Rising Sophistication of Chinese Hackers in Cyber Espionage Attacks.

Chinese hackers, identified as UNC3886, have exploited a zero-day vulnerability in the Fortinet FortiOS operating system to deploy backdoors onto Fortinet and VMware solutions and maintain persistent access to victim environments. The vulnerability, tracked as CVE-2022-41328, was patched by Fortinet on March 7, 2023. The attacks mounted by UNC3886 targeted Fortinet's FortiGate, FortiManager, and FortiAnalyzer appliances to deploy two different implants such as THINCRUST and CASTLETAP. The group was previously tied to another intrusion set targeting VMware ESXi and Linux vCenter servers as part of a hyperjacking campaign designed to drop backdoors such as VIRTUALPITA and VIRTUALPIE.
- Chinese Hackers Exploit Fortinet Zero-Day Flaw for Cyber Espionage Attack The Hacker News
- Chinese hackers are becoming more sophisticated, Google researchers say Fox News
- Chinese hackers are getting more sophisticated with their attacks, report says The Hill
- China Hammers US With A Wave Of ‘Stealth Attacks’; WSJ Report Says Trying To Access Sensitive Defense Info EurAsian Times
- Chinese Hackers Exploiting 0-day Vulnerability in Fortinet Products HackRead
Reading Insights
0
1
3 min
vs 4 min read
86%
712 → 97 words
Want the full story? Read the original article
Read on The Hacker News