Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Security Management

12/21/2018
07:00 AM
Scott Ferguson
Scott Ferguson
News Analysis-Security Now
50%
50%

Justice Department Ties 2 Chinese Nationals to Notorious APT10 Group

In another indictment aimed at China's cyberespionage infrastructure, the Justice Department has charged two Chinese nationals with belonging to the notorious APT10 group, which targeted industries in the US, Japan and other countries.

The Justice Department has fired another warning shot at China's elaborate cyberespionage infrastructure, with a new indictment this week that charges two Chinese nationals with belonging to the APT10 group, which is responsible for a series of attacks against facilities and businesses in the US, Japan and dozens of other countries.

The indictment, unsealed December 20, charges Zhu Hua, who also goes by the name "Godkiller," and Zhang Shilong, who is also known as "Atreexp," with belonging to China's Ministry of State Security's Tianjin State Security Bureau, which is believed to be responsible for cyber espionage, as well as various cyber attacks.

The two face charges of conspiracy to commit computer intrusions, conspiracy to commit wire fraud and aggravated identity theft. The hackers are not currently in custody.

APT10 has been in operation since at least 2006, and spies working for the group have targeted at least 45 different US technology companies since that time in attempt to steal intellectual property, personal data and other trade secrets. The group also goes by the names "Red Apollo," "CVNX," "Stone Panda," "MenuPass" and "POTASSIUM," according to Thursday's indictment.

Late on Thursday, Reuters reported that two of the technology companies involved in the APT10 hacking include stalwarts IBM and Hewlett Packard Enterprise.

In an email statement, Ben Read, the senior manager for Cyber Espionage Analysis at FireEye noted:

APT10 has been tracked by FireEye for years and is one of the most prolific cyber espionage groups. They have compromised dozens of public and private organizations worldwide, stealing valuable intellectual property and confidential information. The tactics described in the indictment and verticals targeted are consistent with what FireEye has seen from this group. APT10 has historically targeted organizations with long research and development cycles, including construction and engineering, aerospace and military, telecommunications, high technology sectors, as well as government entities. Their move towards compromising managed service providers (MSPs) showcases the danger of supply chain compromises and reflects their continuously evolving tactics. APT10 is a well-resourced and a global threat.

In the US, APT10 targeted numerous government agencies, including NASA's Goddard Space Center and Jet Propulsion Laboratory; the US Navy, which involved the theft of personal information involving 100,000 personnel; and the Department of Energy's Lawrence Berkeley National Laboratory, which conducts a number of government-sponsored research projects.

This is the second time in two months that federal prosecutors have charged Chinese nationals with cybersecurity and cyber espionage crimes. In November, the Justice Department unveiled a major case against ten people, who were charged with trying to steal intellectual property for years. (See DoJ Charges 10 Chinese Nationals in Elaborate Cyberespionage Case.)

In addition, federal officials believe that China and its spies are responsible for the data theft that affected 500 million customers of Marriott's Starwood chain of hotels, according to a report. (See China Suspected of Massive Marriott Data Breach Report.)

And tensions are mounting between the US and China, as American prosecutors pursue a case against the company's CFO for helping the firm violate trade sanctions involving Iran. (See Unknown Document 748364.)

Mukul Kumar, chief information security officer and vice president of cyber practice at security vendor Cavirin, noted in an email to Security Now that the Justice Department seems more willing to prosecute cases involving the theft of intellectual property than in the past. However, Kumar cautioned that the cyber activity involving these groups, such as APT10, are usually years in the making and enterprises need to factor that into their cybersecurity plans.

"What we all need to understand is that these attacks are not only in the past... they are ongoing as we speak," Kumar wrote. "Organizations must be continually diligent in protecting their cyber posture via a layered approach to security that includes inside-the-firewall protection, training and implementation of best practices."

Indeed, this week's indictment describes two specific incidents involving long-term spying operations.

The first campaign targeted an unnamed managed service provider (MSP), where APT10 successfully planted malware, including PlugX, RedLeaves and QuasarRAT, on the company's servers to help steal passwords and other credentials. The group then used those to gain access to administrative tools, including Remote Desktop Protocols. From there, the spies had access to the much larger network, which, in turn, gave them access to the MSP's clients in Brazil, Canada, Finland, France, Germany, India, Japan, Sweden, Switzerland, the United Arab Emirates, the UK and the US.

The second part of the indictment looks at the theft of data and intellectual property that included "hundreds of gigabytes of sensitive data and information from the victims' computer systems, including from at least the following victims: seven companies involved in aviation, space and/or satellite technology; three companies involved in communications technology; three companies involved in manufacturing advanced electronic systems and/or laboratory analytical instruments; a company involved in maritime technology; a company involved in oil and gas drilling, production, and processing."

This part of the campaign also included the thefts involving NASA, the Department of Energy and the Navy.

Related posts:

— Scott Ferguson is the managing editor of Light Reading and the editor of Security Now. Follow him on Twitter @sferguson_LR.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
COVID-19: Latest Security News & Commentary
Dark Reading Staff 7/6/2020
Introducing 'Secure Access Service Edge'
Rik Turner, Principal Analyst, Infrastructure Solutions, Omdia,  7/3/2020
Russian Cyber Gang 'Cosmic Lynx' Focuses on Email Fraud
Kelly Sheridan, Staff Editor, Dark Reading,  7/7/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Special Report: Computing's New Normal, a Dark Reading Perspective
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
The Threat from the Internetand What Your Organization Can Do About It
The Threat from the Internetand What Your Organization Can Do About It
This report describes some of the latest attacks and threats emanating from the Internet, as well as advice and tips on how your organization can mitigate those threats before they affect your business. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-5604
PUBLISHED: 2020-07-09
Android App 'Mercari' (Japan version) prior to version 3.52.0 allows arbitrary method execution of a Java object by a remoto attacker via a Man-In-The-Middle attack by using Java Reflection API of JavaScript code on WebView.
CVE-2020-5974
PUBLISHED: 2020-07-08
NVIDIA JetPack SDK, version 4.2 and 4.3, contains a vulnerability in its installation scripts in which permissions are incorrectly set on certain directories, which can lead to escalation of privileges.
CVE-2020-15072
PUBLISHED: 2020-07-08
An issue was discovered in phpList through 3.5.4. An error-based SQL Injection vulnerability exists via the Import Administrators section.
CVE-2020-15073
PUBLISHED: 2020-07-08
An issue was discovered in phpList through 3.5.4. An XSS vulnerability occurs within the Import Administrators section via upload of an edited text document. This also affects the Subscriber Lists section.
CVE-2020-2034
PUBLISHED: 2020-07-08
An OS Command Injection vulnerability in the PAN-OS GlobalProtect portal allows an unauthenticated network based attacker to execute arbitrary OS commands with root privileges. An attacker requires some knowledge of the firewall to exploit this issue. This issue can not be exploited if GlobalProtect...