FEATURED: FBI, CISA & NSA Reveal How Hackers Targeted a Defense Industrial Base Organisation

Published on

in

This is our daily post that is shared across Twitter & Telegram and published first on here with Kindness & Love XX on peace-truth.com/

#AceNewsRoom With ‘Kindness & Wisdom’ Oct.06, 2022 @acenewsservices

Ace News Room Cutting Floor 06/10/2022

Follow Our Breaking & Daily News Here As It Happens:

#AceNewsDesk – U.S. cybersecurity and intelligence agencies on Tuesday disclosed that multiple nation-state hacking groups potentially targeted a “Defense Industrial Base (DIB) Sector organization’s enterprise network” as part of a cyber espionage campaign.

Industrial Base Organization
HACKERS SECURITY REPORT

[‘Advanced persistent threat] actors used an open-source toolkit called Impacket to gain their foothold within the environment and further compromise the network, and also used a custom data exfiltration tool, CovalentStealer, to steal the victim’s sensitive data,” the authorities said.

The joint advisory, which was authored by the Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and the National Security Agency (NSA), said the adversaries likely had long-term access to the compromised environment.

The findings are the result of CISA’s incident response efforts in collaboration with a trusted third-party security firm from November 2021 through January 2022. It did not attribute the intrusion to a known threat actor or group.

The initial infection vector used to breach the network is also unknown, although some of the APT actors are said to have obtained a digital beachhead to the target’s Microsoft Exchange Server as early as mid-January 2021.

Subsequent post-exploitation activities in February entailed a mix of reconnaissance and data collection efforts, the latter of which resulted in the exfiltration of sensitive contract-related information. Also deployed during this phase was the Impacket tool to establish persistence and facilitate lateral movement.

A month later, the APT actors exploited ProxyLogon flaws in Microsoft Exchange Server to install 17 China Chopper web shells and HyperBro, a backdoor exclusively used by a Chinese threat group called Lucky Mouse(aka APT27, Bronze Union, Budworm, or Emissary Panda).

The intruders, from late July through mid-October 2021, further employed a bespoke malware strain called CovalentStealer against the unnamed entity to siphon documents stored on file shares and upload them to a Microsoft OneDrive cloud folder.

Organizations are recommended to monitor logs for connections from unusual VPNs, suspicious account use, anomalous and known malicious command-line usage, and unauthorized changes to user accounts.

#AceNewsDesk report ………..Published: Oct.06: 2022:

Editor says …Sterling Publishing & Media Service Agency is not responsible for the content of external site or from any reports, posts or links, and can also be found here on Telegram: https://t.me/acenewsdaily and all wordpress and live posts and links here: https://acenewsroom.wordpress.com/ and thanks for following as always appreciate every like, reblog or retweet and free help and guidance tips on your PC software or need help & guidance from our experts AcePCHelp.WordPress.Com


Hey!

Hey there, fellow Robloxian! Whether you’re here to discover hidden gem games, level up your building skills, or just stay in the loop with the latest events, you’re in the right place. This blog is all about sharing the coolest things in the Roblox universe—from developer tips to epic game reviews. So grab your Bloxy Cola, hit that follow button, and let’s explore the world of Roblox together! 🚀


Join the Club

Stay updated with our latest tips and other news by joining our newsletter.

Discover more from Peace & Truth

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from Peace & Truth

Subscribe now to keep reading and get access to the full archive.

Continue reading