Press ESC to close

China-linked group hacked Tibetan media and university sites to distribute Cobalt Strike paylad

CategoryDetails
Threat ActorsTAG-112 (linked to China), subgroup of Evasive Panda
Campaign OverviewEspionage campaign targeting Tibetan media and university websites for intelligence gathering for China
Target Regions (Victims)Tibetan community in India, Taiwan, Hong Kong, Australia, U.S., and other regions linked to Tibetan exiles
MethodologyExploited Joomla CMS vulnerabilities, uploaded malicious code, distributed Cobalt Strike Beacon payload disguised as a “security certificate”
Product TargetedTibet Post and Gyudmed Tantric University websites
Malware ReferenceCobalt Strike Beacon
Tools UsedCobalt Strike
Vulnerabilities ExploitedJoomla CMS vulnerabilities
TTPsWebsite compromise, spear-phishing, social engineering (disguised as security certificate), exploitation of unpatched CMS vulnerabilities
AttributionAttributed to TAG-112, a subgroup of the Chinese state-sponsored Evasive Panda hacking group
RecommendationsRegular CMS updates, enhanced website security, increased awareness of phishing attacks disguised as security certificates
SourceThe Record

Read full article:Read More

Disclaimer: The above summary has been generated by an AI language model.

Source: The Record from Recorded Future News

Published on: November 13, 2024

Leave a Reply

Your email address will not be published. Required fields are marked *