Showing posts with label cyber espionage. Show all posts
Showing posts with label cyber espionage. Show all posts

Wednesday, August 13, 2025

Two hackers breach and expose a major North Korean hacking and spying operation

Good news! Hack the hackers!

"Hackers claim to have compromised the computer of a North Korean government hacker and leaked its contents online, offering a rare window into a hacking operation by the notoriously secretive nation. ..."

Hackers breach and expose a major North Korean spying operation | TechCrunch

The chief hacker


Tuesday, April 29, 2025

Government hackers are leading the use of attributed zero-day exploits in 2024, Google says

Bad news!

"Google Threat Intelligence Group (GTIG) tracked 75 zero-day vulnerabilities exploited in the wild in 2024, a decrease from the number we identified in 2023 (98 vulnerabilities), but still an increase from 2022 (63 vulnerabilities).
We divided the reviewed vulnerabilities into two main categories: end-user platforms and products (e.g., mobile devices, operating systems, and browsers) and enterprise-focused technologies, such as security software and appliances. ...

Key Takeaways
  • Zero-day exploitation continues to grow gradually. The 75 zero-day vulnerabilities exploited in 2024 follow a pattern that has emerged over the past four years. ...
  • Enterprise-focused technology targeting continues to expand. GTIG continued to observe an increase in adversary exploitation of enterprise-specific technologies throughout 2024. In 2023, 37% of zero-day vulnerabilities targeted enterprise products. This jumped to 44% in 2024, primarily fueled by the increased exploitation of security and networking software and appliances.
  • Attackers are increasing their focus on security and networking products. Zero-day vulnerabilities in security software and appliances were a high-value target in 2024. We identified 20 security and networking vulnerabilities, which was over 60% of all zero-day exploitation of enterprise technologies. ...
  • Actors conducting cyber espionage still lead attributed zero-day exploitation. Between government-backed groups and customers of commercial surveillance vendors (CSVs), actors conducting cyber espionage operations accounted for over 50% of the vulnerabilities we could attribute in 2024. People's Republic of China (PRC)-backed groups exploited five zero-days, and customers of CSVs exploited eight, continuing their collective leading role in zero-day exploitation. For the first year ever, we also attributed the exploitation of the same volume of 2024 zero-days (five) to North Korean actors mixing espionage and financially motivated operations as we did to PRC-backed groups.
..."

Government hackers are leading the use of attributed zero-days, Google says | TechCrunch



Figure 4: 2024 attributed zero-day exploitation


Saturday, April 17, 2021

The $1 billion Russian cyber company that the US says hacks for Moscow

Recommendable! The Russian company Positive Technologies has quite a business model!

"... MIT Technology Review understands that US officials have privately concluded that the company is a major provider of offensive hacking tools, knowledge, and even operations to Russian spies. Positive is believed to be part of a constellation of private sector firms and cybercriminal groups that support Russia’s geopolitical goals, and which the US increasingly views as a direct threat. ...
But according to previously unreported US intelligence assessments, it also develops and sells weaponized software exploits to the Russian government

One area that’s stood out is the firm’s work on SS7, a technology that’s critical to global telephone networks. ... Positive showed how it can bypass encryption by exploiting weaknesses in SS7. Privately, the US has concluded that Positive did not just discover and publicize flaws in the system, but also developed offensive hacking capabilities to exploit security holes that were then used by Russian intelligence in cyber campaigns. ..."

The $1 billion Russian cyber company that the US says hacks for Moscow | MIT Technology Review Washington has sanctioned Russian cybersecurity firm Positive Technologies. US intelligence reports claim it provides hacking tools and runs operations for the Kremlin.

Saturday, August 15, 2020

U.S. Government Contractor Embedded Software in Apps to Track Phones

If a U.S. government contractor can do this, then what are China (e.g. TikTok), Russia, North Korea, Iran capable of?

