targeted networks.

They also use a “difficult-to-detect” backdoor codenamed PingPull in its espionage attacks directed against companies operating in Southeast Asia, Europe, Africa, and the Middle East.

The latest campaign is the deployment of a custom variant of Mimikatz referred to as mim221, which has new anti-detection features.

The use of special-purpose modules indicates the continuous maintenance and further development of the Chinese espionage malware arsenal.

The attacks ultimately proved to be unsuccessful, as the breaches were detected and blocked before any implants could be deployed on the target networks.

Chinese cyber espionage threat actors are known to have a strategic interest in the Middle East. These threat actors will almost certainly continue exploring and upgrading their tools with new techniques for evading detection, including integrating and modifying publicly available code.

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

Hackers steal more than $1.5M in crypto from General Bytes ATMs

Previous article

North Dakota is first state to approve required cybersecurity education

Next article

You may also like

Comments

Leave a reply

Your email address will not be published. Required fields are marked *