US officials allege Chinese technology manufacturers are producing equipment that allegedly permits China to spy on users. US universities are replacing telecom equipment made by Huawei and other Chinese companies to avoid losing federal funding under the NDAA.
To read the full article and find an archive of related reporting, follow this link to READBOARD.
WWW.WAPACKLABS.COM
Showing posts with label Chinese. Show all posts
Showing posts with label Chinese. Show all posts
Tuesday, February 26, 2019
Friday, March 23, 2018
China Government Hacker Resurgent
In 2015, China and the United States pledged a bilateral Cyber Agreement that they would refrain from conducting cyber operations to steal intellectual property from one another. In 2016, a major drop in such intrusions was noted. By 2017, however, several new cases of cyber intrusion against defense contractors and other commercial entities were identified, which raises the question of whether the Chinese have in fact been constrained by the 2015 agreement. Wapack Labs reviewed the major cyber operations cases of 2017, that appeared to have Chinese origins, to assess the current trends in government-sponsored operations and answer the question: is China currently abiding by this agreement? Has being a signatory to the agreement constrained Chinese government behavior in any meaningful way?...READ MOREWapack Labs has cataloged and reported on Chinese state-sponsored cyber operations in the past. An archive of related reporting can be found in the Red Sky Alliance portal.
WWW.WAPACKLABS.COM
Labels:
China,
Chinese,
cyber intelligence,
government,
state-sponsored
Wednesday, October 18, 2017
Iranian Cyber Campaign Evolutions – The Next Wave: Greenbug and Ismdoor

Greenbug is an Advanced Persistent Threat (APT) cyber-espionage group with suspected Iranian ties. In August 2017, a Greenbug tool dubbed Ismdoor resurfaced in the wild. The malware possesses many reconnaissance capabilities, and in August of 2016 was deployed to harvest account credentials prior to an attack against Saudi Arabian infrastructure. Wapack Labs assesses with moderate confidence that the presence of Ismdoor is an indicator that Greenbug may be performing reconnaissance for a future campaign. While the Greenbug group is not directly affecting the membership, the targeting of Middle Eastern gas and energy companies affects multiple supply chains with repercussions for U.S. and Allied interests in the region. Wapack Labs’ analysts have also detected an evolution in Iranian cyber campaigns indicating likely adoption of cyber espionage and cyber hacktivism models similar to those employed by the Chinese APT groups, whereby different groups are utilized in different campaigns and multiple teams conduct separate phases of a cyber campaign. The Iranian originated campaigns, similar to the Chinese APT model, are also conducted in waves. The resurgence of Greenbug and Ismdoor indicate another Iranian based cyber campaign cycle is being initiated in the Middle East...READ MORE
Wapack Labs has cataloged and reported on APT groups and campaigns in the past. An archive of related reporting can be found in the Red Sky Alliance portal.
Tuesday, December 27, 2016
Reorganization of China’s Military Cyber Forces
A significant reform of China’s People’s Liberation Army (PLA) instituted by President Xi Jinping on 31 December 2015, has resulted in a sweeping restructure of PLA command elements and combat forces. This restructure has impacted China’s military cyber forces that include identified cyber actors. The PLA General Staff Third Department, under which these military cyber actors were subordinated, was apparently disestablished. This report analyzes how China’s military cyber forces are currently structured, and where they are located in China’s military structure.
Information available from Chinese open sources, while still fragmentary, suggests that the following changes have taken place in Chinese cyber forces:
- The former Third Department is now subordinated under an entirely new branch of service: the PLA Strategic Support Force (SSF).
- The Third Department is now known as the SSF Network Systems Department. This was indicated by references to former Third Department elements that are now under this new entity.
- The Third Department Eighth Bureau was one element identified as under the Network Systems Department. This suggests that cyber actors are also under the Network Systems Department.
- The Third Department’s technical reconnaissance bureaus are probably also under the Network Systems Department...READ MORE
Handling Requirements: Traffic light protocol (TLP) GREEN.
Attribution/Threat Actors: State actors who are organized, highly technical, proficient, well-funded professionals working in teams to discover new vulnerabilities and develop exploits.
Actor Type: Adversary capabilities have been assessed as Tier IV.
Industries Targeted: US government, Department of Defense, defense contractors, and other US corporations.
Previous Reporting: N/A
Previous Reporting: N/A
The full report may be viewed in the Red Sky Alliance as DOC-4556.
Contact Wapack Labs for more information.
Contact Wapack Labs for more information.
Labels:
China,
Chinese,
military cyber forces,
PLA,
SSF,
Strategic Support Force
Tuesday, December 20, 2016
27 Chinese Hackers Profiled
Hacker use information sharing and collaboration, and there is a large community of Chinese coders are doing just that -- exchanging ideas, and tools, and sharing software development. This week, Wapack Labs published a study of 27 of the most active Chinese coders, revealing the some common characteristics of this community:- These coders are not lone hackers. They are mostly employed in major corporations or network security entities. This includes Alibaba, TenCent, and Huawei, and security entities KnownSec, Keen Team, and Evil Octal.
- They are not anonymous. Real names were found for 18 of the 27 coders studied.
- Many are well known in China and abroad. Several of those studied had more than 400 followers, and one had about 1,800.
