Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats //

Advanced Threats

Chinese Attackers Targeting U.S. Think Tanks, Researchers Say

Government-backed group "Deep Panda" compromised "several" nonprofit national security policy research organizations, CrowdStrike says

The Chinese cyber attack group Deep Panda late last month compromised "several" national security think tanks with multiple, simultaneous, and sophisticated attacks designed to collect information about foreign policy decisions, according to researchers at security firm CrowdStrike.

Deep Panda, a group that has been attacking targets in the high-tech, financial services, and government arenas since 2009, was found to be cracking think tank systems to collect data on national security policy related to southeast Asia and the Middle East -- two areas where international disputes heightened in June. CrowdStrike officials declined to name the think tanks or the exact details of the data that was compromised, but the attackers breached email, directories and files, they said.

Deep Panda had been collecting information primarily on U.S. policy in southeast Asia, but suddenly shifted direction and began collecting data about Iraq and Middle East policy, according to a blog posted on the CrowdStrike site this afternoon.

"This is undoubtedly related to the recent Islamic State of Iraq and the Levant (ISIS) takeover of major parts of Iraq, and the potential disruption for major Chinese oil interests in that country," the blog says. "In fact, Iraq happens to be the fifth-largest source of crude oil imports for China and the country is the largest foreign investor in Iraq’s oil sector. Thus, it wouldn’t be surprising if the Chinese government is highly interested in getting a better sense of the possibility of deeper U.S. military involvement that could help protect the Chinese oil infrastructure in Iraq. In fact, the shift in targeting of Iraq policy individuals occurred on June 18, the day that ISIS began its attack on the Baiji oil refinery."

The attacks were sophisticated, exploiting a vulnerability in Windows which allowed the group to deploy powershell scripts as scheduled tasks on Microsoft Windows machines, according to CrowdStrike. "The scripts are passed to the powershell interpreter through the command line to avoid placement of extraneous files on the victim machine that could potentially trigger AV- or Indicator of Compromise (IOC)-based detection," the blog states.

"This particular group makes a lot of attacks through a Web exploit or SQL injection, which is followed by in-memory and command line exploits that are difficult to detect because they don't leave artifacts behind," says Adam Meyers, vice president of intelligence at CrowdStrike. "This is a tactic that they will probably continue to use because it works well for them."

CrowdStrike was able to detect the attacks through its Falcon Host software, an agent that collects security information from each endpoint and correlates it with threat data that the company collects from other endpoints. CrowdStrike provides its software to a number of think tanks and human rights organizations on a pro bono basis, because they are nonprofit organizations but are frequent targets of cyber espionage, Meyers says.

The think tanks are "well into the cleanup" of the compromises and are taking steps to prevent future similar attacks, Meyers states. However, it is likely that Deep Panda will continue to target such organizations, he says.

"These think tanks often employ ex-government people who have great contacts and are well connected with foreign governments," Meyers notes. "They are a great source of policy data and I don't think Deep Panda will stop targeting them anytime soon."

Tim Wilson is Editor in Chief and co-founder of Dark Reading.com, UBM Tech's online community for information security professionals. He is responsible for managing the site, assigning and editing content, and writing breaking news stories. Wilson has been recognized as one ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Why Cyber-Risk Is a C-Suite Issue
Marc Wilczek, Digital Strategist & CIO Advisor,  11/12/2019
DevSecOps: The Answer to the Cloud Security Skills Gap
Lamont Orange, Chief Information Security Officer at Netskope,  11/15/2019
Unreasonable Security Best Practices vs. Good Risk Management
Jack Freund, Director, Risk Science at RiskLens,  11/13/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Navigating the Deluge of Security Data
In this Tech Digest, Dark Reading shares the experiences of some top security practitioners as they navigate volumes of security data. We examine some examples of how enterprises can cull this data to find the clues they need.
Flash Poll
The State of Ransomware
The State of Ransomware
Ransomware has become one of the most prevalent new cybersecurity threats faced by today's enterprises. This new report from Dark Reading includes feedback from IT and IT security professionals about their organization's ransomware experiences, defense plans, and malware challenges. Find out what they had to say!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-19040
PUBLISHED: 2019-11-17
KairosDB through 1.2.2 has XSS in view.html because of showErrorMessage in js/graph.js, as demonstrated by view.html?q= with a '"sampling":{"value":"<script>' substring.
CVE-2019-19041
PUBLISHED: 2019-11-17
An issue was discovered in Xorux Lpar2RRD 6.11 and Stor2RRD 2.61, as distributed in Xorux 2.41. They do not correctly verify the integrity of an upgrade package before processing it. As a result, official upgrade packages can be modified to inject an arbitrary Bash script that will be executed by th...
CVE-2019-19012
PUBLISHED: 2019-11-17
An integer overflow in the search_in_range function in regexec.c in Oniguruma 6.x before 6.9.4_rc2 leads to an out-of-bounds read, in which the offset of this read is under the control of an attacker. (This only affects the 32-bit compiled version). Remote attackers can cause a denial-of-service or ...
CVE-2019-19022
PUBLISHED: 2019-11-17
iTerm2 through 3.3.6 has potentially insufficient documentation about the presence of search history in com.googlecode.iterm2.plist, which might allow remote attackers to obtain sensitive information, as demonstrated by searching for the NoSyncSearchHistory string in .plist files within public Git r...
CVE-2019-19035
PUBLISHED: 2019-11-17
jhead 3.03 is affected by: heap-based buffer over-read. The impact is: Denial of service. The component is: ReadJpegSections and process_SOFn in jpgfile.c. The attack vector is: Open a specially crafted JPEG file.