City
Epaper

Chinese APT20 hacker group bypassing 2FA in latest attacks

By IANS | Updated: December 23, 2019 13:40 IST

A Chinese state sponsored hacking group, APT20, has been found bypassing two-factor authentication (2FA) in a recent wave of attacks, security researchers at the Dutch cyber-security firm Fox-IT have warned.

Open in App

Security researchers say they found evidence that the attacks have been attributed to a group which the cyber-security industry was tracking as APT20, believed to operate on the behest of the Beijing government.

The group's primary targets were government entities and managed service providers (MSPs). The government entities and MSPs were active in fields like aviation, healthcare, finance, insurance, energy, and even something as niche as gambling and physical locks, ZDNet reported on Monday.

It is pertinent to note that the Chinese state sponsored hacking group was said to be dormant for years.

While on the inside, Fox-IT said the group dumped passwords and looked for administrator accounts, in order to maximise their access.

A primary concern was obtaining virtual private network (VPN) credentials, so hackers could escalate access to more secure areas of a victim's infrastructure, or use the VPN accounts as more stable backdoors, the report added.

According to the researchers, the hackers would generally gain entry to an organisation's systems by exploiting a vulnerability on web servers that the company or government agency operated. They would then penetrate further to identify people, usually system administrators, with privileged access to the most sensitive parts of the computer network.

( With inputs from IANS )

Open in App

Related Stories

InternationalTrump claims "massive strike" in Tehran has "terminated" Iranian military leaders

InternationalIranian tribesmen reportedly fire at US helicopters searching for missing crew member

NationalRow over MP Mahua Moitra's 'Gujaratis' remark in Bhabanipur; TMC distances itself

InternationalIran warns of "radioactive contamination" risk after strike near Bushehr nuclear plant

International"Will be a big relief": Former diplomat Manju Seth hails Indian LPG tanker's transit through Strait of Hormuz

टेकमेनिया Realted Stories

TechnologyFuel supplies adequate, no need to panic: IOCL

TechnologyGovt working to minimise supply chain impact, pharma sector unaffected: Commerce Secretary

TechnologyNITI Aayog launches ATL Sarthi, Mentor India Academy to deepen school‑level innovation

Technology21 states carrying out press briefs to counter misinformation around LPG: Centre

TechnologySAIL provides 4,000 tonnes of steel for 'INS Taragiri' warship