{"id":3288,"date":"2024-04-28T20:00:00","date_gmt":"2024-04-29T01:00:00","guid":{"rendered":"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/philippines-pummeled-by-assortment-of-cyberattacks-tied-to-china"},"modified":"2024-04-28T20:00:00","modified_gmt":"2024-04-29T01:00:00","slug":"philippines-pummeled-by-assortment-of-cyberattacks-misinformation-tied-to-china","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/04\/28\/philippines-pummeled-by-assortment-of-cyberattacks-misinformation-tied-to-china\/","title":{"rendered":"Philippines Pummeled by Assortment of Cyberattacks &amp; Misinformation Tied to China"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt4e491c982b6a8019\/662ba6a7ebda195afa3ad383\/Philippines_robertharding_Alamy_Stock_Photo.jpeg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/philippines-pummeled-by-assortment-of-cyberattacks-misinformation-tied-to-china.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/philippines-pummeled-by-assortment-of-cyberattacks-misinformation-tied-to-china.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">A recent massive spike in cyber misinformation and hacking campaigns against the Philippines coincides with rising tensions between the country and its superpower neighbor China.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The cyberattacks consist of a combination of hack and leak (55%), distributed denial-of-service (10%), and misinformation and influence campaigns (35%), according to researchers at Resecurity who have been following the campaigns. The main targets are government (80%) and educational institutions (20%) in the Philippines, and these attacks \u2014 on police agencies, government ministries, and universities \u2014 and associated data leaks are sowing discontent in the country, according to the researchers.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">This represents a four-fold (325%) increase in what the researchers identify as malicious cyber-espionage activity targeting the Philippines in the first quarter of 2024 compared to the same period last year. &#8220;The goal of this activity is to discredit the government and create chaos via cyberspace, as the Philippine population also relies on digital media channels and is active on social media networks,&#8221; says Shawn Loveland, COO of Resecurity.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Resecurity has worked with authorities in the Philippines to trace back the source of attacks to online infrastructures in China and Vietnam. These &#8220;false flag&#8221; and &#8220;other territories&#8221; could be allies of China in such campaigns or provide them infrastructure for it, according to Resecurity.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Fake News\">Fake News<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The goal of the cyberattacks correlates with disinformation campaigns spinning Chinese narratives on topics such as regional disputes about territories in the South China Sea.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In a <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.resecurity.com\/blog\/article\/misinformation-and-hacktivist-campaigns-target-the-philippines-amidst-rising-tensions-with-china\" rel=\"noopener\">blog post<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> this month, Resecurity detailed the myriad of different groups associated with this collective activity. In one notable attack, a threat actor going by the alias &#8220;KryptonZambie&#8221; claimed to have obtained from unnamed sources over 152 gigabytes of stolen data containing Philippine citizen identity cards. Resecurity investigated this claim, which related to a post on Breach Forums, a Dark Web site, but found it unsubstantiated. The threat actor did not respond to any messages Resecurity investigators sent to a Telegram account used to publicize the supposed breach.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Other elements of the campaign involved posting an &#8220;audio deepfake&#8221; of Philippine President Ferdinand Marcos Jr. supposedly ordering military action against China. <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.scmp.com\/week-asia\/politics\/article\/3260229\/audio-deepfake-marcos-jnr-ordering-military-action-against-china-prompts-manila-debunk-clip\" rel=\"noopener\">No such directive exists<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, according to authorities in the Philippines.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">It\u2019s not all fakery, however. Several of the groups covered by Resecurity&#8217;s report \u2014 including&nbsp; Philippines Exodus Security and DeathNote Hackers \u2014 ran attacks that led to a confirmed data breach.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Not Real Hacktivists\">Not Real Hacktivists<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">While some of this activity might resemble that of hactivists, Resecurity believes nation state-backed hackers from China or possibly North Korea (another regional adversary to the Philippines) are really to blame.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Resecurity has reported over 12 government organizations in the Philippines being targeted in the same timeframe \u2014 hallmarks of a well-organised co-ordinated attack by nation-state actors rather than independent hacktivists.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Leveraging hacktivist-related monikers allows threat actors to avoid attribution while creating the perception of homegrown social conflict online,&#8221; according to Resecurity.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Last year a Chinese state-linked advanced persistent threat (APT) group known as <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/amid-military-buildup-china-deploys-mustang-panda-in-the-philippines\" rel=\"noopener\">Mustang Panda hacked <\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">a Philippine government target via a simple side-loading technique. &#8220;This group has a strong focus on Philippines and [is] still active,&#8221; according to Resecurity. Hacks by the group on&nbsp;Philippine government entities have been actively promoted via social media.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In April 2023, more than 800 gigabytes of both applicant and employee records from multiple state agencies \u2014 including the Philippine National Police (PNP), National Bureau of Investigation (NBI), Bureau of Internal Revenue (BIR), and Special Action Force (SAF) \u2014 were compromised.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">This was followed in September by a breach and ransomware attack on the Philippine Health Insurance Corporation&nbsp;(PhilHealth) that led to the exposure of hospital bills, internal memos, and identification documents. There remains an ongoing investigation into the full extent of the leak, according to cyber threat detection firm Gatewatcher.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Why Spy?\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">Why Spy?<\/span><\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">China (and to a lesser extent North Korea) is the prime suspect in much of this malfeasance, according to both Resecurity and other threat intel experts.