pwshub.com

Researchers discover China-linked hacking campaign targeting US internet providers

Hackers are using a vulnerability in a network management tool to launch cyberattacks against U.S. internet providers.

Black Lotus Labs, the cybersecurity research unit of telecommunications company Lumen Technologies Inc., revealed the hacking campaign today. The unit’s researchers believe that the campaign is likely run by Volt Typhoon, a state-backed hacking group linked to China. Black Lotus Labs has determined that the cyberattacks began as early as June 12.

The hackers are spreading malware using a zero-day or yet-unpatched vulnerability in Versa Director, a software tool that helps companies manage their networks. The application coordinates the sections of a corporate network that link together geographically disparate technology assets such as data centers. Versa Director is used by not only internet providers but also managed service providers, or MSPs, companies that focus on maintaining other organizations’ technology infrastructure.

The hackers are exploiting the vulnerability using a custom piece of malware dubbed VersaMem. It’s a so-called web shell, a malicious program that allows a threat actor to remotely access a compromised system. The hackers packaged VersaMem into a JAR file, a type of file typically used store applications written in the Java programming language.

Several key components of Versa Director are likewise written in Java. Some of those modules are powered by Apache Tomcat, an open-source tool that provides a software foundation on which Java code can run. According to Black Lotus Labs, VersaMem works by attaching to Versa Director’s Tomcat installation and modifying it.

The first purpose of the malicious code changes is to steal administrators’ Versa Director login credentials. VersaMem extracts credentials in a plaintext format, which means they can be readily read by the hackers. According to Black Lotus Labs, the stolen login details could potentially be used to compromise not only internet providers and MSPs but also such companies’ customers.

The other purpose of the code changes made by VersaMem is to facilitate the installation of additional malware modules. Those programs are loaded in a manner that makes them difficult for breach prevention systems to detect.

“The functionality described above occurs in memory only, and no Java files on disk are modified to enable the hooks,” Black Lotus Labs’ researchers detailed in a blog post. “This significantly improves the actor’s chances of avoiding detection.”

The Lumen unit believes that the hackers have so far breached at least four companies in the U.S. and one in India. The companies in question are active across the telecommunications, MSP and information technology markets.

Researchers first disclosed the Versa Director vulnerability last Thursday. Versa Software Inc., the venture-backed startup that develops the network management tool, was notified of the flaw several weeks earlier. It has released a patch that removes the vulnerability from customers’ environments. 

Photo: Unsplash

Source: siliconangle.com

Related stories
3 weeks ago - All eyes were on Nvidia’s earnings report this week as a proxy for the artificial intelligence economy, and even for the graphics chip giant, it was too much to live up to. Nvidia earnings disappointed, but really, how could they not?...
1 month ago - (Bloomberg) -- Asian equities fell Thursday, continuing a bout of volatile trading as investors digest signals from central banks on the path ahead for interest rates.Most Read from BloombergAfrica’s Richest City Needs $12 Billion to Fix...
5 days ago - Choosing your Social Security filing age is perhaps the most important retirement decision you'll make, as it can affect your benefit amount by...
1 month ago - Tokyo-based artificial intelligence startup Sakana AI today unveiled what it says is the first generative AI model in the world designed to conduct scientific research on its own. The model, called AI Scientist, is the result of a...
3 weeks ago - The race to build good artificial intelligence apps is a long one and getting off the starting block from zero can be difficult without some kind of an advantage. To provide customers that advantage, Nvidia Corp. announced NIM Agent...
Other stories
34 minutes ago - The Dow closed at a record high on Friday. Investors see more gains ahead as the Fed kicks off a new cycle of easing interest rates.
34 minutes ago - (Bloomberg) -- Lawyers for Ricardo Salinas Pliego unveiled new details Friday of the loan agreement they allege was part of a scam to con the Mexican billionaire out of hundreds of millions of dollars.Most Read from BloombergAOC Proposes...
1 hour ago - There's no end to the excitement for Intel (NASDAQ: INTC), it seems. After shares surged earlier this week on a partnership with Amazon and a $3...
2 hours ago - "A soft landing is the most likely economic scenario which makes the current environment most comparable to the mid-1990s," BMO's Brian Belski said.
2 hours ago - Owning a home can give some people confidence about their retirement prospects, but experts warn that this confidence might be misplaced. According to the Your Money Retirement Survey conducted by SurveyMonkey and CNBC.com, about 37% of...