Chinese APT groups are targeting Linux servers
Research from Blackberry uncovers almost a decade of hacking from state-sponsored civilian contractors
Chinese-sponsored hackers have been targeting Linux servers in order to steal intellectual property, according to Blackberry researchers, and it's been happening for almost a decade.
The 'RATs' the report refers to is remote access trojans and the five groups have been using them to exploit the "always on, always available" nature of Linux servers by establishing a "beachhead" that can then be used for coordinated attacks.
"As China forges its role as one of the great world powers, it continues to rely upon a blast furnace of cyber espionage operations in order to acquire foreign technologies and intellectual property, to better position itself against the global influence of competing international powers, and to control its own image both at home and abroad," the report states.
According to the report, the five groups "acting in the interests of the Chinese government" have strategically targeted Linux servers because the OS is not a primary focus for enterprise security. It suggests that defensive coverage in this area is immature at best as endpoint protection products are either lack the capabilities to defend them or are "inadequately utilised".
Compromising Linux web servers in this way allows hackers to exfiltrate massive amounts of data that can be obscured within daily web traffic, according to the report. This both provides them with a chance to find valuable and sensitive data and also erases a layer of protection that corporate networks need.
What's more, the groups are coordinating their attacks and are operating in a single domain, which the report suggests is rare. Although it doesn't name the groups specifically, it identifies them as civilian contractors and relations of the Winnti group. According to Kaspersky, the Winnti group has been active for several years but mostly focused on the online gaming industry.
"This reflects a highly agile government/contractor ecosystem with few of the bureaucratic or legal hurdles that can be observed in Western nations with similar capabilities and provides a level of plausible deniability for the Chinese government," the report suggests.
Unleashing the power of AI initiatives with the right infrastructure
What key infrastructure requirements are needed to implement AI effectively?Download now
Achieve today. Plan tomorrow. Making the hybrid multi-cloud journey
A Veritas webinar on implementing a hybrid multi-cloud strategyDownload now
A buyer’s guide for cloud-based phone solutions
Finding the right phone system for your modern businessDownload now
The workers' experience report
How technology can spark motivation, enhance productivity and strengthen securityDownload now