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;China is a far more complex and nuanced territory than generally portrayed. Its internal pressures are likely to lead to increased cyber-espionage activity, rather than slowing it down,&#8221;&nbsp; says Ian Thornton-Trump, CISO at threat intel firm Cyjax.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;The PRC&#8217;s approach to cyberspace has always been to use it to advance its business interests, extracting technologies from Western companies and creating a protected domestic market for these industries, giving them an advantage in the global market,&#8221; Thornton-Trump notes.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Relations between China and the Philippines have deteriorated over recent months. Beijing condemned Filipino President Ferdinand Marcos Jr.&#8217;s congratulations to Taiwanese President-elect Lai following the latter&#8217;s recent election. China regards Taiwan as a renegade province.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The Philippines has recently reaffirmed its strong alliance with the United States, announcing plans for &#8220;more robust&#8221; military activities with the US and its allies, much to the chagrin of China. In addition, the Philippines and China are in dispute over territorial claims involving islands and waters in the South China Sea.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Incident Response\">Incident Response<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The US, Japan, and the Philippines recently entered a <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/japan-philippines-us-forge-cyber-threat-intelligence-sharing-alliance\" rel=\"noopener\">cyber threat-sharing arrangement<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> in the wake of rising attacks by China, North Korea, and Russia, a development likely to help the Philippines stay on top of the growing tide of cyberthreats.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Understanding the pattern of upsurge in malign cyber activity is the first step towards combatting it, experts say. &#8220;[With] a better understanding of the country&#8217;s internal forces, and how these relate to its cyber strategy, we can plan better defenses against PRC cyber espionage,&#8221; Cyjax&#8217;s Thornton-Trump says.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Resecurity offered recommendations to safeguard both the populace and Philippine business from cyberattacks:<\/span><\/p>\n<div data-component=\"basic-list\" class=\"BasicList BasicList_nestedLevel_0 BasicList_variant_unordered BasicList_limited\">\n<ul data-testid=\"basic-list-unordered\" class=\"BasicList-UnorderedList\">\n<li>\n<div class=\"BasicList-ListItem BasicList-ListItem_variant_unordered\" readability=\"6.5\"><span data-component=\"icon\" data-name=\"Circle\" class=\"BasicList-ListIcon BasicList-ListIcon_variant_unordered\"><\/span><\/p>\n<div class=\"BasicList-Item\" readability=\"8\">\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Accelerate digital identity protection of Philippine citizens \u2014 as hack and leak activity is putting their personal data at risk of being exposed.<\/span><\/p>\n<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"BasicList-ListItem BasicList-ListItem_variant_unordered\" readability=\"7\"><span data-component=\"icon\" data-name=\"Circle\" class=\"BasicList-ListIcon BasicList-ListIcon_variant_unordered\"><\/span><\/p>\n<div class=\"BasicList-Item\" readability=\"9\">\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Tighten Web application security by implementing WAFs (web application firewalls) and ongoing vulnerability assessment and pen-testing automation procedures to detect and contain vulnerabilities before bad actors exploit them.<\/span><\/p>\n<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"BasicList-ListItem BasicList-ListItem_variant_unordered\" readability=\"6.5\"><span data-component=\"icon\" data-name=\"Circle\" class=\"BasicList-ListIcon BasicList-ListIcon_variant_unordered\"><\/span><\/p>\n<div class=\"BasicList-Item\" readability=\"8\">\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Create fact-checking services online to combat disinformation and influence campaigns. Citizens should be offered a process for reporting suspicious online activity.<\/span><\/p>\n<\/div>\n<\/div>\n<\/li>\n<\/ul>\n<\/div>\n<p><a href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/philippines-pummeled-by-assortment-of-cyberattacks-tied-to-china\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A recent massive spike in cyber misinformation and hacking campaigns<\/p>\n","protected":false},"author":12,"featured_media":3289,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-3288","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/philippines-pummeled-by-assortment-of-cyberattacks-misinformation-tied-to-china.jpg?fit=1800%2C1229&ssl=1",1800,1229,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/philippines-pummeled-by-assortment-of-cyberattacks-misinformation-tied-to-china.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/philippines-pummeled-by-assortment-of-cyberattacks-misinformation-tied-to-china.jpg?fit=300%2C205&ssl=1",300,205,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/philippines-pummeled-by-assortment-of-cyberattacks-misinformation-tied-to-china.jpg?fit=640%2C437&ssl=1",640,437,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/philippines-pummeled-by-assortment-of-cyberattacks-misinformation-tied-to-china.jpg?fit=640%2C437&ssl=1",640,437,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/philippines-pummeled-by-assortment-of-cyberattacks-misinformation-tied-to-china.jpg?fit=1536%2C1049&ssl=1",1536,1049,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/philippines-pummeled-by-assortment-of-cyberattacks-misinformation-tied-to-china.jpg?fit=1800%2C1229&ssl=1",1800,1229,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/philippines-pummeled-by-assortment-of-cyberattacks-misinformation-tied-to-china.jpg?fit=1024%2C699&ssl=1",1024,699,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/philippines-pummeled-by-assortment-of-cyberattacks-misinformation-tied-to-china.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/philippines-pummeled-by-assortment-of-cyberattacks-misinformation-tied-to-china.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/philippines-pummeled-by-assortment-of-cyberattacks-misinformation-tied-to-china.jpg?fit=1800%2C1229&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3288","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=3288"}],"version-history":[{"count":1,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3288\/revisions"}],"predecessor-version":[{"id":3307,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3288\/revisions\/3307"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/3289"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=3288"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=3288"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=3288"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}