"A small U.S. company with ties to the U.S. defense and intelligence communities has embedded its software in numerous mobile apps, allowing it to track the movements of hundreds of millions of mobile phones world-wide, according to interviews and documents reviewed by The Wall Street Journal. ..."

U.S. Government Contractor Embedded Software in Apps to Track Phones - WSJ Anomaly Six has ties to military, intelligence agencies and draws location data from more than 500 apps with hundreds of millions of users

Friday, July 31, 2020

Chinese, North Korean and Russian hackers were just sanctioned by Europe for the first time | MIT Technology Review

Finally, the EU is getting more serious too about Russian, North Korean, and Chinese spying and hacking! The West has been way too lenient for way too long!



"Retaliation for Russian attacks: The most prominent target of EU action is unit 74455 of Russia’s GRU military intelligence service, a group known as Sandworm. It is linked to the NotPetya ransomware attacks, which experts say began as a political attack against Ukraine but then quickly spread across the world and caused over $10 billion in damage. ... China’s corporate espionage: In China, two citizens and a company, Haitai Technology Development, were sanctioned in connection with a hacking campaign known as Cloudhopper. ... The North Korean firm Chosun Expo was sanctioned because of its role  supporting WannaCry , the 2017 ransomware outbreak that ripped through IT systems across the globe"



Chinese and Russian hackers were just sanctioned by Europe for the first time | MIT Technology Review The European Union imposed its first-ever sanctions for cyberattacks on Thursday, targeting Russian, Chinese, and North Korean groups connected to several major hacking incidents.

Thursday, July 16, 2020

Corona: Russland soll Impfstoff-Forschung im Westen ausspioniert haben

Doing business the former KGB and its successor organisation chief Putin the Terrible way! As if the former Soviet Union still exists!

Corona: Russland soll Impfstoff-Forschung ausspioniert haben Sicherheitsbehörden aus Grossbritannien, den USA und Kanada werfen einer Hackergruppe Angriffe auf Einrichtungen vor, die an der Impfstoffentwicklung arbeiten. Die Gruppe gilt als Arm der russischen Geheimdienste.

Wednesday, July 15, 2020

Joe Biden, Barack Obama, Bill Gates: In den USA wurden Twitter-Konten von Prominenten und Firmen gehackt

Wer oder welches Land steckt hinter diesem raffinierten, koordinierten Angriff auf Twitter accounts ausgesuchter Prominenter?

Der immer noch niedrige Standard von cyber security wurde mal wieder deutlich demonstriert! Oder ist Twitter extrem nachlässig in Sachen cyber security?

"... und des früheren New Yorker Bürgermeisters Michael Bloomberg. Auch Tesla-Gründer Elon Musk, Amazon-Chef Jeff Bezos, Microsoft-Gründer Bill Gates, Rapper Kanye West und Firmen wie Apple und Uber sollen Opfer der Hacker-Attacke sein. ... Auf den Twitter-Konten wurde ein mehr oder weniger identischer Aufruf veröffentlicht, Bitcoins auf ein bestimmtes Konto zu überweisen ... Es wird spekuliert, dass das Regime in Nordkorea als Drahtzieher fungiert ... Twitter hatte in der Vergangenheit immer wieder Probleme mit gekaperten Accounts – aber noch nie auf so breiter Front und bei so vielen prominenten Namen auf einmal."

Neue Zürcher Zeitung Briefing 7/16/2020

Sunday, May 10, 2020

Naikon, Group Tied to China's Military, Deploys Debilitating New Cyberattack Tool

The cyberwar is hot! The Cold War is an old hat!

"... In the preceding months, Naikon had also used it to hack government agencies and state-owned technology companies in Indonesia, the Philippines, Vietnam, Myanmar and Brunei, according to Check Point, which said the attacks underscored the breadth and sophistication of China’s use of cyberespionage against its neighbors. ..."

Naikon, Group Tied to China's Military, Deploys Debilitating New Cyberattack Tool - The New York Times An Israeli security company said the hacking software, called Aria-body, had been deployed against governments and state-owned companies in Australia and Southeast Asia.