{"id":3605,"date":"2024-05-16T14:37:00","date_gmt":"2024-05-16T19:37:00","guid":{"rendered":"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/asian-threat-actors-use-new-techniques-to-attack-familiar-targets"},"modified":"2024-05-16T14:37:00","modified_gmt":"2024-05-16T19:37:00","slug":"asian-threat-actors-use-new-techniques-to-attack-familiar-targets","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/05\/16\/asian-threat-actors-use-new-techniques-to-attack-familiar-targets\/","title":{"rendered":"Asian Threat Actors Use New Techniques to Attack Familiar Targets"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt067891c8ed741073\/64f16fb3095a7f672290fc51\/Cyberattack_Skorzewiak_Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/asian-threat-actors-use-new-techniques-to-attack-familiar-targets.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/asian-threat-actors-use-new-techniques-to-attack-familiar-targets.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Since June 2023, Microsoft has observed several notable&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.microsoft.com\/en-us\/security\/business\/security-insider\/reports\/east-asia-threat-actors-employ-unique-methods\/\" rel=\"noopener\">cyber and influence trends<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&nbsp;from China and North Korea that indicate nation-state threat groups are doubling down on familiar targets by using more sophisticated influence techniques to achieve their goals. To protect their organizations against the latest attack vectors and nation-state threats, security teams must remain abreast of these trends.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Chinese Influence Actors Hone Techniques, Experiment With A\">Chinese Influence Actors Hone Techniques, Experiment With A<span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">I<\/span><\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In recent months, Chinese cyber actors have broadly targeted three core areas: entities across the South Pacific islands, regional adversaries in the South China Sea, and the US defense industrial base. Meanwhile, Chinese influence actors have been able to refine their use of AI-generated and AI-enhanced content while also experimenting with new media in an attempt to stoke divisions within the US and exacerbate rifts in the Asia-Pacific region.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">For example, in a&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.microsoft.com\/en-us\/security\/business\/security-insider\/reports\/nation-state-reports\/digital-threats-from-east-asia-increase-in-breadth-and-effectiveness\/\" rel=\"noopener\">September 2023 report<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, we explored the use of generative artificial intelligence by Chinese influence operation (IO) assets to create engaging visual content, including AI-generated memes that targeted the US to amplify controversial domestic issues and criticize the Biden administration.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Storm-1376 is one of the most prolific Chinese threat actors using AI content, with IO campaigns that span over 175 websites and 58 different languages. Recently, Storm-1376&#8217;s campaigns have begun using AI-generated photos to mislead audiences, stoke conspiratorial content \u2014 particularly against the US government \u2014 and target new populations with localized content.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Last August, Storm-1376 spread a number of&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.nytimes.com\/2023\/09\/11\/us\/politics\/china-disinformation-ai.html\" rel=\"noopener\">conspiratorial social media posts<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&nbsp;claiming that the US government deliberately set fires on the island of Maui in Hawaii, to test a military-grade &#8220;weather weapon.&#8221; In addition to posting the text in at least 31 languages across dozens of websites and platforms, Storm-1376 used AI-generated images of burning coastal roads and residences to make the content more eye-catching. As we approach the 2024 election cycle in the US, we expect China to continue creating and amplifying AI-generated content targeted at the American public.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"North Koreans Increase Software Supply Chain Attacks, Crypto Heists\">North Koreans Increase Software Supply Chain Attacks, Crypto Heists<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">On the North Korean side, cyber threat actors stole hundreds of millions of dollars in cryptocurrency, conducted software supply chain attacks, and targeted their perceived national security adversaries in 2023. These operations are used to generate revenue for the North Korean government \u2014 particularly its&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\/aa20-106a\" rel=\"noopener\">weapons program<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> \u2014 and collect intelligence on the US, South Korea, and Japan. The United Nations estimates that North Korean cyber actors have stolen over&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.reuters.com\/technology\/cybersecurity\/un-experts-investigate-58-cyberattacks-worth-3-bln-by-north-korea-2024-02-08\/\" rel=\"noopener\">$3 billion<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&nbsp;in cryptocurrency since 2017, with multiple heists totaling between&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.trmlabs.com\/post\/north-korean-hackers-stole-600-million-in-crypto-in-2023\" rel=\"noopener\">$600 million and $1 billion<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&nbsp;in 2023 alone.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">One threat actor tracked by Microsoft, named Sapphire Sleet, conducted a number of small yet frequent cryptocurrency theft operations. The group developed new techniques to carry out these operations, such as sending fake virtual meeting invitations containing links to an attacker domain and registering fake job-recruiting websites. Sapphire Sleet is known to target executives and developers at cryptocurrency, venture capital, and other financial organizations.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">We&#8217;ve also seen North Korean threat actors conduct software supply chain attacks on IT firms, resulting in access to downstream customers. One group, known as Jade Sleet, used GitHub repos and weaponized npm packages in a&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/github.blog\/2023-07-18-security-alert-social-engineering-campaign-targets-technology-industry-employees\/\" rel=\"noopener\">social engineering spear-phishing campaign<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&nbsp;that targeted employees of cryptocurrency and technology organizations. The attackers impersonated developers or recruiters, invited targets to collaborate on a GitHub repository, and convinced them to clone and execute its contents, which contained malicious npm packages.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Another group, known as Onyx Sleet, exploited the TeamCity CVE-2023-42793 vulnerability to perform a remote code execution attack and gain administrative control of servers. The group has been tied to software supply chain attacks on at least 10 victims \u2014 including a software provider in Australia and a government agency in Norway \u2014 and used post-compromise tooling to execute additional payloads.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">As North Korea embarks upon new government policies and pursues ambitious plans for weapons testing, we can expect increasingly sophisticated cryptocurrency heists and supply chain attacks targeted at the defense sector. Security teams for defense and related industries must remain vigilant against these threats.&nbsp;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/asian-threat-actors-use-new-techniques-to-attack-familiar-targets\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Since June 2023, Microsoft has observed several notable&nbsp;cyber and influence<\/p>\n","protected":false},"author":12,"featured_media":3606,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-3605","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/asian-threat-actors-use-new-techniques-to-attack-familiar-targets.jpg?fit=800%2C474&ssl=1",800,474,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/asian-threat-actors-use-new-techniques-to-attack-familiar-targets.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/asian-threat-actors-use-new-techniques-to-attack-familiar-targets.jpg?fit=300%2C178&ssl=1",300,178,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/asian-threat-actors-use-new-techniques-to-attack-familiar-targets.jpg?fit=640%2C379&ssl=1",640,379,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/asian-threat-actors-use-new-techniques-to-attack-familiar-targets.jpg?fit=640%2C379&ssl=1",640,379,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/asian-threat-actors-use-new-techniques-to-attack-familiar-targets.jpg?fit=800%2C474&ssl=1",800,474,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/asian-threat-actors-use-new-techniques-to-attack-familiar-targets.jpg?fit=800%2C474&ssl=1",800,474,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/asian-threat-actors-use-new-techniques-to-attack-familiar-targets.jpg?fit=800%2C474&ssl=1",800,474,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/asian-threat-actors-use-new-techniques-to-attack-familiar-targets.jpg?resize=800%2C474&ssl=1",800,474,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/asian-threat-actors-use-new-techniques-to-attack-familiar-targets.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/asian-threat-actors-use-new-techniques-to-attack-familiar-targets.jpg?fit=800%2C474&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3605","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=3605"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3605\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/3606"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=3605"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=3605"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=3605"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}