{"id":4370,"date":"2024-07-09T12:08:06","date_gmt":"2024-07-09T17:08:06","guid":{"rendered":"https:\/\/www.darkreading.com\/endpoint-security\/chinese-apt40-exploits-nday-vulns-rapid-pace"},"modified":"2024-07-09T12:08:06","modified_gmt":"2024-07-09T17:08:06","slug":"chinese-threat-group-apt40-exploits-n-day-vulns-at-rapid-pace","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/07\/09\/chinese-threat-group-apt40-exploits-n-day-vulns-at-rapid-pace\/","title":{"rendered":"Chinese Threat Group APT40 Exploits N-Day Vulns at Rapid Pace"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt35897d80e0367100\/668d67956b429c4da78ad356\/chinesethreatactor_3D_generator_alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/chinese-threat-group-apt40-exploits-n-day-vulns-at-rapid-pace.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/chinese-threat-group-apt40-exploits-n-day-vulns-at-rapid-pace.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">APT40, a <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/threat-intelligence\/microsoft-mystery-group-targeting-telcos-chinese-apts\" rel=\"noopener\">Chinese state-sponsored actor<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, is targeting newly discovered software vulnerabilities with the goal of exploiting them within hours, according to a joint government advisory.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The advisory \u2014 authored by the Cybersecurity and Infrastructure Security Agency, FBI, and National Security Agency in the US, as well as government agencies in Australia, the UK, Canada, New Zealand, Germany, South Korea, and Japan \u2014 said the cyber group has targeted organizations in a variety of different arenas, using techniques that are commonly used by other state-sponsored actors in China. It has repeatedly targeted Australian networks, for instance, and it remains an ongoing threat, the agencies warned.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Rather than using techniques that require user interaction, the group seemingly prefers to exploit vulnerable, public-facing infrastructure and prioritizes obtaining valid credentials. It often hops on public exploits as soon as they become available, setting up a &#8220;patching race&#8221; condition for organizations.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;The focus on public-facing infrastructure is interesting. It shows they&#8217;re looking for the path of least resistance; why bother with elaborate phishing campaigns when you can just hit exposed vulnerabilities directly?&#8221; says Tal Mandel Bar, product manager at DoControl.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The APT targets newly disclosed bugs but also has plenty of older exploits at its disposal, the agencies said. Thus, a comprehensive vulnerability management effort is in order.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;it\u2019s imperative for security teams to patch vulnerabilities promptly and keep an eye on advisories from trusted sources, especially in the case of APT40, which quickly adapts <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/application-security\/poc-exploit-critical-rce-bug-ivanti-endpoint-manager\" rel=\"noopener\">public proof-of-concept (PoC) exploits<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">,&#8221; Darren Guccione, CEO and co-founder at Keeper Security, wrote in an email to Dark Reading. &#8220;Because this group regularly exploits vulnerable, end-of-life or no longer maintained devices \u2014 including vulnerabilities from as early as 2017 \u2014 it is imperative that organizations regularly update their software and apply patches as soon as vulnerabilities are made public. Devices that are no longer maintained or cannot be patched quickly should be taken offline.&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"APT40's Extensive Reconnaissance Efforts\">APT40&#8217;s Extensive Reconnaissance Efforts<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">APT40 regularly conducts reconnaissance against networks of interest, &#8220;including networks in the authoring agencies&#8217; countries, looking for opportunities to compromise its targets,&#8221; according to the joint advisory. The group then deploys Web shells for persistence, and focuses on exfiltrating information from sensitive repositories.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;The data stolen by APT40 serves dual purposes: It is used for state espionage and <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/threat-intelligence\/china-apt-stole-geopolitical-secrets-from-middle-east-africa-and-asia\" rel=\"noopener\">subsequently transferred to Chinese companies<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">,&#8221; Chris Grove, director of cybersecurity strategy at Nozomi Networks, wrote in an emailed statement to Dark Reading. &#8220;Organizations with critical data or operations should take these government warnings seriously and strengthen their defenses accordingly. One capability that assists defenders in hunting down these types of threats is advanced anomaly detection systems, acting as intrusion detection for attackers able to &#8216;live off the land&#8217; and avoid deploying malware that would reveal their presence.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">APT40 has evolved its techniques, as well, embracing using compromised endpoints such as small-office\/home-office (SOHO) devices for operations, which have ultimately led to the authoring agencies being able to better track the group. That tactic, <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cloud-security\/volt-typhoon-soho-botnet-infects-us-govt-entities\" rel=\"noopener\">infamously used by Volt Typhoon<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, is one of many aspects of the group&#8217;s activity that&#8217;s similar to other China-backed threat groups such as Kryptonite Panda, Gingham Typhoon, Leviathan, and Bronze Mohawk, the advisory noted.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In the advisory, the agencies provide <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.cyber.gov.au\/sites\/default\/files\/2024-07\/apt40-advisory-prc-mss-tradecraft-in-action.pdf\" rel=\"noopener\">mitigation techniques<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> for the four main types of tactics, techniques, and procedures (TTPs) that APT40 uses, including initial access, execution, persistence, and privilege escalation.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/endpoint-security\/chinese-apt40-exploits-nday-vulns-rapid-pace\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>APT40, a Chinese state-sponsored actor, is targeting newly discovered software<\/p>\n","protected":false},"author":12,"featured_media":4371,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-4370","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/chinese-threat-group-apt40-exploits-n-day-vulns-at-rapid-pace-scaled.jpg?fit=2560%2C1450&ssl=1",2560,1450,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/chinese-threat-group-apt40-exploits-n-day-vulns-at-rapid-pace-scaled.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/chinese-threat-group-apt40-exploits-n-day-vulns-at-rapid-pace-scaled.jpg?fit=300%2C170&ssl=1",300,170,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/chinese-threat-group-apt40-exploits-n-day-vulns-at-rapid-pace-scaled.jpg?fit=640%2C363&ssl=1",640,363,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/chinese-threat-group-apt40-exploits-n-day-vulns-at-rapid-pace-scaled.jpg?fit=640%2C363&ssl=1",640,363,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/chinese-threat-group-apt40-exploits-n-day-vulns-at-rapid-pace-scaled.jpg?fit=1536%2C870&ssl=1",1536,870,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/chinese-threat-group-apt40-exploits-n-day-vulns-at-rapid-pace-scaled.jpg?fit=2048%2C1160&ssl=1",2048,1160,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/chinese-threat-group-apt40-exploits-n-day-vulns-at-rapid-pace-scaled.jpg?fit=1024%2C580&ssl=1",1024,580,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/chinese-threat-group-apt40-exploits-n-day-vulns-at-rapid-pace-scaled.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/chinese-threat-group-apt40-exploits-n-day-vulns-at-rapid-pace-scaled.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/chinese-threat-group-apt40-exploits-n-day-vulns-at-rapid-pace-scaled.jpg?fit=2560%2C1450&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4370","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=4370"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4370\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/4371"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=4370"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=4370"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=4370"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}