Chinese APT groups are targeting Linux servers

Research from Blackberry uncovers almost a decade of hacking from state-sponsored civilian contractors

Chinese-sponsored hackers have been targeting Linux servers in order to steal intellectual property, according to Blackberry researchers, and it's been happening for almost a decade.

A report from the Canadian company called 'Decade of the RATs' has revealed that five APT groups have been hacking into businesses via Linux servers, Windows systems and even Android mobiles.

The 'RATs' the report refers to is remote access trojans and the five groups have been using them to exploit the "always on, always available" nature of Linux servers by establishing a "beachhead" that can then be used for coordinated attacks.  

"As China forges its role as one of the great world powers, it continues to rely upon a blast furnace of cyber espionage operations in order to acquire foreign technologies and intellectual property, to better position itself against the global influence of competing international powers, and to control its own image both at home and abroad," the report states. 

According to the report, the five groups "acting in the interests of the Chinese government" have strategically targeted Linux servers because the OS is not a primary focus for enterprise security. It suggests that defensive coverage in this area is immature at best as endpoint protection products are either lack the capabilities to defend them or are "inadequately utilised".

Compromising Linux web servers in this way allows hackers to exfiltrate massive amounts of data that can be obscured within daily web traffic, according to the report. This both provides them with a chance to find valuable and sensitive data and also erases a layer of protection that corporate networks need. 

What's more, the groups are coordinating their attacks and are operating in a single domain, which the report suggests is rare. Although it doesn't name the groups specifically, it identifies them as civilian contractors and relations of the Winnti group. According to Kaspersky, the Winnti group has been active for several years but mostly focused on the online gaming industry. 

"This reflects a highly agile government/contractor ecosystem with few of the bureaucratic or legal hurdles that can be observed in Western nations with similar capabilities and provides a level of plausible deniability for the Chinese government," the report suggests. 

Featured Resources

Unleashing the power of AI initiatives with the right infrastructure

What key infrastructure requirements are needed to implement AI effectively?

Download now

Achieve today. Plan tomorrow. Making the hybrid multi-cloud journey

A Veritas webinar on implementing a hybrid multi-cloud strategy

Download now

A buyer’s guide for cloud-based phone solutions

Finding the right phone system for your modern business

Download now

The workers' experience report

How technology can spark motivation, enhance productivity and strengthen security

Download now

Recommended

Global ransom DDoS extortionists are retargeting companies
distributed denial of service (DDOS)

Global ransom DDoS extortionists are retargeting companies

22 Jan 2021
BEC scammers are using Google Forms to identify easy victims
phishing

BEC scammers are using Google Forms to identify easy victims

21 Jan 2021
FBI warns of ongoing corporate vishing attacks
phishing

FBI warns of ongoing corporate vishing attacks

19 Jan 2021
Hackers using COVID vaccine as a lure to spread malware
hacking

Hackers using COVID vaccine as a lure to spread malware

15 Jan 2021

Most Popular

How to move Windows 10 from your old hard drive to SSD
operating systems

How to move Windows 10 from your old hard drive to SSD

21 Jan 2021
WhatsApp could face €50 million GDPR fine
General Data Protection Regulation (GDPR)

WhatsApp could face €50 million GDPR fine

25 Jan 2021
How to recover deleted emails in Gmail
email delivery

How to recover deleted emails in Gmail

6 Jan 2021