- Many are contributing regularly; Several updating ideas and code more than 200 times over a year period.
Publication Date: 8 December 2016
Handling Requirements: Traffic light protocol (TLP) AMBER
Attribution/Threat Actors: Criminal or state actors who are organized, highly technical, proficient, well-funded professionals working in teams to discover new vulnerabilities and develop exploits.
Attribution/Threat Actors: Criminal or state actors who are organized, highly technical, proficient, well-funded professionals working in teams to discover new vulnerabilities and develop exploits.
Actor Type: Adversary capabilities have been assessed as Tier IV
Industries Targeted: Multi-industry targets/International
Past Reporting: The full reports may be viewed in Red Sky Alliance as DOC-2098, DOC-4350, and comment-7187. Contact Wapack Labs for more information.
Labels:
China,
Chinese,
coders,
GitHub,
hackers,
network security,
software,
white hat hacker,
Wooyun
Friday, December 2, 2016
E-Cigarettes Are Spreading Malware
Suspect Chinese e-cigarette manufacturers are hardcoding USB charging units with malware. If an infected e-cigarette USB charger is used to connect with a computer, malware can be downloaded. This information is being supplied for your situational awareness.
- E-cigarettes were invented in 1963, but further developed in 2003.
- E-cigarettes are charged via USB connected chargers or directly into computers.
- USBs continue to be infected with malware through hardcoding within the manufacturing process.
Using a USB as a malware delivery system is not a new phenomenon, but illustrates how companies can be easily breached in a very innocuous way. If you have ever questioned the legitimacy of an $5.00 Ebay, made in China USB connected item, you should seriously think twice before purchasing and using it with your computer.
Publication Date: 28 November 2016
Handling Requirements: Traffic light protocol (TLP) GREEN
Attribution/Threat Actors: Chinese e-cigarette manufacturer(s)
Actor Type: Adversary capabilities have been assessed as Tier II
Potential Targets: Financial, business and retail sectors
Past Reporting: DOC-4214
Labels:
China,
Chinese,
e-cigarette,
malware,
USB
Tuesday, November 29, 2016
Huawei: Monopoly in Africa
Huawei Technologies Co. Ltd. has a very strong telecommunications foothold in Africa. Many security experts believe that Huawei has been and continues to be associated with the Chinese government information sharing program. Their strong presence in Africa in numerous aspects of cyber technology, is close to becoming a monopoly in Africa. This corner of the market sets the stage for ambiguous domination of cyber technology within the African continent. This information is being supplied for your situational awareness.
- Huawei Ltd. began their African operations in 1999.
- In 17 years, Huawei has expanded exponentially with major footholds in Egypt, Kenya, South Africa, North African and Western Africa.
- Huawei has long been suspected as a corporation in collusion with the government of China and continues to create cyber security suspicion.
Huawei was suspected by South Sudan of surveillance and forgery in 2014. This was an alleged effort to gain market intelligence and delay of a funding timeline for a rival telecom infrastructure project. There has not been current reporting on these accusations, yet it illustrates the savvy nature of Huawei in creating a near African monopoly on cyber systems, IT infrastructure, cyber products and associated training. Mr. Vincent (Bo) Pang, President of Huawei’s Western European Region, in response to the South Sudan claim, stated that Huawei is trusted across Africa because it is, “in the region for the long haul.” This never a truer statement.
Wapack Labs, Africa Desk will continue to monitor Huawei and their African development.
Publication Date: 27 November 2016
Handling Requirements: Traffic light protocol (TLP) GREEN
Attribution/Threat Actors: Chinese APT
Actor Type: Adversary capabilities have been assessed as Tier IV
Potential Targets: Vodafone, French Thales, Orange & numerous African telecoms
Past Reporting: DOC-4455/4249/2902, Msg-8558
Labels:
africa,
China,
Chinese,
cyber technology,
Huawei,
information sharing,
South Sudan
Thursday, August 11, 2016
2016 Delta Airlines Computer “Glitch”

On 8-10
August 2016, OSINT research revealed Delta Airlines had a disruption of cyber service,
initially blamed on a local power outage and subsequently identified a
“computer glitch” in the media. The
disruption lasted over 6 hours; but caused major flight delays, loss in revenue
and many angry passengers. Current cyber
security experts, to include our research, theorize that a Chinese hacking from
January 2016 may have been associated with cyber disruptions of American
Airlines, Southwest Airlines and now Delta.
Disruptions to the airline
transportation industry causes serious negative effects to our American
commerce and has a ripple effect to many international markets. Further research in DDoS type attacks against
the airline industry is being conducted.
We are providing this information for your situational awareness.
Publication date: 10 August 2016
Handling requirements: Traffic light protocol (TLP) GREEN
Attribution/Threat Actors: OSINT – Airline cyber disruptions
Actor Type: Tier II
Potential Targets: USA / International
This report was published in its entirety to the Financial Services ISAC and Red Sky Alliance portal on August 10, 2016. For more information, contact Wapack Labs at 844-4-WAPACK.
Labels:
American Airlines,
Chinese,
computer,
cyber,
cyber security,
DDoS,
Delta Airlines,
glitch,
Southwest Airlines
Subscribe to:
Posts (Atom)


