This page was machine-translated and may differ from the original. View original
Evidence emerges that five APT groups linked to the Chinese government hijacked IPs by exploiting Linux server vulnerabilities
5 APT groups acting on behalf of the Chinese government,
Sharing tools, technology, infrastructure, target information, etc.
Using a Linux server as a network bridgehead for other tasks
Claims have been raised that five APT groups acting on behalf of the Chinese government have been cooperating with each other for over a decade to steal intellectual property contained in the Linux servers of major companies.

On the 20th, BlackBerry released an analysis report on how five associated "Advanced Persistent Threat (APT) groups" operating for the Chinese government were able to remain undetected for nearly 10 years while strategically attacking Android-powered Linux servers, Windows systems, and mobile devices.
The BlackBerry report released this time concerns intellectual property (IP) targeting cases involving more than 1,000 of the investigations recently disclosed by the U.S. Department of Justice from all 56 FBI field offices.It provides insights into my espionage activities.
The cross-platform nature of these attack activities is a particular concern amidst the security issues raised by the rapid increase in remote work. Devices used in the ongoing attack campaign were already planted to target the work-from-home period, and the reduced on-site personnel required to maintain the security of core systems exacerbate the risk.
In response to the COVID-19 outbreak, most of the workforce is working from home, but the majority of IPs still remain in enterprise data centers running on Linux.
According to 2019 and 2020 data from Netcraft and the Linux Foundation, Linux operates most of the top one million websites online, accounts for 75% of all web servers, 98% of supercomputers worldwide, and 75% of major cloud service providers. It was found that most large corporations use Linux to operate their websites, proxy network traffic, and store critical data.
The report investigated how APTs exploited the "always on, always available" characteristics of Linux servers to establish a foothold for operations across a wide range of targets.
"Most security companies focus their engineering and marketing on products designed for the front office rather than server racks, so coverage for Linux, which is not user-facing, is sparse," explained Eric Cornelius, BlackBerry's Chief Product Architect. "APT groups have targeted this security gap and have been exploiting it unnoticed for years to steal IPs from their target areas."
Other key analysis results of the report are as follows.
APT groups are expected to consist of private sector experts contracted by the Chinese government who can easily share tools, technologies, infrastructure, and target information not only with other APT groups but also with government agencies.
Generally, APT groups have pursued their own goals and focused on various attack targets. However, it was found that there was a significant level of organized movement among these groups when targeting the Linux platform.
The report covers two Android malware cases and confirmed that the trends shown in BlackBerry's report, "Scale of Mobile Malware Spread in Cross-Platform APT Spy Campaigns," which revealed how APT groups combine mobile malware with existing desktop malware for cross-platform surveillance and espionage campaigns, are continuing.
One of the Android malware samples is very similar to the code of a commercial penetration testing tool, but it appears to have been created about two years before that commercial tool was released to the market.
The report revealed several new variants of well-known malware that bypass network defenders by using code signing certificates for adware. The attackers' tactic is to increase infection rates by having AV red flags dismissed as mere repetitive alarm signals amidst continuous adware alerts.
The report pointed out that attackers have shifted toward using cloud service providers for command and control (C2) and data exfiltration communications that appear as trusted network traffic.
“This investigation clearly demonstrates espionage targeting the foundation of a massive organization’s network infrastructure in a more systematic manner than previously identified,” said John McClurg, BlackBerry’s Chief Information Security Officer. “The report opens a new chapter in the story of Chinese IP theft and will provide us with new lessons.”
Sharing tools, technology, infrastructure, target information, etc.
Using a Linux server as a network bridgehead for other tasks
Claims have been raised that five APT groups acting on behalf of the Chinese government have been cooperating with each other for over a decade to steal intellectual property contained in the Linux servers of major companies.

▲ BlackBerry claims that 5 APT groups linked to the Chinese government on Linux servers
Detected and analyzed circumstances of IP hijacking exploiting vulnerabilities
Published a report [Image=BlackBerry]
Detected and analyzed circumstances of IP hijacking exploiting vulnerabilities
Published a report [Image=BlackBerry]
On the 20th, BlackBerry released an analysis report on how five associated "Advanced Persistent Threat (APT) groups" operating for the Chinese government were able to remain undetected for nearly 10 years while strategically attacking Android-powered Linux servers, Windows systems, and mobile devices.
The BlackBerry report released this time concerns intellectual property (IP) targeting cases involving more than 1,000 of the investigations recently disclosed by the U.S. Department of Justice from all 56 FBI field offices.It provides insights into my espionage activities.
The cross-platform nature of these attack activities is a particular concern amidst the security issues raised by the rapid increase in remote work. Devices used in the ongoing attack campaign were already planted to target the work-from-home period, and the reduced on-site personnel required to maintain the security of core systems exacerbate the risk.
In response to the COVID-19 outbreak, most of the workforce is working from home, but the majority of IPs still remain in enterprise data centers running on Linux.
According to 2019 and 2020 data from Netcraft and the Linux Foundation, Linux operates most of the top one million websites online, accounts for 75% of all web servers, 98% of supercomputers worldwide, and 75% of major cloud service providers. It was found that most large corporations use Linux to operate their websites, proxy network traffic, and store critical data.
The report investigated how APTs exploited the "always on, always available" characteristics of Linux servers to establish a foothold for operations across a wide range of targets.
"Most security companies focus their engineering and marketing on products designed for the front office rather than server racks, so coverage for Linux, which is not user-facing, is sparse," explained Eric Cornelius, BlackBerry's Chief Product Architect. "APT groups have targeted this security gap and have been exploiting it unnoticed for years to steal IPs from their target areas."
Other key analysis results of the report are as follows.
APT groups are expected to consist of private sector experts contracted by the Chinese government who can easily share tools, technologies, infrastructure, and target information not only with other APT groups but also with government agencies.
Generally, APT groups have pursued their own goals and focused on various attack targets. However, it was found that there was a significant level of organized movement among these groups when targeting the Linux platform.
The report covers two Android malware cases and confirmed that the trends shown in BlackBerry's report, "Scale of Mobile Malware Spread in Cross-Platform APT Spy Campaigns," which revealed how APT groups combine mobile malware with existing desktop malware for cross-platform surveillance and espionage campaigns, are continuing.
One of the Android malware samples is very similar to the code of a commercial penetration testing tool, but it appears to have been created about two years before that commercial tool was released to the market.
The report revealed several new variants of well-known malware that bypass network defenders by using code signing certificates for adware. The attackers' tactic is to increase infection rates by having AV red flags dismissed as mere repetitive alarm signals amidst continuous adware alerts.
The report pointed out that attackers have shifted toward using cloud service providers for command and control (C2) and data exfiltration communications that appear as trusted network traffic.
“This investigation clearly demonstrates espionage targeting the foundation of a massive organization’s network infrastructure in a more systematic manner than previously identified,” said John McClurg, BlackBerry’s Chief Information Security Officer. “The report opens a new chapter in the story of Chinese IP theft and will provide us with new lessons.”
본 기사에 대한 정정·반론·추후보도 청구는 보도 청구 안내를, 그간 게재된 보도문은 정정·반론보도 모아보기를 참고해 주세요.














