Breach

Multi-Year Telco Hack Conducted By Chinese APT

Chinese hacker. Laptop with binary computer code and china flag

China-nexus advanced persistent threat (APT) Weaver Ant has compromised a major Asian telecommunications services provider's network with web shells and various payloads for more than four years as part of its cyberespionage efforts, according to Security Affairs.

Weaver Ant reportedly deployed an encrypted China Chopper web shell variant on the organization's internal server followed by the distribution of other webshells, including the nascent INMemory web shell, which enabled in-memory execution of nefarious modules to circumvent forensic detection, according to a Sygnia report.

Aside from using a recursive HTTP tunnel tool for lateral movement, Weaver Ant also executed PowerShell commands and leveraged Zyxel routers to conceal malicious activity.

"The primary objective was to enumerate the compromised Active Directory environment to identify high-privilege accounts and critical servers and add them to their target bank," said Sygnia researchers, who associated the APT with China based on its usage of Zyxel routers, previously Chinese threat actor-linked backdoors, and operating hours.

Related Terms

Attack Vector

You can skip this ad in 5 seconds

Cookies

This website uses cookies to improve your experience, provide social media features and deliver advertising offers that are relevant to you.

If you continue without changing your settings, you consent to our use of cookies in accordance with our privacy policy. You may disable cookies.