Tag

Blacktech

All articles tagged with #blacktech

cybersecurity2 years ago

China's Router Hacking Threat: US and Japan Issue Warnings

The US and Japan have issued a joint advisory warning that Chinese government spies may be using Cisco routers to steal intellectual property and sensitive data. The advisory highlights the activities of BlackTech, a cyber-espionage group that can modify router firmware undetected and exploit domain-trust relationships to target international subsidiaries and headquarters in Japan and the US. While Cisco gear is specifically mentioned, the report notes that similar techniques could be used to set up backdoors in other networking equipment. BlackTech, also known as Palmerworm, targets government, industrial, technology, media, electronics, telecommunication, and defense players. The advisory emphasizes the need for companies to update, patch, and secure their network devices.

cybersecurity2 years ago

China-Linked Hackers Exploit Cisco Router Firmware for Covert Operations

Chinese state-sponsored hacking group BlackTech has been discovered using firmware implants in Cisco routers to maintain persistence and move stealthily within the networks of multinational companies in the US and Japan. The group modifies router firmware to hide their activity and uses compromised branch routers to blend in with corporate network traffic and pivot to other victims. BlackTech, active since 2010, targets various sectors including government, technology, and media. The group has been caught replacing firmware and using a built-in SSH backdoor to maintain access without logging connections. The advisory recommends monitoring network devices, upgrading to devices with secure boot capabilities, and reviewing logs for unauthorized changes. Cisco denies any vulnerabilities being exploited and states that compromised software only affects legacy devices.