Chinese hacker group StormBamboo successfully hijacked an ISP

https://www.tomshardware.com/tech-industry/cyber-security/chinese-hacker-group-stormbamboo-successfully-hijacked-an-isps-automatic-software-updates-with-backdoor-malware-and-bad-chrome-extensions-to-breach-a-downstream-target

Prominent Chinese hacker group StormBamboo (alternately known as StormCloud or Evasive Panda) successfully compromised an ISP and several MacOS and Windows devices on those networks, reports cybersecurity organization Volexity. Specifically, insecure protocols like HTTP were hijacked to alter DNS query responses and supplement intended automatic software updates with MACMA (MacOS-targeted malware) and MGBot/POCOSTICK (Windows-targeted malware), as well as subsequent malicious Google Chrome extension installation.

originally posted at https://stacker.news/items/637069

Reply to this note

Please Login to reply.

Discussion

No replies yet.