Become a fan of Slashdot on Facebook

 



Forgot your password?
typodupeerror
×
Security China IT

Researchers Discover New Malware From Chinese Hacking Group (axios.com) 18

Researchers have discovered new "highly malleable, highly sophisticated" malware from a state-backed Chinese hacker group, according to Palo Alto Network's Unit 42 threat intelligence team. From a report: The malware "stands in a class of its own in terms of being one of the most sophisticated, well-engineered and difficult-to-detect samples of shellcode employed by an Advanced Persistent Threat (APT)," according to Unit 42. The malware, which Unit 42 has dubbed "BendyBear," bears some resemblance to the "WaterBear malware family" (hence the bear in the name), which has been associated with BlackTech, a state-linked Chinese cyber spy group, writes Unit 42. Background: BlackTech has been active since at least 2013, according to Symantec researchers. BlackTech has historically focused chiefly on intelligence targets in Taiwan, as well as some in Japan and Hong Kong. The group has targeted both foreign government and private-sector entities, including in "consumer electronics, computer, healthcare, and financial industries," said researchers with Trend Micro. Trend Micro also previously assessed that BlackTech's "campaigns are likely designed to steal their target's technology."
This discussion has been archived. No new comments can be posted.

Researchers Discover New Malware From Chinese Hacking Group

Comments Filter:
  • Comment removed (Score:4, Informative)

    by account_deleted ( 4530225 ) on Wednesday February 10, 2021 @01:01PM (#61048034)
    Comment removed based on user account deletion
    • by functor0 ( 89014 )

      Current-gen antivirus tools instantly block everything that isn't whitelisted that uses PIC or modifies its own runtime.

      What OS are we talking about here? On Linux, PIC is the prevailing standard when building shared libraries so I can't see that having tight controls or you'll need to whitelist practically everything.

  • At what point does the world put a great wall around China's great wall, just to avoid these problems?

  • to deliver and install their backdoor. Golly who would have thought about doing that in this day and age.
    Why can email lead to the installation of anything on a computer.
    Why isn't the basic core functionality isolated, why not just do away with all one click installs.
    Force users to do the install process, if they can't get it done that user should not be installing anything anyway.
    • to deliver and install their backdoor. Golly who would have thought about doing that in this day and age. Why can email lead to the installation of anything on a computer.

      Because there are stupid people out there who are supposed to be the filter preventing that.

      Why isn't the basic core functionality isolated, why not just do away with all one click installs. Force users to do the install process, if they can't get it done that user should not be installing anything anyway.

      That's a good idea that would barely help.

      • by PPH ( 736903 )

        Because there are stupid people out there who are supposed to be the filter preventing that.

        Stupid people with one button [pinimg.com] that bypasses all the system protection.

    • There are email programs that make it harder to install attachments, or even "accidentally" load images that are actually malware packages, In some cases, they have other features that are highly appealing.

      But... institutions are trying to enforce uniformity, so EVERYONE runs the same, vulnerable software. The college I used to work for decided that pesky third-party email programs were too dangerous, after one of the directors was compromised using the approved software, so it was decided that no one would

  • You cannot use "China" in a potentially negative headline e.g. "China Virus" or "Chinese Hacking Group" because it is racist. Therefore "Researchers Discover New Malware From Chinese Hacking Group" is a racist headline. Although now it is acceptable to use phrases like "UK virus variant" or "South African virus variant" that is only because the UK is white and racist and South Africa was practicing Apartheid so that makes it good to do so. Try changing the headline to Researchers Discover New Malware From
  • I guess that now that Trump's out, we no longer have to blame everything on Russia and Russian, which seemed to be a synonym for 'somebody smarter than us who can do things we don't or can't do'. Now it's China or 'Chinese state backed' and we meekly accept the labels without being shown a shred of actual proof. Thanks to Snowden we have proof that our TLAs can cover their tracks and spoof their malware to look like it comes from someone else, so why do we think that those other nasty people can't do the sa
  • Well, Biden is soft on China!
    Let's support POTUS Biden by naming this malware after him.
    That way, he won't have to wait to die to get a school name after him.
    Something Totally Now! And totally within his realm of understanding!
  • The attack vector will be mass infiltration of the most widely used open source packages. Contribute for a few years, fork a dying library, make good changes, then put in nefarious code once it gets enough traction. Just taking down a mass used second tier JavaScript library would effectively cost millions of dollars of economic damage around the world. This is already being done by buying a widely downloaded, revenue poor Android app, adding nefarious code and uploading it to the app store. For a large
  • Once we learned, from the Wikileaks Vault 7 release, that the NSA has developed and continues to develop hacking programs that can mimic and implicate third parties, none of these reports are believable. Yes, I'm sure there are hacking groups in Russia and China and no doubt some are linked to their respective governments, but no one spies like the Five Eyes. The US (allied with Australia, the UK, Canada, and New Zealand) does the most snooping and the most hacking. Why do you think our bloated war departme

The only function of economic forecasting is to make astrology look respectable. -- John Kenneth Galbraith

Working...