Chinese APT groups are targeting Linux servers
Research from Blackberry uncovers almost a decade of hacking from state-sponsored civilian contractors
Chinese-sponsored hackers have been targeting Linux servers in order to steal intellectual property, according to Blackberry researchers, and it's been happening for almost a decade.
The 'RATs' the report refers to is remote access trojans and the five groups have been using them to exploit the "always on, always available" nature of Linux servers by establishing a "beachhead" that can then be used for coordinated attacks.
"As China forges its role as one of the great world powers, it continues to rely upon a blast furnace of cyber espionage operations in order to acquire foreign technologies and intellectual property, to better position itself against the global influence of competing international powers, and to control its own image both at home and abroad," the report states.
According to the report, the five groups "acting in the interests of the Chinese government" have strategically targeted Linux servers because the OS is not a primary focus for enterprise security. It suggests that defensive coverage in this area is immature at best as endpoint protection products are either lack the capabilities to defend them or are "inadequately utilised".
Compromising Linux web servers in this way allows hackers to exfiltrate massive amounts of data that can be obscured within daily web traffic, according to the report. This both provides them with a chance to find valuable and sensitive data and also erases a layer of protection that corporate networks need.
What's more, the groups are coordinating their attacks and are operating in a single domain, which the report suggests is rare. Although it doesn't name the groups specifically, it identifies them as civilian contractors and relations of the Winnti group. According to Kaspersky, the Winnti group has been active for several years but mostly focused on the online gaming industry.
"This reflects a highly agile government/contractor ecosystem with few of the bureaucratic or legal hurdles that can be observed in Western nations with similar capabilities and provides a level of plausible deniability for the Chinese government," the report suggests.
The case for a marketing content hub
Transform your digital marketing to deliver customer expectationsDownload now
Fast, flexible and compliant e-signatures for global businesses
Be at the forefront of digital transformation with electronic signaturesDownload now
Why CEOS should care about the move to SAP S/4HANA
And how they can accelerate business valueDownload now
IT faces new security challenges in the wake of COVID-19
Beat the crisis by learning how to secure your networkDownload now