Chinese APT groups are targeting Linux servers

Research from Blackberry uncovers almost a decade of hacking from state-sponsored civilian contractors

Chinese-sponsored hackers have been targeting Linux servers in order to steal intellectual property, according to Blackberry researchers, and it's been happening for almost a decade.

A report from the Canadian company called 'Decade of the RATs' has revealed that five APT groups have been hacking into businesses via Linux servers, Windows systems and even Android mobiles.

The 'RATs' the report refers to is remote access trojans and the five groups have been using them to exploit the "always on, always available" nature of Linux servers by establishing a "beachhead" that can then be used for coordinated attacks.  

"As China forges its role as one of the great world powers, it continues to rely upon a blast furnace of cyber espionage operations in order to acquire foreign technologies and intellectual property, to better position itself against the global influence of competing international powers, and to control its own image both at home and abroad," the report states. 

According to the report, the five groups "acting in the interests of the Chinese government" have strategically targeted Linux servers because the OS is not a primary focus for enterprise security. It suggests that defensive coverage in this area is immature at best as endpoint protection products are either lack the capabilities to defend them or are "inadequately utilised".

Compromising Linux web servers in this way allows hackers to exfiltrate massive amounts of data that can be obscured within daily web traffic, according to the report. This both provides them with a chance to find valuable and sensitive data and also erases a layer of protection that corporate networks need. 

What's more, the groups are coordinating their attacks and are operating in a single domain, which the report suggests is rare. Although it doesn't name the groups specifically, it identifies them as civilian contractors and relations of the Winnti group. According to Kaspersky, the Winnti group has been active for several years but mostly focused on the online gaming industry. 

"This reflects a highly agile government/contractor ecosystem with few of the bureaucratic or legal hurdles that can be observed in Western nations with similar capabilities and provides a level of plausible deniability for the Chinese government," the report suggests. 

Featured Resources

Digital document processes in 2020: A spotlight on Western Europe

The shift from best practice to business necessity

Download now

Four security considerations for cloud migration

The good, the bad, and the ugly of cloud computing

Download now

VR leads the way in manufacturing

How VR is digitally transforming our world

Download now

Deeper than digital

Top-performing modern enterprises show why more perfect software is fundamental to success

Download now

Recommended

What is hacktivism?
hacking

What is hacktivism?

13 Oct 2020
Microsoft: Iranian hackers are exploiting ZeroLogon flaw
Security

Microsoft: Iranian hackers are exploiting ZeroLogon flaw

6 Oct 2020
The Ritz suffers data breach after hackers pose as staff
data breaches

The Ritz suffers data breach after hackers pose as staff

17 Aug 2020
Russia hacked Liam Fox's personal email to steal trade documents
phishing

Russia hacked Liam Fox's personal email to steal trade documents

4 Aug 2020

Most Popular

The top 12 password-cracking techniques used by hackers
Security

The top 12 password-cracking techniques used by hackers

5 Oct 2020
The enemy of security is complexity
Sponsored

The enemy of security is complexity

9 Oct 2020
What is a 502 bad gateway and how do you fix it?
web hosting

What is a 502 bad gateway and how do you fix it?

5 Oct 2020