Security firms pour on evidence of Chinese hacking against Vietnam

A hacking group with suspected ties to the Chinese government is engaged in an ongoing and expansive cyber espionage operation against Vietnamese organizations, based on evidence obtained by three different cybersecurity firms. The campaign’s discovery comes during a period of mounting geopolitical tension due to a territorial dispute related to the South China Sea. China, Vietnam, Indonesia and the Philippines, among other powers, disagree on which country has claim to a collection of resource-rich islands that sit in the middle of an important international trade route. Cybersecurity firms Votiro, FireEye and Fortinet each obtained phishing emails that were sent to Vietnamese organizations in recent months. Researchers say these emails carried certain forensic indicators, including overlaps in malware and attack servers, that can be traced back to a group previously attributed to Chinese hackers. The South China Sea dispute represents a longstanding disagreement that dates back years. Foreign policy experts believe […]

The post Security firms pour on evidence of Chinese hacking against Vietnam appeared first on Cyberscoop.

Continue reading Security firms pour on evidence of Chinese hacking against Vietnam

This hacking group with suspected ties to the Vietnamese government is wreaking havoc

A hacking group with suspected ties to the Vietnamese government, known as APT32 or OceanLotus, has been actively conducting cyber espionage missions against valuable corporations, foreign governments, dissidents and domestic journalists since at least 2014, according to new research conducted by cybersecurity firm FireEye. “We have known them to target governments and citizens, but the targeting of global corporations — and the pace at which APT32 adapted — was unexpected,” said FireEye analyst Nick Carr. “Frankly, their capabilities surprised us.” FireEye was able to confirm that at least 12 private sector organizations were targeted by APT32, which is known to send well-crafted phishing emails with booby-trapped Microsoft Word attachments. Most of the assets initially compromised are geographically located in southeast Asia, Carr said. The findings underscore how developing nations are increasingly investing resources to cultivate their own hacking capabilities to effectively collect intelligence on both economic and political targets. By leveraging […]

The post This hacking group with suspected ties to the Vietnamese government is wreaking havoc appeared first on Cyberscoop.

Continue reading This hacking group with suspected ties to the Vietnamese government is wreaking havoc

Facebook Is a Black Market For Vietnam’s Wildlife Traffickers

A year-long investigation revealed that Facebook has unwillingly become a safe haven for wildlife smugglers. Continue reading Facebook Is a Black Market For Vietnam’s Wildlife Traffickers

Unpacking the spyware disguised as antivirus

Recently we got access to several elements of the espionage toolkit that has been captured attacking Vietnamese institutions. During the operation, the malware was used to dox 400,000 members of Vietnam Airlines.Categories: Malware
Threat analysisTags… Continue reading Unpacking the spyware disguised as antivirus